A proposal promised compliance and never explained how. That absence is the argument. Compliance is not a property of a system, it is a property of a system inside a particular organization, and no vendor can encode your promises. Here is the one question that tests the claim.
Boards heard "delay" and moved AI governance down the priority list. The fact remains that EU AI Act obligations arriving first did not move at all. And the list of systems those rules touch? Producing it is not the hard part. Keeping it true is.
Most governance frameworks grew by accumulation. The 'cut in half' question forces you to explain why each piece exists. What you'll find is which parts have a clear rationale and which parts exist purely because they seemed responsible at the time.
Most governance frameworks fail by optimizing for coverage instead of business outcomes. Strategic governance requires three pillars: compliance requirements as your foundation, organizational needs addressing specific friction, and strategic enablers that unlock competitive advantage.
After twenty years working with data, I've seen the same pattern: companies discover data quality issues and respond with standardization initiatives, new policies, stricter controls.
It never works. The problems just get hidden under bureaucracy while the dysfunction continues underneath.