Gary Cheung

Beyond1n0 · Information Risk & AI Governance

Clearer decisions.
Accountable AI.

I’m Gary Cheung, an information risk leader working at the intersection of AI governance, technology risk, and business judgment.

Beyond1n0 examines how AI developments change decision authority, accountability, and business risk, especially in insurance and other regulated businesses. The news is the context; the judgment is the point.

My focus

Better questions.
Earlier decisions.
Clearer accountability.

Who owns the decision?
When can governance still influence the design?
What needs executive judgment?

Professional experience

An information risk perspective, grounded in practice.

My financial services experience shapes a practical view of oversight: connect risk to the decision, make authority explicit, and give leaders a clear basis for judgment.

Director, Information Risk Management

Manulife Asia · Hong Kong

Second-line information risk leadership with Asia oversight responsibilities across technology and information security risk.

Professional certifications: CISSP · CEH · PCNSE · CCNP

The perspectives shared here are my own.

Three governance questions

The questions I return to.

Policies matter. These questions help connect them to the decisions leaders actually need to make.

01 · Decision accountability

Who owns the decision?

When AI influences an outcome, who has the authority to approve, challenge, or stop it — and who remains accountable for the consequences?

02 · Design-phase governance

When can we still change the design?

Does governance arrive while objectives, data flows, and decision rights can still be shaped, or only after the important choices have been made?

03 · Executive judgment

What requires a leadership decision?

Which uncertainties and trade-offs need explicit executive judgment, rather than being absorbed into technical controls or routine approval?

Selected writing

AI developments. A leadership perspective.

Accountability

The AI Governance Question Regulators Are Forcing — And Most Leaders Can’t Answer

Why governing models and controls still leaves a fundamental question about decision ownership.

Governance timing

AI Governance Is Failing at the Design Phase — Not the Review Phase

What happens when oversight begins after the architecture and operating assumptions are already set.

Leadership & oversight

From Guardrails to Governance: What Actually Changes When Organizations Get Serious About AI Risk

The shift from constraining system behavior to establishing authority, accountability, and oversight.

Applied governance

Turn governance questions into decisions.

Considering AI in a client-facing or operational workflow? I help frame the intended use, clarify decision ownership, and surface the safeguards and trade-offs leaders need to consider.

Frame the decision

Clarify the intended outcome, the role of AI, and who holds decision authority.

Challenge the design

Examine assumptions, information flows, human intervention, and escalation while choices are still open.

Make the judgment explicit

Surface material trade-offs and uncertainties, identify the accountable owner, and define what would trigger reconsideration.

Contact

Have an AI decision to work through?

If you are deciding where AI belongs in a business workflow, I welcome a conversation about the intended use, accountable owner, and material safeguards.

Beyond1n0 is my space for independent thinking on information risk and AI governance.