- The paper demonstrates that internal expert collaboration transforms high-level regulatory frameworks into practical, team-implemented AI governance.
- It employs a five-step translation pipeline within an SME context to align compliance with engineering priorities and user-centric outcomes.
- Findings reveal that participatory workshops drive latent alignment discovery, foster legitimacy, and reduce risks of performative compliance.
Collaborative Expert Engagement for Team-Level AI Governance: Addressing the Last Mile Challenge
Introduction
The implementation of AI governance is complicated by the disconnect between high-level mandatory regulatory frameworks such as the EU AI Act and the everyday practices of software development teams. "Engaged AI Governance: Addressing the Last Mile Challenge Through Internal Expert Collaboration" (2604.21554) analyzes this gap—termed the "Last Mile" challenge—by embedding insider action research into an AI startup context. The study proposes an internal expert collaboration pipeline as a concrete method for transforming externally imposed requirements into operationalized, team-owned governance practices. The research sheds light on three distinct practitioner engagement patterns with regulatory obligations and clarifies the mechanisms by which collaborative translation can make governance actionable in resource-constrained environments.
The "Last Mile" Challenge and Internal Action Research
The paper characterizes AI governance as structurally tiered: requirements and standards are formulated at the industry level (e.g., EU AI Act), interpreted through organizational policies and management systems (e.g., ISO 42001), but must ultimately be realized through the daily, concrete decisions and practices of software development teams. The "Last Mile" challenge is the disconnect between organizational policies and the messy, resource-constrained realities of actual development practices.
This disconnect is especially acute in SMEs where governance resources are minimal, and product timelines dominate. Externally imposed frameworks risk fostering what the literature labels as "performative" or superficial compliance, typically limited to documentation and box-ticking. The study confronts this through insider action research, granting unique access to practices and attitudes that are often inaccessible due to organizational boundaries and competitive pressures.
Figure 2: A translation pipeline for operationalizing EU AI Act requirements, situating the collaborative workshop as the center of practical transformation from legal text to team action.
The research employs a five-step pipeline. Legal text is extracted, practitioner workshops assess and brainstorm requirements, and strategies are prioritized before being operationalized within standard development workflows. This process is empirically situated in a realistic SME scenario, with all the organizational and technical frictions this implies.
Patterns of Team-Level Engagement With Governance Requirements
The implementation and evaluation cycle revealed three salient patterns:
(1) Convergence Between Compliance and Development Priorities:
Some requirements (notably those related to observability, transparency, and user support) are seen as directly aligned with the team's engineering or product quality goals. For example, the mandate for logging (Article 12) was fulfilled by deploying Langfuse, an observability tool that was already desirable for debugging and supporting deployment. In these cases, compliance efforts reinforce existing engineering best practices, and practitioners perceive genuine value.
(2) Satisfying Requirements Via Existing Practice:
Other obligations were found to already be satisfied by the status quo (e.g., AI interaction disclosure), requiring minimal new effort beyond documenting and verifying current workflows. Here, regulatory compliance is "costless" at the technical level but surfaced an unexpected benefit: practitioners gain explicit awareness of how their work maps onto external expectations.
(3) Perceived Administrative Overhead and Disconnection:
A subset of requirements—especially verification-oriented ones such as exhaustive technical documentation and formalized risk management—were perceived as disconnected from immediate engineering practice. Developers saw little alignment with user needs or day-to-day quality improvements, viewing them primarily as burdensome paperwork. This category is at highest risk of superficial, performative compliance.
Figure 4: Impact-effort mapping of 14 workshop-generated strategies showing that requirements tied to transparency and oversight cluster as high-impact/low-effort, while documentation, data governance, and risk management cluster as high-effort/low-impact ("Money Pit").
This empirical mapping makes visible how internal priorities diverge substantially from the regulatory intent for certain requirement classes.
Mechanisms of Collaborative Translation
A central theoretical contribution is validation of participatory, expert-internal workshops as an effective mechanism for translating external requirements into actionable developer strategies. In the studied intervention, teams were central actors in ideation, assessment, and prioritization, rather than subjects of top-down mandates. This internal expert collaboration approach surfaced several dynamic benefits:
- Latent Alignment Discovery: Workshops made visible overlaps between governance obligations and what teams already value, turning compliance from a "necessary evil" into a foundation for system improvements.
- Ownership and Legitimacy: Practitioner co-generation of governance strategies fostered durable commitment and decreased resistance, in contrast to externally imposed requirements.
- Transparency of Governance Work: Collaborative processes made otherwise "invisible" translation and bridging work explicit, distributing governance awareness across the team.
Nonetheless, structural tensions remain—especially for documentation-focused requirements deriving value primarily for external auditors rather than the product or users. Collaborative translation cannot eliminate the compliance/quality dichotomy but can surface and mitigate it.
Practical and Theoretical Implications
The results suggest that meaningful AI governance adoption hinges not just on robust frameworks or checklists but on mechanisms that enable genuine translation at the level where software is built. The expert-collaborative approach interrogates "who benefits" from any requirement, enabling practitioners to distinguish between system-improving versus verification-driven dictates. The empirical mapping from the intervention shows that requirements perceived to benefit end-users or engineering (e.g., transparency, logging) are prioritized and implemented meaningfully, whereas auditor-targeted requirements risk being treated perfunctorily unless reframed to emphasize developmental or user value.
For policymakers, this finding challenges the notion that technical documentation or risk management can be demanded by fiat without risk of "box-ticking." It further motivates the design of regulatory guidance that is sector-specific, context-aware, and framed in ways that clarify their quality- and user-impact rationale.
From a governance research standpoint, the methodology demonstrates the value—and rare feasibility—of longitudinal, insider-embedded qualitative work in high-security, competitive SME settings, complementing prior interview- and framework-centric FAccT literature.
Limitations and Directions for Future AI Governance
The study acknowledges that a single 90-minute intervention is insufficient to shift deep-seated priorities in resource-constrained teams, and that legal translation labor cannot be fully delegated to internal workshops—specialized compliance expertise remains essential. Additionally, the context is a certified, governance-proactive startup, and generalizability will depend on organizational culture, sector, and maturity. Sustained change needs longitudinal support, leadership buy-in, and frictionless integration with development planning.
Future research should probe:
- The durability of collaborative practice and governance framing under evolving regulatory guidance (e.g., as harmonized EU standards and SME templates are developed)
- The applicability of collaborative workshop mechanisms in larger, more hierarchical and/or less governance-oriented organizations
- Sectoral and technical refinement of requirement-translation pipelines
Conclusion
"Engaged AI Governance: Addressing the Last Mile Challenge Through Internal Expert Collaboration" (2604.21554) demonstrates that bridging the implementation gap in AI governance requires internal expert collaboration that situates regulatory translation as a team-local, participatory process. The paper's pipeline and empirical results show that meaningful compliance is most likely when practitioners can discover quality or user-aligned rationales for governance work, and are empowered to prioritize strategies accordingly. While resource competition and verification-driven requirements constrain universal alignment, participatory mechanisms can distribute ownership, mitigate resistance, and make genuine compliance operationally viable for SMEs and, by extension, the broader AI industry.