AI governance

Establish who can authorize AI use, what evidence is required, where controls apply, and who can intervene when AI begins affecting consequential work.

01The governance questionAuthority

AI governance becomes material when AI can affect consequential work. At that point the enterprise needs more than principles. It needs explicit answers about authority: what the system may do, what evidence justifies that authority, who owns the outcome, and who can intervene.

A policy that cannot change operating behavior is not sufficient governance.

02Govern the responsibility, not the labelMethod

The appropriate control depends on consequence. A drafting assistant and an autonomous operating system should not pass through the same approval machinery merely because both use AI.

We connect policy, technical controls, evaluation, monitoring, and organizational authority so the level of governance rises with the level of responsibility the system is being asked to assume.

03Inside the discipline

The capabilities this discipline integrates.

01 · Authority

Decision rights

We define who may approve AI use, delegate authority, accept residual risk, and stop a system when its behavior exceeds the organization's tolerance.

02 · Evaluation

Evidence before responsibility

We establish the tests, thresholds, and operating evidence required before an AI system is trusted with more consequential work.

03 · Controls

Boundaries that operate

We translate policy into access rules, guardrails, approvals, escalation paths, and technical controls that can actually constrain behavior.

04 · Traceability

Know what happened

We create the logging, provenance, monitoring, and accountability required to reconstruct important actions and determine who owns the response.

04Decision to capability

From decision to owned capability.

  1. 01
    Inventory real and intended use.

    Identify where AI is already influencing work, what new uses are being considered, and which uses can materially affect customers, employees, operations, capital, or risk.

  2. 02
    Classify consequence and authority.

    Separate low-stakes assistance from uses that require stronger evaluation, approval, supervision, traceability, or human intervention.

  3. 03
    Define the operating controls.

    Set access, policy, evaluation standards, approval thresholds, escalation paths, and technical guardrails at the level each use case requires.

  4. 04
    Instrument evidence and oversight.

    Capture the signals needed to know what the system did, whether it remained inside its authority, and when its permissions should change.

  5. 05
    Adapt governance with the operation.

    Review incidents, performance, new capabilities, and changing use so governance evolves with the actual risk and value of the system.

Related insights