top of page

The AI Governance Gap Is in the Middle


Boards are setting expectations. Executives are approving investments. But the leaders responsible for turning AI ambition into responsible operations are too often left to improvise.


Artificial intelligence has secured a permanent place on the board agenda.


Boards are discussing risk, regulation, cybersecurity, privacy, bias and return on investment (ROI). Executives are buying tools, approving pilots and pressing for productivity. Employees are already using AI to research, write, analyze and automate parts of their work. Yet one part of the organization remains dangerously exposed: the leaders between enterprise strategy and frontline execution.


VPs, directors and senior managers are expected to translate AI ambition into everyday practice. They must decide which workflows should change, where human judgement must remain authoritative, who reviews AI-generated work and what happens when a system produces an unreliable or harmful result.


Many have been given targets and tools, but no operating model.


Policy does not redesign the work

An acceptable-use policy can tell employees what they must not enter into a public AI tool. It cannot show a director how to redesign a customer-service process, determine which outputs require review or assign responsibility when several departments and an outside vendor share the work.


The NIST AI Risk Management Framework gives organizations a sound structure for governing, mapping, measuring and managing AI risk. But even the best framework must be translated into real roles, workflows, reporting practices and escalation paths inside each organization.

Otherwise, policy remains at the top while uncertainty spreads through the middle.


Middle leaders need a repeatable way to examine each proposed use: map the workflow being changed, identify where AI influences an outcome, assign decision rights, specify the required human review and establish how concerns will be escalated and corrected. Without that structure, each team invents its own approach and enterprise policy fragments into inconsistent practice.


Pilots are not organizational capability

AI experiments are easy to launch, structural integration is harder. A pilot may produce a promising result within one team, but scaling it across the organization raises different questions:

  • Who owns the process once the pilot ends?

  • Which roles and decision rights must change?

  • How will one department’s use affect another?

  • What evidence will determine whether the tool is improving quality and not merely increasing output?

  • When should the system be paused, corrected or retired?


These are not primarily technology questions. They are questions of governance and organizational design. Research reinforces the point.


A 2025 McKinsey global survey found that workflow redesign had the greatest effect among the factors tested for bottom-line impact from generative AI. Yet only 21 percent of respondents using generative AI said their organizations had fundamentally redesigned at least some workflows.


Organizations are experimenting faster than they are rebuilding the way work gets done.


“Human in the loop” is not enough

The phrase human in the loop (HITL) appears frequently in responsible AI discussions. But the presence of a person does not guarantee meaningful oversight.


Does that person understand the system well enough to question its output?

Do they have time to review it properly?

Can they override it?

Are they protected when they delay a process or challenge a result?

Does the organization learn when their intervention reveals a recurring problem?


Without authority, competence and recourse, human review can become little more than a ceremonial approval.


This is also where cognitive surrender becomes a leadership risk: people gradually stop testing the logic, evidence and consequences of an AI-generated recommendation because the system appears faster, more confident or more objective than they feel. AI may inform judgement. It must not quietly replace the responsibility to exercise it.


Accountability cannot remain abstract

When an AI-assisted process fails, responsibility can scatter quickly.

The vendor built the tool.

Technology approved it.

Legal reviewed the agreement.

A business unit adopted it.

A manager accepted the output.

The board provided oversight.

Everyone touched the decision, yet no one clearly owns the consequence.


The complexity grows as organizations connect third-party platforms, internal AI systems and human work across several functions. An output may pass through multiple tools and teams before affecting an employee, customer or operational decision. Accountability must therefore follow the entire workflow instead of stopping at departmental or vendor boundaries.



Ethical (or responsible) AI requires an accountability structure that answers five practical questions:

  1. Who may approve this use?

  2. Who must review its outputs?

  3. Who has authority to challenge, suspend or redesign it?

  4. How can an affected person seek reconsideration?

  5. Who ultimately answers for the outcome?


If those questions cannot be answered, the organization is not ready to scale the use, regardless of how impressive the pilot appears.


The middle is where ethical AI becomes real

Boards should establish purpose, boundaries and oversight.

Executives should provide resources, authority and enterprise-wide direction.

Technology, legal and risk teams should provide necessary expertise and controls, but VPs, directors and senior managers are often the people who must make AI work inside the actual organization.


They see where processes break, where employees improvise, where workloads shift and where a productivity target may create an ethical or operational cost elsewhere. They therefore need more than AI awareness. They need the authority and capability to:

  • redesign work responsibly

  • preserve meaningful human judgement

  • assign clear operational ownership

  • connect pilots across functions

  • monitor effects on people and performance, and

  • escalate concerns before they become institutional failures.


This is the territory between policy and practice where strategy either becomes organizational capability or dissolves into disconnected experiments. Ethical AI will not be achieved through board principles, procurement controls or employee-use policies alone. It must be built into the structures through which leaders assign authority, redesign work, evaluate consequences and answer for results.


Executive leaders cannot hold VPs and directors accountable for ethical AI execution while withholding the methods, authority and resources required to lead it. These leaders need a repeatable approach to redesigning workflows, explicit decision rights, and the authority to question, suspend or refuse an implementation when its consequences cannot be responsibly governed.


AI cannot carry accountability, therefore, organizations must.



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page