---
title: "AI Governance"
date: 2026-07-12
description: Governance people route around fails to govern; the task is governing AI the Board cannot fully see without strangling adoption.
author: Mario Thomas
canonical: https://mariothomas.com/briefings/ai-governance/
---

## Start here

Two short reads before you go deeper: what this subject actually asks of a Board, and how to work through the briefing.

### If People Route Around It, It Is Not Governance

AI has changed the shape of what a Board is asked to govern. Decision-making that once ran to hundreds of human judgements a day now runs to millions of machine-made decisions a second, and a large share of the AI producing them was never approved by anyone. BCG's 2025 AI at Work research found that **54%** of employees would use AI tools even if their organisation had not authorised them, while MIT's 2025 State of AI in Business report found **95%** of formal enterprise AI pilots fail to deliver measurable ROI. On that evidence the governed programme struggles while the ungoverned one thrives.

Most of the Boards I meet respond to that picture with weight: approval committees, policy libraries, prohibitions on consumer tools. In my experience it rarely works, because heavyweight governance is heavy where it should be light and light where it should be heavy, and people simply route around it. That is the uncomfortable test running through this briefing. If people are routing around the organisation's governance, it is not governance. It is documentation.

The position these articles take is that shadow AI is a signal, not a discipline problem, and that the answer is not less governance but better-designed governance. The Six Board Concerns model provides the diagnostic lens, an interconnected system rather than a checklist. Minimum Lovable Governance provides the operating principle: the smallest system that achieves the necessary guardrails and that people actually want to use. And the AI amnesty provides the practical first move, converting an invisible risk into an inventory the Board can govern.

Read the briefing and you should be able to make one judgement about your own organisation, in three parts: whether its AI governance governs in practice or only on paper, whether its intensity matches actual risk, and whether the Board could demonstrate its position tomorrow rather than after weeks of preparation.

### From the Six Concerns to the Amnesty

Take [the articles](#core-reading) in the order the core sequence lists them. Start with the Six Concerns, which sets out what a Board must govern; the diagnosis piece, later, shows why the concerns behave as one system rather than six separate items. Then Minimum Lovable Governance, the operating principle that makes the rest workable. The two amnesty pieces follow: the case for a time-limited disclosure window, and the roadmap for the weeks after it closes, when the trust the amnesty has earned is at its most perishable.

The supporting articles go deeper on specific fronts. The diagnosis piece shows what happens when the Six Concerns are addressed sequentially instead of together. The inherited values piece asks whose ethics the organisation's models are actually running. The accountability gap piece shows that agency transfers to AI while accountability does not, and the Centre of Excellence piece explains why the Centre is the Board's governance vehicle rather than an IT function. The director playbook defines the literacy the role now demands of every NED, and The Board in the machine is the 2022 article where this body of work began; it is worth reading for how much of the problem was already visible then.

[Remake](#remake-assets) gathers the named mechanisms beneath the thinking as a model, a diagnostic, a methodology, and a principle: the apparatus you can take into a Board pack rather than an argument you have to reconstruct. And [the questions](#faqs) at the end are the ones directors put to me most often, each answered with a pointer back into the work, with the references beneath them if you want the primary evidence the articles draw on.

## Core reading

The core sequence runs from what a Board must govern, through the operating principle that makes governance work, to the amnesty that brings shadow AI into the light.

1. [AI is transforming governance: Six key Boardroom priorities](https://mariothomas.com/blog/board-ai-governance-priorities/) (10 minute read, 4 February 2025): AI takes Boards from overseeing hundreds of decisions a day to millions a second, each needing to be transparent, explainable and correct: six priorities follow.
2. [Minimum Lovable Governance: The AI Operating Principle Boards Should Use](https://mariothomas.com/blog/minimum-lovable-governance/) (13 minute read, 30 November 2025): Minimum lovable governance replaces episodic compliance with continuous, embedded oversight people actually want to use: guardrails that earn adoption rather than enforce it. Podcast edition: 17 minute listen.
3. [Shadow AI and the Case for an AI Amnesty](https://mariothomas.com/blog/shadow-ai-amnesty-governance/) (15 minute read, 21 September 2025): Shadow AI is surging and most employees would use AI tools without permission. An AI amnesty turns that hidden risk into governed, employee-validated innovation.
4. [After the AI Amnesty: Practical Steps to Operationalise Discovered Shadow AI](https://mariothomas.com/blog/shadow-ai-amnesty-next-steps/) (12 minute read, 28 September 2025): After the amnesty, speed matters: employees who disclosed expect enablement, not restriction. A roadmap for turning discovered shadow AI into governed capability.

## Further reading

- [AI's Interconnected Challenge: Diagnosing the Six Concerns of the Board](https://mariothomas.com/blog/ai-strategy-diagnosis/) (12 minute read, 12 October 2025): The Board's six concerns demand simultaneous orchestration and receive sequential, project-level attention. Treating them as one diagnostic lens is where AI governance starts.
- [Ethical AI: When the Model Imposes Values Your Organisation Did Not Choose](https://mariothomas.com/blog/ethical-ai-inherited-values/) (14 minute read, 17 May 2026): A foundation model arrives with a value system its provider built and the Board did not choose. The decision: accept it, reject it, or build. Podcast edition: 15 minute listen.
- [AI and the Director: A Practical Playbook for Governing What You Can't Fully See](https://mariothomas.com/blog/director-ai-governance-playbook/) (11 minute read, 29 March 2026): Directorial AI literacy is not technical fluency. It is four specific capacities that let directors interrogate maturity claims, assess real governance, and exercise independent judgement. Podcast edition: 15 minute listen.
- [The Board in the machine](https://mariothomas.com/blog/the-board-in-the-machine/) (10 minute read, 17 October 2022): AI and machine learning are becoming ubiquitous in business decisions, and Boards need to know what is deployed and how it is governed.
- [The Accountability Gap: When AI Delegation Meets Human Responsibility](https://mariothomas.com/blog/ai-agency-accountability/) (15 minute read, 16 November 2025): Organisations are transferring decision-making agency to AI while accountability stays with people, and approving deployments without the verification capability that accountability needs.
- [AI Centre of Excellence: Moving Beyond Shadow AI Risk to Scaled AI Adoption](https://mariothomas.com/blog/ai-coe-why-boards-need-one/) (11 minute read, 8 June 2025): AI makes millions of decisions at speeds traditional oversight cannot match, and shadow AI adds unmanaged risk: the case for an AI Centre of Excellence.

## Remake

The mechanisms beneath the thinking: the model, diagnostic, methodology, and principle from the Remake Library that turn this briefing into apparatus a Board can use.

- **Model: Six Board Concerns**. An interconnected lens of six concerns, Strategic Alignment, Ethical and Legal Responsibility, Financial and Operational Impact, Risk Management, Stakeholder Confidence and Safeguarding Innovation, that must be orchestrated together so AI discussion does not collapse into risk management alone. [Remake Library](https://mariothomas.com/remake/library/six-board-concerns/)
- **Diagnostic: AI Amnesty Questionnaire**. The structured instrument for running an AI amnesty: ten sections capturing which tools employees actually use, the use cases they serve, the data they touch, the value already created, and the risks encountered, turning unknown unknowns into a governable inventory. [Remake Library](https://mariothomas.com/remake/library/ai-amnesty-questionnaire/)
- **Methodology: AI Amnesty**. The time-boxed programme that brings shadow AI under governance: a declaration window, typically 30 to 45 days, in which employees disclose all AI tool usage without fear of punishment, followed by the post-amnesty roadmap of rapid triage, governance guardrails, pilot launch, and ongoing operations. [Remake Library](https://mariothomas.com/remake/library/#ai-amnesty)
- **Principle: Minimum Lovable Governance**. Governance embedded in how work happens: proportionate to risk, continuous rather than episodic, and used because it works. [Remake Library](https://mariothomas.com/remake/library/minimum-lovable-governance/)

## Questions

The questions directors put to me most often on this subject, answered from the work in this briefing.

### We cannot see most of the AI our people use. How do we govern it?

Not by pretending the visibility problem away. Menlo Security documented a 68% year-on-year surge in shadow generative AI usage in 2025, and most of it never touches a formal approval process. The practical first step is [a time-limited AI amnesty](/blog/shadow-ai-amnesty-governance/): a disclosure window, without punishment, that converts an invisible risk into an inventory the Board can actually govern, and surfaces the use cases employees have already validated.

### Should we simply block unapproved AI tools?

The evidence says blocking does not stop the use; it hides it. BCG's 2025 AI at Work research found 54% of employees would use AI tools even if the organisation had not authorised them, and Gigster's 2025 research found 57% already hide their usage. Prohibition drives the activity further underground, where the data exposure is worst. The better questions are why people route around the sanctioned route, and [what would make them choose it](/blog/shadow-ai-amnesty-next-steps/) instead.

### Is lighter-touch governance not just weaker governance?

No. [Minimum Lovable Governance](/blog/minimum-lovable-governance/) is not less governance; it is governance matched to risk. A credit decisioning system warrants heavier scrutiny than a meeting summariser, continuous assurance beats the annual audit scramble, and controls embedded in the workflow get used where separate approval queues get bypassed. The test is whether the organisation could demonstrate its compliance posture tomorrow, not after weeks of preparation.

### Whose values is our AI actually running?

The provider's, unless the Board has decided otherwise. Every foundation model arrives with a value system built upstream in pre-training and alignment, and system prompts, retrieval, and guardrails constrain that standard without re-authoring it. The choice for each material deployment is to [accept, reject, or build](/blog/ethical-ai-inherited-values/), and the failure mode is accepting everywhere by default without ever naming the decision.

### What does the Board itself need to learn to govern AI credibly?

Not technical fluency. Directorial AI literacy is [four specific capacities](/blog/director-ai-governance-playbook/): interrogating maturity claims, distinguishing operational governance from governance theatre, identifying material AI risk, and exercising independent judgement rather than ratifying management's framing. Deloitte's 2025 Global Board Survey found two-thirds of Boards still report limited or no AI knowledge, so most directors will find gaps. Finding them is the point.

### Where should our AI Centre of Excellence report?

To the Board, through the risk and compliance committee, not to IT. That has been my position since [the article introducing the Six Board Concerns model](/blog/board-ai-governance-priorities/): the AI Centre of Excellence is a governance mechanism for decision-making at machine speed, not another technology function, and a reporting line through IT tends to narrow it to technical implementation. My 2022 article The Board in the machine made the same point in earlier language, placing oversight with the Audit and Risk Committee. Independence from operational pressure is the point; [the case for the Centre](/blog/ai-coe-why-boards-need-one/) sets out the mandate, authority, and resources the Board resolution should carry.

### Who owns the intellectual property our people create with public AI tools?

Often nobody can say. When people use public tools to create content or code, ownership of the output can be unclear, and the provider's terms of service may be the only text on the point. [The article introducing the Six Board Concerns model](/blog/board-ai-governance-priorities/) raises the question because organisations have been discovering intellectual property built in unapproved tools. The Board's job is to require an answer for each material use case and to bring that work into the open. The AI Amnesty methodology does that, and [the post-amnesty triage](/blog/shadow-ai-amnesty-next-steps/) treats IP created without controls as a first-week, high-risk item.

### Does ISO 42001 certification mean we are governing AI well?

Not on its own. ISO 42001 sets requirements for an AI management system, and ISO/IEC 42006:2025 adds the audit and certification requirements, but a certificate says a system exists, not that governance happens in practice. [The diagnosis piece](/blog/ai-strategy-diagnosis/) describes organisations that tick the boxes, implement ISO 42001, and still fail, because the Six Board Concerns model is an interconnected system and they worked through it one concern at a time. Certification pursued too early also tends to produce the heavyweight governance people route around. The [Minimum Lovable Governance](/blog/minimum-lovable-governance/) principle is the progressive path: embedded, proportionate, continuous governance first, maturing towards certification.

## References

The research houses, institutes, and regulators these articles draw on; go here for the primary evidence.

- **Institute of Directors** (2025): [AI Governance in the Boardroom](https://web.archive.org/web/20251121075957/https://www.iod.com/app/uploads/2025/09/AI-Governance-in-the-Boardroom-1c7612e872fa3fce3f9d6cad78b0b4ba.pdf). The IoD business paper on Board-level AI governance, including the expectation that a Board can pause or reverse an AI system whose behaviour proves unacceptable.
- **IoD NEDs Reimagined Commission** (January 2026): [NEDs Reimagined](https://www.iod.com/app/uploads/2026/01/FINAL-IoD-Business-Paper-NEDs-reimagined-14.01-6ca5096ee6348f2301347e942a1ffe29.pdf). Formally names the directorial AI literacy gap and calls on NEDs to build their own understanding and independent sources of insight.
- **Deloitte Global Board Survey** (28 April 2025): [Governance of AI: A critical imperative for today’s boards](https://www.deloitte.com/global/en/issues/trust/progress-on-ai-in-the-boardroom-but-room-to-accelerate.html). Finds 69% of Boards discuss AI regularly while only a third feel equipped to oversee it, and two-thirds report limited or no AI knowledge.
- **BCG** (June 2025): [AI at Work 2025: Momentum Builds, but Gaps Remain](https://web-assets.bcg.com/fd/0d/bcc5dfae4cbaa08c718b95b16cf5/ai-at-work-2025-slideshow-june-2025-edit-02.pdf). The source of the 54% figure: employees who would use AI tools whether or not the organisation authorises them.
- **MIT NANDA** (July 2025): [The GenAI Divide: State of AI in Business 2025](https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf). The research behind the 95% pilot failure figure and the GenAI Divide between individual adoption and organisational readiness.
- **Menlo Security** (4 August 2025): [Menlo Security’s 2025 Report Uncovers 68% Surge in “Shadow” Generative AI Usage in the Modern Enterprise](https://www.menlosecurity.com/press-releases/menlo-securitys-2025-report-uncovers-68-surge-in-shadow-generative-ai-usage-in-the-modern-enterprise). Menlo Security's 2025 report on AI in the modern workspace, documenting a 68% year-on-year surge in shadow generative AI use (vendor research, press release).
- **Harmonic Security** (31 July 2025): [GenAI Data Exposure: What GenAI Usage Is Really Costing Enterprises](https://www.harmonic.security/blog-posts/genai-data-exposure-report-fa6wt). Quantifies what shadow AI actually leaks: sensitive content in uploaded files and prompts, much of it through personal accounts.
- **Stanford CRFM** (December 2025): [The Foundation Model Transparency Index](https://crfm.stanford.edu/fmti/). Scores foundation model providers on disclosure; the 2025 edition averaged roughly 40 out of 100, which is why an inherited value system cannot be fully read.
- **EUR-Lex** (12 July 2024): [Regulation (EU) 2024/1689 (Artificial Intelligence Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689). The risk-tiered architecture of Regulation (EU) 2024/1689 that makes proportionate governance a legal expectation rather than a preference, with the high-risk obligations deferred in 2026 to December 2027 and August 2028.
- **PwC** (30 October 2025): [PwC’s 2025 Responsible AI survey: From policy to practice](https://www.pwc.com/us/en/tech-effect/ai-analytics/responsible-ai-survey.html). Evidence that adaptive, embedded governance correlates with 30 to 40% faster innovation cycles.
- **Gigster** (28 May 2025): [The Dangers of Shadow AI and Need for an Enterprise AI Plan](https://gigster.com/blog/the-dangers-of-shadow-ai-and-need-for-an-enterprise-ai-plan/). Gigster, 2025: 57% of employees using AI tools at work conceal their usage, the shadow-AI figure the governance articles cite.
- **arXiv** (4 February 2026): [Alignment Drift in Multimodal LLMs: A Two-Phase, Longitudinal Evaluation of Harm Across Eight Model Releases](https://arxiv.org/abs/2602.04739). The 2026 pre-print on alignment drift in multimodal models: why governance cannot assume a model's behaviour is fixed between versions.

## The ideas beneath this briefing

Ideas I've named and matured writing about AI Governance: what each one means, and where it started.

- **Emergent Threat Paradox**: AI risks evolve through learning, adaptation and interaction in ways traditional risk frameworks cannot anticipate, so established controls fail against systems that continuously learn and change. [Read more](https://mariothomas.com/blog/ai-strategy-diagnosis/)
- **Multi-Speed Collision**: When functions align AI to their own objectives at different velocities, their individual successes actively undermine each other, for example marketing generating demand that supply chain AI cannot fulfil. [Read more](https://mariothomas.com/blog/ai-strategy-diagnosis/)
- **Trust Multiplier Effect**: How stakeholder confidence cascades, employee doubt breeding customer suspicion, alerting regulators, spooking investors, so lost trust in one group turns technical triumphs into organisational disasters. [Read more](https://mariothomas.com/blog/ai-strategy-diagnosis/)
- **Value Attribution Crisis**: The difficulty of measuring AI value that emerges through compound effects defying simple attribution, causing project-based evaluation to systematically undervalue transformation while overvaluing incrementalism. [Read more](https://mariothomas.com/blog/ai-strategy-diagnosis/)
- **Velocity Mismatch**: The gap between AI's rapid development pace and traditional quarterly board governance cycles, where the capability justifying a business case in January may be obsolete by June. [Read more](https://mariothomas.com/blog/ai-strategy-diagnosis/)

All concepts: https://mariothomas.com/glossary/concepts/

## More Board Briefings

More complete resources on AI and emerging technology for the Boards that need the full picture.

- [AI Accountability](https://mariothomas.com/briefings/ai-accountability/): Agency can move to the machine; accountability cannot, and answering for what AI decides now takes capability that policy alone does not supply.
- [AI Regulation](https://mariothomas.com/briefings/ai-regulation/): AI regulation has split into incompatible regimes, and the Board's task is not compliance with each but a deliberate position across all of them.
- [AI Risk](https://mariothomas.com/briefings/ai-risk/): The AI risks that bite are seldom on the register, and the bill for sovereignty shocks, readiness gaps, verification costs, and model risk arrives later.
- [AI & the Board](https://mariothomas.com/briefings/ai-and-the-board/): AI changes how every Board duty is discharged, from director to Company Secretary, and moves none of the accountability.
