Governance meetups have a characteristic failure mode: an evening spent comparing frameworks. Someone maps NIST AI RMF 1.0 against ISO/IEC 42001, someone else adds a column for the EU AI Act, everyone nods, and nobody's Monday is different.
The sessions that keep an audience do the opposite. They take one concrete decision an organisation actually faces and work it through in public, using the frameworks as reference material rather than as the subject.
Start from a decision, not a standard
Good session prompts look like this:
- A team wants to deploy a model that touches hiring. What has to exist before it ships, and who signs?
- Your vendor will not disclose training data provenance. Do you proceed, and what do you write down either way?
- A model in production has drifted. Who is accountable, on what timescale, and what triggers a rollback?
- Someone wants to use a general-purpose assistant with customer data. What is the minimum viable control set?
Each of these pulls in the frameworks naturally — you cannot answer the hiring question without touching risk classification, and you cannot answer the vendor question without touching documentation obligations. But the room stays anchored to something recognisable.
Who should be in the room
Governance sessions go wrong when they are all one profession. A room of lawyers produces policy nobody can implement; a room of engineers produces controls that do not survive an audit. The useful mix is legal and compliance, engineering, a product owner who has to ship, and if you can get one, somebody who has been through a real external audit.
That last person is worth actively recruiting. The gap between what a framework says and what an auditor asks for is where most of the practical knowledge lives, and it is almost entirely undocumented.
A format that produces output
Ninety minutes. Twenty minutes framing the decision, including any relevant regulatory context. Forty minutes working it in small groups of four or five — small enough that nobody can hide. Twenty minutes where each group reports what they decided and, more usefully, where they disagreed. Ten minutes of open discussion.
Write the disagreements down and publish them. A short public note saying "six practitioners could not agree whether this needed a formal impact assessment, and here is why" is more valuable to the next reader than any framework summary, and it is the kind of artefact that makes people attend the next session.
Keeping it current without chasing headlines
Regulatory timelines move, and a governance group can easily become a news-reading circle. A reasonable discipline: spend no more than ten minutes per session on what changed, and only where it changes a decision. If a development does not alter what somebody would do on Monday, it belongs in a newsletter, not in the room.
It also pays to be explicit that the group is not giving legal advice. Practitioners share how they handled something; that is not the same as telling somebody else what is compliant, and being clear about the distinction keeps the conversation candid.
Where these groups exist
Governance meetups cluster where regulation and industry concentration overlap — financial centres, capitals, cities with large healthcare or public-sector employers. If nothing exists near you, the joint-session route works well here too: an established compliance, privacy or risk group will often host an AI governance evening before there is enough demand for a standalone one.