There is a seductive way to talk about AI governance: imagine a powerful new technology arriving at the gates of an organisation, and imagine governance as the fence that keeps it safe. The problem is that organisations do not work like that.

AI enters through budgets, procurement processes, product roadmaps, data teams, legal reviews and executive incentives. By the time a model reaches a governance committee, many consequential decisions have already been made.

The governance gap is organisational

A company can have excellent model documentation and still make poor decisions. It can have an ethics committee and still launch a system whose incentives are fundamentally misaligned. It can have a sophisticated risk framework and still discover that nobody owns the decision when something goes wrong.

The real question is not whether an organisation has an AI policy. It is whether the organisation has a person who can make a difficult decision when the policy meets reality.

This is particularly visible in regulated industries. Legal, compliance, model risk, technology and business teams may each have a legitimate piece of the problem. The failure occurs in the space between them.

What good governance looks like

Good governance is less about adding another approval gate and more about making decisions explicit: who owns the use case, what evidence is required, which risks are tolerable, who can stop deployment, and what happens when business objectives conflict with regulatory requirements.

The strongest governance systems do not eliminate ambiguity. They make ambiguity visible early enough for an institution to respond intelligently.

Continue exploring

Books →
Teaching →
Ideas journal →