AI can speed up a decision; governance determines whether that decision should be made at all.

There's a conversation that's starting to come up more and more often in boardrooms. Which model should we use? Which agents can we deploy? How much can we automate? How much can we save? What is the competition doing?
These are legitimate questions. But I think we're starting from the wrong place.
Before asking ourselves which artificial intelligence we're going to adopt, we should ask something far more important: are we ready to govern it?
Artificial intelligence is no longer purely a technology conversation. It's entering commercial, financial, operational, legal, and HR processes — it's helping analyze information, generate content, recommend decisions and, increasingly, execute certain activities. And when a technology starts taking part in decisions that affect the business, customers, employees, or the organization's information, the conversation necessarily changes. It's no longer enough to ask what AI can do. We have to decide what we allow it to do, under what conditions, and who is accountable when something goes wrong.
To me, AI Governance is the set of rules, roles, and controls that help ensure the artificial intelligence an organization uses is profitable, safe, legally compliant, protective of information, consistent with the company's values, and doesn't end up eroding trust in the brand.
In other words, it's not only about controlling AI — it's about governing the value and the risk AI can generate.
This distinction matters. Because an organization can have an AI that technically works very well and still be making a bad business decision by using it.
When we talk about AI Governance, we usually think first about security, privacy, or regulation — these are fundamental issues, but they're not the only ones.
There are legal and compliance risks: regulation, intellectual property, contracts, misuse of information, or decisions that can create liabilities for the organization.
There are security risks: data breaches, attacks, unauthorized access, lack of traceability, or sensitive information ending up where it should never have been.
There are also operational risks. An AI can discriminate, make mistakes, generate false information, become obsolete, or keep operating once the model behind it should no longer be used.
And there are reputational and ethical risks. A decision can be technically possible and still be completely misaligned with a company's values or with what its customers expect from it.
But there's one risk I consider especially important that many organizations still underestimate: not having proper data management in place.
Data quality, security, cleanliness, currency, stewardship, access, and purpose aren't secondary matters — if data isn't governed, it will be very difficult to properly govern an intelligence that learns, combines information, draws conclusions, and may recommend or even execute actions.
The difference can be summed up simply: Data Governance helps define what information can be used, who is responsible for it, and under what conditions. AI Governance adds a more complex question: what can artificial intelligence do with that information?
We don't need to imagine extreme scenarios to understand the risk. Real cases already exist.
In 2024, a British Columbia tribunal held Air Canada liable for incorrect information its chatbot gave about a bereavement fare. The company tried to argue the chatbot was a separate tool from its operations, but the tribunal didn't accept that separation. To the customer, the information came from Air Canada, and the responsibility remained the company's.
The case left a lesson that goes well beyond a chatbot: an organization can't transfer its responsibility to the artificial intelligence it uses.
Something similar happened at Samsung in 2023, when employees entered sensitive company information into generative AI tools. The organization's response was to temporarily restrict their use while it defined more adequate controls.
That case points to another reality CEOs should keep in mind: artificial intelligence can enter an organization long before the organization has formally decided how to govern it. This is now commonly called Shadow AI — tools used by employees without a formal process of approval, evaluation, or control.
That's why AI Governance shouldn't begin when the company decides to buy a platform. It should begin when it understands that AI is already changing the way people work.
One of the mistakes that would concern me most would be turning AI Governance into a bureaucratic process that ends up holding back innovation.
Not every AI application carries the same risk or requires the same level of control. A low-impact tool used to summarize internal documents shouldn't go through the same process as an intelligence that takes part in a credit decision, recommends a hire, or has access to sensitive customer information.
“Governance should be proportional to risk and to the level of autonomy.”
Lower risk means more room to experiment quickly; higher impact and autonomy call for greater controls, traceability, and accountability.
The organization needs to find that balance. Controlling too much can hold back innovation; controlling too little can lead to innovating without understanding the consequences and with little relevance to the business.
Another common mistake is thinking that, because artificial intelligence relies on technology, its governance should sit exclusively with the CIO or the technology area. I don't see it that way.
AI Governance needs to sit close to strategy, and therefore close to the CEO. IT plays a fundamental role, but so do Security, Internal Control, Legal, Innovation, and Human Talent.
The business has to define what value it's after. Technology has to make sure the architecture and systems can support it. Security has to assess information and access risks. Legal has to help understand the regulatory, contractual, and intellectual-property implications. Innovation has to help connect what the technology can do with the strategy. And Human Talent carries an enormous responsibility for adoption, capability-building, training, and change management.
The conversation, then, shouldn't be about who owns the AI. It should be about who is accountable for the decisions the organization is starting to delegate to it.
The arrival of artificial intelligence can make us think the conversation is about models, agents, automation, and productivity, but behind every one of those elements, there are still people.
People who have to learn to use these tools, people who need to understand when to trust a response and when to question it, people who need to know what information they can share and what they can't, people who will have to adapt to new ways of working and, in some cases, take on different responsibilities.
That's why adoption can't be left for later.
An organization that brings in AI without preparing its people risks having two realities at once: a formal strategy and an informal practice. While leadership tries to define rules, employees may already be using different tools, sharing information, building their own workarounds, and creating dependencies no one is aware of.
The goal shouldn't just be avoiding Shadow AI or so-called AI Sprawl — it should be building a culture where people understand the purpose, know the limits, and have the judgment to use AI responsibly.
The best governance isn't the kind that forces people to follow rules they don't understand. It's the kind that gets people to understand why those rules exist and to act correctly even when no one is watching.
A CEO doesn't need to become a specialist in models, algorithms, or AI architecture — their responsibility lies elsewhere.
They must understand the impact AI can have on the business, the risks they're willing to take on, how it connects to the strategy, and which decisions the organization is starting to delegate.
The questions they should be asking are far more business-oriented than technical: what problem are we solving? What value do we expect to generate? What data does the solution need? What risks are we taking on? What level of autonomy will it have? What happens if it makes a mistake? Who is accountable? Who can stop it? What happens if tomorrow we need to switch providers or models?
The CEO doesn't have to govern the algorithm; they have to govern the decision.
To me, this is one of the most important ideas when we talk about AI Governance. The discussion shouldn't stop at whether the model works — it should extend all the way to the decision that model is helping to make, and the consequences that decision can have.
Another risk I see often is confusing using AI with having an AI strategy.
An organization can have dozens of isolated initiatives: an assistant for customer service, another to generate documents, another to analyze information, and a few experiments built internally.
That shows activity — it doesn't necessarily show strategy.
Strategy appears when the organization starts asking where AI can meaningfully change its value chain, where it can improve an experience, speed up a decision, reduce a risk, free up capacity, or create an advantage a competitor doesn't yet have.
A localized improvement can even create a problem somewhere else in the business: automating one activity can increase the workload in the next process, reducing time can raise control risks, improving productivity can create dependency on a vendor, or expose information that used to stay inside the organization.
That's why, before automating, we should understand the decision; before delegating, understand the risk; before giving an agent autonomy, define what it can and can't do.
The technology can change, the model can change, the vendor can change, but the organization's responsibility remains.
In one of the projects I've been developing around the concept of AI governance, there's an idea I find especially powerful: before adopting artificial intelligence, we should sit down and define our limits.
What are we going to delegate? What are we going to supervise? What will we never delegate? Who is accountable? What data can the AI use? What decisions can it execute? What happens when it makes a mistake? What principles are we not willing to negotiate, even if an AI promises to make things faster or cheaper?
This may sound simple, but it forces a conversation many organizations still aren't having.
A mature organization isn't necessarily the one that automates the most — it's the one that knows what it should automate, what it should keep under human control, and why.
That judgment becomes even more important as autonomy increases. First AI recommends, then it automates, then it executes, and at some point someone may ask why it still needs human authorization at all.
The line between autonomy and responsibility shouldn't move simply because the technology proved it can do something.
Sometimes the conversation about governance starts from fear: what could go wrong, what rule could we break, what information could we lose.
It's necessary to talk about those risks, but I think staying there alone would be a mistake.
Governance should also help capture value — it should allow the organization to experiment, learn, measure, adjust, and scale whatever actually works.
It should help decide when an initiative should continue, when it should change, when it's time to retire a model, and when it's better to simply say: this doesn't make sense for our business.
Ultimately, governing well doesn't mean saying no to artificial intelligence — it means knowing where to say yes, where to set limits, and under what conditions the risk is worth taking.
I would start with very simple questions, though not necessarily easy ones to answer.
What do we want to use artificial intelligence for?
What specific pain point do we want to solve?
What advantage can it give us over our competitors?
Can it help us improve profitability or accelerate growth?
How can it support a genuinely differentiated strategy?
After answering these, other conversations will follow: what data we have, how reliable it is, which processes we want to transform, which people we need to prepare, which risks we need to manage, what architecture we need, and what level of governance applies.
Technology should arrive after that conversation, not before.
For years we talked about digital transformation, then we talked about automation, now we talk about AI — but something remains constant.
Organizations still need strategy, governance, reliable data, well-defined processes, architecture, and leadership, and they still need people capable of taking responsibility when there's no obvious answer.
That's why an AI strategy shouldn't start with: “which AI can we buy?”
It should start with: “what do we want to transform, and what intelligence do we need to do it better?”
That's where AI Governance begins. And that's also where a far more important conversation begins for a CEO: are we using artificial intelligence to transform our business, or are we simply adding intelligence to our processes?
The difference may seem small. But it could end up defining who leads the future, and who is simply trying to catch up to it.

Tell us your organization's challenge. We'll set up a conversation with the right team and tell you straight whether we can help.