AI can assist with drafting, summarising and research. That does not mean a generative model should decide the governance requirements that apply to an organisation's AI use.
Consistency matters
For core governance triage, deterministic rules allow the same conditions to produce the same result. That makes the process easier to test, review and maintain.
People should be able to see why
If a control or approval is required, the user should be able to see the condition that triggered it. A recommendation is much easier to defend when the reasoning is visible.
Rules still have limits
No rule set can replace legal advice, privacy assessment, security judgement or professional risk decisions. A good governance system knows when to route the issue to a human specialist.
Versioning matters too
Governance requirements change. Historical decisions should retain the rule version and context that applied when the assessment was made rather than silently changing after a framework update.