Most organisations approaching AI governance are solving for the wrong problem. The instinct — understandable, defensible — is to design the rules first, comprehensively, and then implement. Define the use cases, establish the ethics policy, stand up a review committee, and proceed. The governance model is familiar because it worked before. The difficulty is that the conditions that made it work before do not apply to AI.
In Brief
- Upfront AI governance rules are obsolete before they are implemented — the technology changes faster than policy cycles can ratify.
- Human committee review operates on timescales incompatible with the speed at which AI systems generate and propagate decisions.
- Decentralised governance is not reduced control — it is centrally defined rules about who decides, and when to escalate.
- A Chief AI Officer with a clear accountability structure holds responsibility without centralising every decision.
- Global standards govern skills, behaviours, and guardrails; local decisions govern everything that can safely be made close to the work.
AI governance is not a complicated problem with a knowable answer that expert analysis can determine in advance. It is a complex problem — one where the technology itself changes faster than the governance mechanisms designed to contain it. The distinction matters, because applying complicated-domain responses to a complex-domain problem does not just fail to produce the expected result. As Snowden and Boone (2007) established in their foundational work on decision-making frameworks, it creates the illusion of having acted while the underlying system continues operating on its own logic.
The operating model most organisations are using for AI governance needs to be redesigned for the domain it is actually in. Most currently are not.
Upfront rules are obsolete before they are implemented
The first problem with specification-based AI governance is timing. Organisations spend months — sometimes longer — designing their AI policy framework. By the time it is ratified, socialised, and embedded in operating procedures, the AI landscape has moved.
This is not conjecture. The Organisation for Economic Co-operation and Development (OECD) has observed directly that the inability of governance mechanisms and institutions to keep pace with rapid AI evolution is among the most critical risks associated with AI deployment (OECD, 2024a). The OECD itself updated its own AI Principles twice — in 2023 and in 2024 — specifically to account for AI systems that continue to evolve after deployment (OECD, 2024b). If the peak international body governing AI policy cannot produce stable rules faster than the technology changes, an internal enterprise policy team has no realistic prospect of doing so.
The practical consequence is predictable. An organisation finalises its AI governance framework based on the capabilities and risk profile of models available when the framework was designed. By implementation, the models in use have materially different capabilities. The framework governs a version of the technology that no longer exists. The gaps are structural, not incidental, and they accumulate faster than governance review cycles can close them.
Research into the governance of generative AI published in peer-reviewed literature has reached an equivalent conclusion: more abstract rules covering fundamental values can remain stable, but more specific coordination rules must change frequently as the technology and its risks co-evolve (Grisold et al., 2025). The layering of abstraction levels is not a design preference — it is a structural requirement of any governance design that intends to remain relevant.
Committee timescales do not match AI timescales
The second problem is response time. Most organisations govern AI failures and breaches through human committee review: a governance board or risk committee that convenes periodically, assesses incidents, and issues guidance. In environments where technology moved slowly and systems were comparatively stable, this worked. The committee’s timescale was roughly compatible with the rate at which problems could develop.
AI does not operate on that timescale. Agentic AI systems make decisions and take actions faster than committee review cycles can detect, assess, and respond. The gap between when a problem occurs and when a committee can address it is not a minor inefficiency — it is a structural mismatch between the speed of the governed system and the speed of the governing one.
This is the same domain problem identified earlier. Snowden and Boone (2007) are explicit: in complex and rapidly-moving environments, the command-and-control response — escalating to a central authority that analyses and decides — is actively counterproductive. It is a design calibrated to systems where cause and effect are visible and stable. AI incidents frequently have causes that are only coherent in retrospect, and effects that have already propagated by the time the committee convenes.
The International Association of Privacy Professionals (IAPP) AI Governance in Practice research found that AI governance is still evolving, and that even mature programs continue to find room to innovate as new guidance and compliance burdens emerge (IAPP, 2024). The programs that manage this successfully are not the ones with the most sophisticated committees. They are the ones that have built sensing and response capacity into the operating model itself — so that the people closest to the system can act on what they observe without waiting for central review to authorise every decision.
Decentralised governance is not a loss of control
The response to these two problems is frequently misread. When the argument for decentralised AI governance is made, it tends to be heard as an argument for less governance — for loosening the controls, for accepting more risk, for letting the edges of the organisation operate without accountability. That reading is incorrect.
MIT’s Centre for Information Systems Research (CISR) published research in March 2026 introducing what they term minimum viable governance — a design intended to match the pace of generative AI while enabling the organisation to sense and seize opportunities (van der Meulen et al., 2026). The finding is precise: foundational principles can reduce the need for comprehensive policies, giving teams greater operational decision rights while safeguarding business continuity. In their research, organisations with well-developed minimum viable policy practices halved the average time to make complex decisions, and their teams identified new opportunities at three times the rate of peers without such practices (van der Meulen et al., 2026).
This is not less governance. It is governance calibrated to what it actually governs.
Centralised control: Infrequent decisions with large impacts
Centralised control is appropriate for decisions that are infrequent but carry a significant scale of impact — decisions about AI design, about risk appetite, about the fundamental ethical constraints that apply across the organisation. These decisions are made rarely, and their consequences are significant enough to warrant delaying central review.
Decentralised control: Infrequent decisions with large impacts
Everything else — the daily decisions made by teams who understand the context — is better governed by clear rules about who may decide, on what basis, and when escalation is necessary.
Concurrent research from MIT CISR on decision rights in the agentic AI enterprise confirms this structure. Sebastian et al. (2026) identify ambiguity and risk as the two key dimensions that determine how AI and human decision-making should be distributed. High-ambiguity, high-risk decisions warrant escalation. Low-ambiguity decisions — even consequential ones — can be delegated when the rules governing them are clear. The enterprise that centralises all AI decisions is not exercising good governance; it is creating a bottleneck that makes accurate, timely decision-making impossible.
The parallel in information technology operating model research is equally clear. MIT CISR’s 2025 analysis of enterprise IT operating models found that top performers increase both speed and scale by distributing technology decision rights to business units while maintaining strong central information technology leadership for modularity and reuse (Thorogood & Woerner, 2025). Decision-making close to the work is not a compromise on control. It is the mechanism through which control actually functions at scale.
What the accountability structure looks like in practice
The design implication is a specific accountability structure — not a set of policies, but a defined map of who holds authority for which decisions, under which conditions.
The Chief AI Officer (CAIO) sits at the centre of this map, not because every AI decision flows through that role, but because the CAIO holds accountability for how well decisions are being made across the organisation. The role is not a committee chair. It is a single accountable person who collaborates — through a structured Responsible, Accountable, Consulted, and Informed (RACI) arrangement — with decision-makers at every level to understand the quality of local decisions and to provide guidance that makes those decisions better over time.
The research supports this structural move. The IAPP’s AI Governance Profession Report found that Chief AI Officer recruitment has tripled in the last five years, reflecting the growing recognition that specialised AI leadership — distinct from the Chief Information Officer or Chief Risk Officer role — is a structural requirement, not a governance fashion (IAPP, 2025). Separately, unclear roles cause nearly one-third of project failures (IAPP, 2025): the accountability gap is not theoretical, it is an observed source of operational failure.
The CAIO’s function is not to review every decision. It is to set the conditions under which decisions can be made reliably without central review, to monitor the quality of those decisions through the RACI relationships, and to engage the escalation mechanism when a decision has a scale of impact that warrants it.
Above this sits the global layer: the enterprise-wide standards that apply regardless of where a decision is made. Global skills define the AI competencies that every practitioner who deploys or governs AI must have. Global behaviours define the standards of conduct that apply universally. Global guardrails define the non-negotiable constraints — the ethical limits, the risk thresholds, the data handling rules — that no local decision can override. These are the stable, high-abstraction rules that the governance research consistently identifies as appropriate for central definition (Grisold et al., 2025). They are not comprehensive; they are foundational. The less prescriptive they are at the specific level, the longer they remain valid as AI capabilities evolve.
This is the structural inversion that most current AI governance has not yet made. The instinct is to specify everything centrally and delegate implementation. The design that actually functions specifies principles centrally and delegates decision-making — while holding the quality of those decisions accountable through the CAIO’s collaborative oversight role.
The question worth asking about your current governance
The pattern that tends to surface when AI governance is examined closely is not a failure of intent. Organisations designing comprehensive policy frameworks, standing up ethics committees, and investing in governance tooling are not making a mistake in motivation. The issue is structural: the model was calibrated for a domain it is not in.
The diagnostic question worth asking is not “do we have an AI policy?” Most organisations do. The question is whether the governance design can sense and respond to AI failures on the timescale those failures actually develop. Whether the rules governing local AI decisions are clear enough that the people closest to the work can act without waiting for central review. Whether the CAIO role — or its equivalent — holds genuine accountability for the quality of distributed decisions, or whether it is primarily a reporting and compliance function. And whether the global standards that underpin all of this are designed at an abstraction level that will survive the next iteration of the technology, not just the current one.
The organisations that will govern AI well are not the ones that wrote the most comprehensive framework. They are the ones that designed their governance to match the domain they are operating in.
References
- Grisold, T., Berente, N., & Seidel, S. (2025). Guardrails for human-AI ecologies: Norm-based coordination and design for predictability. MIS Quarterly, 49(4), 1239–1266. https://doi.org/10.25300/MISQ/2025/18058
- International Association of Privacy Professionals. (2024). AI governance in practice report. IAPP. https://iapp.org/resources/article/ai-governance-in-practice-report
- International Association of Privacy Professionals. (2025). AI governance profession report. IAPP. https://iapp.org/resources/article/ai-governance-profession-report
- Organisation for Economic Co-operation and Development. (2024a). Governing with artificial intelligence: Trends and early lessons from the use of AI across functions of government. OECD. https://www.oecd.org/en/publications/governing-with-artificial-intelligence_795de142-en
- Organisation for Economic Co-operation and Development. (2024b). Evolving with innovation: The 2024 OECD AI Principles update. OECD.AI. https://oecd.ai/en/wonk/evolving-with-innovation-the-2024-oecd-ai-principles-update
- Sebastian, I. M., Weill, P., Haskamp, T., & vom Brocke, J. (2026, June). Designing decision rights for AI (Research Briefing No. XXVI-6). MIT Centre for Information Systems Research. https://cisr.mit.edu/publication/2026_0601_AIDecisionMatrix_SebastianWeillHaskampVomBrocke
- Snowden, D. J., & Boone, M. E. (2007). A leader’s framework for decision making. Harvard Business Review, 85(11), 68–76. https://hbr.org/2007/11/a-leaders-framework-for-decision-making
- Thorogood, A., & Woerner, S. L. (2025, December). Enterprise IT operating models in the AI era (Research Briefing No. XXV-12). MIT Centre for Information Systems Research. https://cisr.mit.edu/publication/2025_1201_EntITOperatingModels_ThorogoodWoerner
- van der Meulen, N., Jewer, J., & Levallet, N. (2026, March). Minimum viable governance for generative AI (Research Briefing No. XXVI-3). MIT Centre for Information Systems Research. https://cisr.mit.edu/publication/2026_0301_GenAIGovernance_VanderMeulenJewerLevallet