AI governance without accountability design is compliance theatre with better dashboards

Every enterprise software vendor at an APS-focused technology event now leads with an AI governance story. The pitch is consistent: dashboards that track model outputs, workflow routing for high-risk decisions, audit trails for regulatory compliance, and monitoring that surfaces anomalies before they become incidents. While the technology is real, it still leaves a governance gap that can only be filled by people.

In Brief


  • A governance platform is a monitoring layer. Who is responsible, for what, with what authority, must be designed separately and first.
  • Gartner's data on AI governance platforms attributes the reduction in incidents to comprehensive implementation, which explicitly requires the human accountability structures, not the platform alone.
  • The 2024 OECD AI Principles update moved risk management into the Accountability principle, framing governance as a design problem rather than a technology problem.
  • Over 40% of agentic AI projects are projected to be cancelled by 2027, primarily due to inadequate governance structure rather than inadequate tooling.
  • APS agencies that purchase an AI governance platform from a single vendor may be creating the kind of dependency they are trying to manage.

Buying a governance platform before the accountability architecture exists is not a technology problem. It is a sequencing problem — and it tends to surface only after the investment has already been made.

Vendors avoid naming where accountability breaks

The distinction vendor events rarely make explicit is the difference between a monitoring layer and an accountability architecture. A monitoring layer does what it says: it observes, logs, reports, and alerts. An accountability architecture assigns who is responsible for what the monitoring is showing, what they are authorised to do about it, and what happens when they don’t. The first is a capability. The second is a governance design. Buying the first does not produce the second.

This is not a criticism of the platforms themselves. Gartner’s research on AI governance platforms acknowledges that comprehensive implementation can reduce AI-related ethical incidents by 40% compared to organisations without such systems (Gartner, 2024). The operative qualifier is comprehensive — meaning the accountability structure, policy frameworks, and board-level visibility that sit beneath the technology. The platform is one component of a governance architecture that must already exist for the platform to function as intended.

The 2024 update to the OECD AI Principles is unambiguous on what governance actually requires. The OECD holds that AI actors should be accountable for the proper functioning of AI systems based on their roles, the context, and consistent with the state of the art (OECD, 2024). The phrase “based on their roles” is load-bearing. No platform creates accountability. It can surface information to support accountability — but the structural assignment of who is responsible, and for what, has to be designed and owned by the organisation. The 2024 update relocated risk management provisions explicitly into the Accountability principle, marking this as a governance design problem rather than a technology problem.

What makes this gap easy to miss is that the monitoring layer looks like governance. It produces reports. It flags exceptions. It creates a visible record of oversight activity. For an SES officer who needs to demonstrate AI governance to a minister or an Australian National Audit Office (ANAO) review, the platform provides evidence of oversight processes in place. The structural question — whether those reports are landing in an accountability structure designed to act on them — is harder to see until it isn’t.

Governance built around the monitoring layer, without the accountability architecture beneath it, is governance theatre: it produces the appearance of control without the structural conditions for it.

A 2024 global survey of 1,100 technology executives conducted by Economist Impact found that 40% of respondents assessed their organisation’s AI governance program as insufficient to ensure safety and compliance (Economist Impact, 2024). These were not organisations without governance tooling. They were executives in active AI programs who judged their governance architecture as inadequate. The technology was present. The accountability structure was not.

The board engagement picture carries the same implication. Research published by the National Association of Corporate Directors found that only 14% of boards discuss AI at every meeting, while 45% have yet to place it on the agenda at all (NACD, 2024). No dashboard resolves a board that has not assigned accountability. The monitoring layer reports upward into a decision-making structure that, in most organisations, has not yet been designed to receive it.

Governance platforms cannot fix accountability

The immediate consequence is familiar to anyone who has sat in a post-implementation review. The platform is operational. The dashboards are live. But when an AI-related incident surfaces, the question of who was responsible — and under what authority — remains unclear. The monitoring layer flagged the anomaly. What happened next, and who owned it, exposes the structural gap the platform was assumed to have closed.

Buying the technology layer first is how organisations end up with expensive software reporting into a governance vacuum.

The compounding cost runs deeper than incident response. Gartner projects that over 40% of agentic AI projects will be cancelled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls as the primary causes (Gartner, 2025). Escalating costs and unclear business value are not problems a governance platform resolves. They are symptoms of a structure that was not designed to own AI as a strategic asset from the outset. The platform monitors what exists. It cannot replace the decisions about what should exist, why, and under whose authority.

For APS agencies, there is an additional dimension that the vendor pitch rarely surfaces. A 2026 survey of enterprise leaders found that 81% are concerned about AI vendor dependency, yet only 6% report being able to switch providers without material disruption (Zapier / AI Assembly Lines, 2026). An agency that purchases a governance platform from a single enterprise vendor to manage its AI risk has created a new dependency to manage alongside the existing ones. For agencies with data sovereignty obligations under Australian Government Hosting Policy and Information Security Registered Assessors Program (IRAP) requirements, that is not a theoretical risk — it is a concrete governance question that must be assigned to someone before procurement begins.

Accountability design comes before platform selection

What this requires, in practice, is a different sequence from the one vendor events tend to suggest. The structural assignment of accountability — which governance body, which executive, which oversight mechanism — needs to be resolved before a platform is selected. Enforcement authority, not just reporting capability, needs to be built into the oversight structure. Board-level engagement with explicit accountability for AI risk needs to be established before the board is asked to receive monitoring reports. The platform comes after these are in place, not before.

Floridi (2021) frames the governance design problem directly: ethical principles without enforceable accountability mechanisms are compliance theatre, not governance. The same logic applies to monitoring platforms that surface information into an accountability vacuum. Reporting without accountability produces a record of what happened. It does not produce the governance structure that changes what happens next.

The platform is valuable inside an accountability architecture that has been designed. Outside one, it is the most expensive record of a governance gap you will ever produce.

References

  • Economist Impact. (2024). AI governance in the enterprise: A global survey of 1,100 technology executives and engineers. Economist Impact.
  • Floridi, L. (2021). The ethics of artificial intelligence: Principles, challenges and opportunities. Oxford University Press.
  • Gartner. (2024, October 21). Gartner identifies the top 10 strategic technology trends for 2025 [Press release]. gartner.com
  • Gartner. (2025, June 25). Gartner predicts over 40% of agentic AI projects will be canceled by end of 2027 [Press release]. gartner.com
  • National Association of Corporate Directors. (2024). Tuning corporate governance for AI adoption. In 2025 Governance Outlook. NACD. nacdonline.org
  • OECD. (2024). OECD principles on artificial intelligence (updated May 2024). OECD. oecd.ai
  • Zapier. (2026). Enterprise AI vendor dependency survey 2026. As cited in AI Assembly Lines. aiassemblylines.com

About the author

Receive insights on strategy, leadership, and transformation.
By subscribing you agree to our Privacy Policy
© 2026 Zen Ex Machina (ZXM) Pty Ltd. All rights reserved. ABN 93 153 194 220

Discover more from Zen Ex Machina

Subscribe now to keep reading and get access to the full archive.

Continue reading

search previous next tag category expand menu location phone mail time cart zoom edit close