Compliance is the part of AI work where the gap between the written standard and the day-to-day practice is widest. A meetup is one of the few places that gap gets discussed honestly, because nobody is being assessed.
Build the session around evidence
The question that produces the best discussion is not "what does the standard require" — that is readable — but "what did you actually put in front of the auditor, and did it hold".
Practical prompts:
- What does your model inventory look like, and who keeps it current?
- How do you evidence that a human reviewed a decision, six months later?
- What does your change log capture when a prompt changes, versus when a model version changes?
- Who signs off, and what happens when that person is on leave?
- Which controls did you inherit from a cloud provider, and how did you verify that inheritance?
Every one of those has a documented answer in some standard and a messier answer in practice. The messier answer is the content.
Control mapping, done live
A format that works well: put one control on the screen — say, a requirement for human oversight of a consequential decision — and have the room work out, together, what evidence would satisfy it in three different contexts: a bank, a hospital, and a twelve-person startup.
The exercise makes the point that compliance is proportionate, which is the single hardest thing to convey to teams reading a standard for the first time. It also surfaces the practices that scale down, which is what most attendees need and what most published guidance ignores.
Who benefits from being in the room
Compliance officers and risk leads, obviously. Less obviously, the engineers who will have to produce the evidence. Most audit pain traces back to instrumentation decisions made a year earlier by someone who did not know what would be asked for, and an evening in the same room fixes more of that than any policy document.
Small-company attendees are worth actively welcoming. They are usually the ones who suspect the whole subject does not apply to them, and they are usually wrong in a way that is cheap to fix early and expensive to fix later.
What to avoid
Do not let the session become a certification sales channel. Training providers and audit firms have a legitimate place in this community, but a room that turns into a funnel loses the practitioners fast.
Do not read standards aloud. Assume the text is available and spend the time on interpretation and evidence instead.
Do not promise definitive answers. Much of this is genuinely unsettled, and a group that admits that is more useful — and more honest — than one that manufactures certainty.
Getting one started
Compliance groups often start inside an existing community rather than standing alone: a privacy meetup, an ISACA or IIA chapter, a risk forum. Offering to run one AI-focused evening for an established group is a lower-friction start than founding something new, and it tells you quickly whether there is local demand.
Look up your local AI community or browse upcoming sessions.