Series
AI governance for leadership teams
AI governance for a leadership team is a set of decisions about authority, information integrity and accountability: what the system may do without human approval, which source it should treat as authoritative, how uncertainty is exposed, how separate contexts are kept apart, and who owns the outcome when it is wrong. Those are technology leadership decisions, not model-selection decisions.
Three pieces written from operating an AI system across my own fractional CTO practice, not from a framework. What it took on, where the boundaries had to sit, and the decisions a leadership team should make before the technology makes them by default.
The series
Part 1
AI can do far more than answer questions. The hard part is knowing what it should do
Where AI genuinely improves the work underneath a CTO role, where judgement has to stay, and why the hard decisions are leadership decisions rather than model choices.
Part 2 · due 20 August 2026
Who is accountable when your AI is confidently wrong?
A bad AI answer does not look bad. Four failure modes seen in live use, and the accountability questions a board should settle before trusting the output.
Part 3 · due 27 August 2026
13 AI governance decisions to make before the technology makes them for you
Thirteen decisions a leadership team should own before AI takes on real operational work: authority, memory, retrieval, context separation and failure.
What has to be decided
Six areas a leadership team has to settle
Authority
What can the system do on its own, what can it prepare for approval, and what is the worst plausible consequence of each action it is allowed to take?
Information integrity
Which source is authoritative when two disagree, how stale information is retired, and whether the system preserves the difference between a validated fact and a hypothesis.
Uncertainty
Whether a reader can tell a strongly supported answer from a plausible guess, and whether the system is allowed to decline rather than manufacture certainty.
Context separation
What actually prevents information from one client, project or department influencing the reasoning applied to another.
Unattended work
What happens when a scheduled process inherits a changed supplier default, hits a dependency that is connected but not permitted, or fails with nobody watching.
Accountability
Who owns the decision, who reviews it, and what the board sees when an AI-supported workflow reports success that nobody actually received.
These are drawn from thirteen situations documented while running the system against real work, set out in full in part three.
Questions
Common questions
- What is AI governance in practice?
- It is the set of operational decisions that sit under an AI policy: what the system is authorised to do, what information it is allowed to trust and retain, how it behaves when evidence is weak, how separate contexts are kept apart, and where human approval is enforced rather than requested.
- Who should own AI governance in a smaller company?
- A named executive, not a committee and not the supplier. In companies without a full-time CTO that ownership often sits with the founder, supported by an independent technology voice who can test whether the controls exist outside the model rather than inside a prompt.
- Does a board need to see this?
- If AI is participating in operational work with commercial, contractual or regulatory consequence, then yes. A board does not need the architecture. It needs to know where AI has authority, what it is allowed to trust, how uncertainty is handled and what happens when it gets something wrong.
- Is this the same as complying with the EU AI Act?
- No. Regulatory compliance is one input. These decisions are about how a specific system behaves inside a specific business, and they are needed whether or not a given regime applies to you.
Written and reviewed by Timothy Ng . Last reviewed 13 August 2026.
Can somebody in your business explain where AI has authority?
If nobody can yet answer that, the governance has not caught up with the technology. Tell me what your systems are already doing and I will tell you what I would put around them.