Claudio Barrientos

Carousel

AI governance: the problem isn't that your teams use AI. It's that nobody knows who is accountable.

Does your organization govern its AI, or only regulate access?

Claudio BarrientosJun 20264 min read

The problem is not that your teams use AI. The problem is that nobody knows who is accountable.

The typical reaction

Faced with this, almost every organization reacts the same way:

  • They create a committee and delegate responsibility.
  • They write an acceptable-use policy.
  • They define who may use ChatGPT, Copilot or Claude.
  • Or they let each team experiment on its own.

And they believe that governs their AI. It doesn't: it only regulates access to tools.

The nature of the change

AI strategy is not adjusted from the outside like a recipe. But it is not improvisation by each area either. AI is a multifactorial change: technological, cultural, strategic, operational and organizational. A change of mindset.

This is no longer opinion

The reference frameworks confirm it:

  • NIST AI RMF — govern, map, measure, manage: AI risk as a continuous practice.
  • ISO/IEC 42001 — AI management system.
  • EU AI Act, article 4 — mandatory AI literacy.
  • OWASP Top 10 for LLMs — injection, leakage and poisoning risks.

NIST AI RMF

Govern · Map · Measure · Manage. AI risk as a continuous practice.

ISO/IEC 42001

AI management system.

EU AI Act · Art. 4

Mandatory AI literacy.

OWASP Top 10 for LLMs

Injection, leakage, poisoning.

Figure 1. Reference frameworks that already formalize AI governance.

And consulting agrees. McKinsey (The State of AI, 2025), Bain (Operating Model for the Age of AI), Deloitte (State of AI in the Enterprise) and PwC (Responsible AI Survey) point in the same direction: the challenge is not adopting more tools. It is redesigning operating models, managing risk, defining accountability and scaling with confidence.

Where the risk appears

You don't need hundreds of models in production. The risk is already there when:

  • Sales uses AI to prepare proposals.
  • Finance projects revenue with models.
  • HR screens candidates with external tools.
  • Customer service connects a chatbot to internal documents.
  • A technical area uses agents to execute tasks.
  • Management assumes ChatGPT is always right.

The questions almost nobody answers

The question is not which tool is used.

  • Who is accountable if the result is wrong?
  • Who approves that use?
  • Who understands the risk?
  • What data is being used?
  • Which decisions can AI influence?
  • What must a person review?
  • When to stop, correct or withdraw?

It doesn't have to be bureaucratic

Governance is proportional to the size of the organization.

Large company: committees and formal roles, risk models, audit, structured processes.

Small company: inventory of AI uses, rules for sensitive data, owners per initiative, human review on key decisions, traceability of sources and prompts, a mechanism to escalate incidents.

What matters is not the size of the structure. It is that accountability exists.

The critical distinction: data governance ≠ AI governance

Data governance controls what AI consumes. AI governance controls what AI learns, generates, recommends and executes.

The more autonomous the AI, the greater the need for governance.

DataIA / AIActionsconsumesgenerates & executesData governancecontrols what AI consumesAI governancecontrols what AI learns, generates, recommends and executes
Figure 2. Data governance controls what AI consumes; AI governance controls what it learns, generates, recommends and executes.

The new competitive gap

The winners will not be those who adopt more AI tools. The winners will be those who understand its limits, redesign processes, manage risk and convert AI into real value.

The new competitive gap will not be only technological. It will be a gap of understanding, leadership and governance.

Does your organization govern its AI, or only regulate access?

Sources

NIST AI Risk Management Framework 1.0 (2023) · ISO/IEC 42001:2023 · EU AI Act (Reg. 2024/1689), Art. 4 · OWASP Top 10 for LLM Applications (2025) · McKinsey, The State of AI (2025) · Bain, An Operating Model for the Age of AI · Deloitte, State of AI in the Enterprise (2026) · PwC, Responsible AI Survey.

More in this topic