The current state: widespread use, uneven control
AI is no longer a contained technology program. Stanford’s 2026 AI Index reports that 88% of surveyed organizations used AI in 2025 and 70% used generative AI in at least one business function. Yet AI-agent deployment remained in the single digits across nearly all functions. Organizations have moved from deciding whether to use AI to discovering that capability, authority, and accountability are not the same thing.
The legal environment is also becoming operational. Major provisions and enforcement milestones under the EU AI Act took effect in August 2026, including transparency rules, while additional high-risk obligations continue on a phased timeline. Leaders should not mistake a changing compliance calendar for permission to delay the underlying work of inventory, ownership, evidence, and recourse.
Govern the system in context
A model does not approve a loan, screen an applicant, alter a medical workflow, or send money by itself. A sociotechnical system does: data, prompts, software, people, incentives, vendors, permissions, and operating procedures. Governance should therefore classify the use case by consequence, reversibility, scale, sensitivity, and the degree to which a person can understand or challenge the outcome.
Every material use needs one named business owner. That owner is accountable for purpose, affected people, acceptable performance, residual risk, monitoring, and retirement. Technical teams can validate the system; they should not be left to accept enterprise risk on behalf of leadership.
The limits I would put in place now
Limits should be explicit enough to change behavior. They should prevent unacceptable use, constrain high-consequence use, and allow low-risk experimentation to proceed within known boundaries.
- No AI-only final decisions affecting employment, credit, health, education, benefits, legal rights, or physical safety; require authorized human judgment, notice, and meaningful appeal.
- No undisclosed synthetic identity, impersonation, or material AI-generated communication where a reasonable person would believe they are interacting with a human.
- No autonomous external action—spending, publishing, deleting, changing records, or contacting people—outside scoped permissions, transaction limits, and a tested rollback path.
- No sensitive or confidential data in an AI system unless the use, provider, retention, access, and downstream handling have been approved.
- No production deployment without an owner, documented purpose, risk tier, evidence threshold, monitoring plan, incident path, and stop authority.
Make oversight a management cadence
NIST’s AI Risk Management Framework places executive responsibility, contextual testing, post-deployment monitoring, appeal, override, incident response, and decommissioning in the operating model. That is the correct level of ambition. A policy alone cannot govern a changing system.
Boards should receive a portfolio view: the highest-consequence uses, accountable owners, material incidents, accepted exceptions, evidence gaps, and upcoming decisions. Management should review the inventory and controls when the model, data, population, autonomy, or purpose changes. Governance is not a promise that AI will never fail. It is the discipline of knowing who decided, on what evidence, within which boundary, and what happens when the system is wrong.
Do not ask whether a model is approved in the abstract. Ask who owns this use, what authority it receives, what evidence justifies it, and whether an affected person can obtain a remedy.