Why it matters now
Many executives feel more confident about AI risk than their controls justify. Policies exist on paper, but nobody watches what actually runs. As AI starts taking actions, not just writing text, that gap matters more. Good governance is not a brake. In my experience, clear rules are what let teams move without asking permission every time.
- Only about a third of companies have responsible-AI controls in place for the AI models they run.EY, Responsible AI Pulse, 2025 ↗
- Organisations with real-time monitoring and oversight committees report better revenue and cost outcomes from AI.EY, Responsible AI Pulse, 2025 ↗
Common mistakes
- Bolting governance on after deployment.
- A policy that exists only on paper, with no monitoring behind it.
- Applying the same heavy process to every use, so people route around it.
- Unclear decision rights, especially for what AI systems may do on their own.
What to do instead
- Tier by risk. Sort uses into low, medium and high risk. Keep the rules light where little can go wrong and strict where customers, money or safety are affected.
- Set decision rights. Write down who approves new uses, and which decisions an AI system may make alone, with approval, or never.
- Monitor and audit. Log what systems do, review quality regularly and keep an audit trail for important decisions.
- Prepare for incidents. Agree how problems are reported, who responds and how you switch to a fallback.
- Form a cross-functional group. Bring IT, legal, compliance and the business together in one small group that meets regularly and can decide.
Your first step this week
Ask for a list of every AI system in use that touches customers, money or personal data, with its owner. The gaps in that list are your first governance task.
Related guides
- Should we restrict ChatGPT, and how do we handle shadow AI?
- How do we lead teams where people work alongside AI agents?
- How do I work with the board on AI?
All AI leadership principles and guides · 100 AI use cases by function