No, this is not another story about digital transformation and AI. What AI did is more elementary than that. It forced us to think about governance again. Now, before you start thinking about challenging me because your organization is embracing and succeeding at governance (more specifically, information and technology governance, and now AI governance), read on.
Volvo introduced the modern seatbelt in 1959, then did something almost unheard of and released the patent so anyone could use it. The engineering was finished. The physics were settled. The lives it would save were entirely predictable.
And then nothing much happened for a decade.
Belts didn’t become required equipment in American cars until the late 1960s, and most states didn’t require anyone to actually buckle one until the mid-1980s. The safety case never changed during those twenty-five years. What changed was the crash data, the lawsuits, and the political cost of ignoring both.
I’ve been thinking about that story all year, because we have been sitting on the governance equivalent of a finished seatbelt for a very long time.
Boards had every model they needed to evaluate, direct, and monitor technology for decades. Many chose not to pick them up. Governance stayed a compliance chore. A slide in the appendix. Something the audit committee glanced at once a year and then set down.
Then AI arrived, and in roughly twenty-four months governance became the thing everyone wants to talk about like it was a new streaming series they binged over the weekend.
I’m giving AI the credit for that. Full credit.
What I’m seeing today. The people in the room have changed. I used to pitch governance sessions to IT audiences and watch executives send a delegate. Now the delegate stays home and the executive shows up with questions they’ve clearly already argued about internally. ISACA’s 2026 AI Pulse Poll (https://www.isaca.org/resources/ai-pulse-poll) found that 45 percent of digital trust professionals now treat AI risk as an immediate organizational priority, and half of Oceania respondents put ultimate accountability for AI harm squarely with the board and executive leadership. Not with IT. Not with the vendor. With leadership. Boards are drafting AI principles at the same table where they set risk appetite. Ten years ago I couldn’t get those same directors to sit through twenty minutes on IT governance objectives. That is a genuine shift, and it’s worth understanding why it happened now.
AI made governance personal. Traditional IT risk asks whether the system is available, secure, and accurate. AI risk asks whether the DECISION the system made was defensible. That’s a different question and it lands in a different place. Air Canada’s chatbot invented a bereavement fare policy that didn’t exist, and a tribunal made the airline honor it anyway. No breach. No outage. No cyber incident. Just a machine making a commitment on the company’s behalf, and a company discovering it owned the outcome. Every director who read that story understood immediately that this was not an IT problem.
Speed removed the review window. Governance used to have slack built in. A bad decision worked its way through a process, and somewhere along that path a human noticed. AI compressed that window to nothing, and agentic AI closed it entirely. When the system doesn’t recommend but executes, controls must exist before the action, not after the report. That forces the conversation upstream, into direction-setting, which is exactly where governance was always supposed to live.
Regulation attached a number to it. The EU AI Act tops out at seven percent of global turnover. GDPR tops out at four. Whatever you think of the drafting, a regulator just priced governance failure higher than data protection failure, and CFOs read those numbers even when they skip the frameworks.
The AI governance gap became measurable. This matters more than people realize. For thirty years, “our governance is weak” was an opinion, and opinions lose arguments to roadmaps. Now we have numbers. Only 38 percent of organizations report a comprehensive AI policy, and only 12 percent have tested their ability to shut an AI system down. Twelve. You can debate a consultant; it’s much harder to debate a board paper that says we cannot demonstrate we could stop this thing.
And everyone got their hands on it. Shadow IT was a nuisance handled by procurement. Shadow AI shows up in legal, marketing, HR, and finance simultaneously, and 89 percent of organizations are worried about it. When every function is deploying the technology, governance stops being an IT topic and becomes an enterprise one. AI did that reclassification for us. We had been asking for it politely since the nineties.
So no, I don’t think AI broke governance. AI is the crash data. It gave a settled discipline the one thing it never had. Urgency. Attention is a perishable asset, and I’d rather spend it than admire it. Governance holds a record nobody wants: most agendas appeared on, fewest things actually changed. Let’s not celebrate the moment with another steering committee. And stop apologizing for the topic. For three decades governance had to justify its seat at the table. It doesn’t anymore. Walk in assuming the mandate exists, because right now it does.
Final Thoughts
1. Extend the system you have, don’t erect a second one beside it. The fastest way to waste this window is to create a standalone AI governance function with its own committee, its own register, and its own vocabulary. Two years in, it will be arguing with enterprise risk about jurisdiction. Frameworks like COBIT were built for exactly this: direction, oversight, and accountability that outlive whatever happens to be on the roadmap this year. What AI needs is new questions, not a new bureaucracy. Try this: add AI scenarios to the enterprise risk register you already maintain rather than opening a separate one, and route them through the same escalation path everything else uses.
2. Convert attention into decision rights. Interest is not authority. Before this cycle cools, get the boring things written down: who owns each AI system by name, who can accept the risk of deploying it, who can pull it out of production, and who signs off when the model version changes underneath you. The vendor owns the tool. You own the outcome. Every time. Try this: take your three highest-impact AI systems and put a person’s name, not a department, against each of those four decisions before the quarter closes.
3. Make oversight something you can test. “Human in the loop” is the most comfortable phrase in AI governance and one of the emptiest. A human is meaningful oversight only when they have the expertise to understand what they’re reviewing, the authority to say no, and the TIME to look properly. Miss one of the three and you’ve appointed a spectator. A policy proves intent. A logged override proves control. Try this: at the next board meeting, bring one AI system and three artifacts: the owner’s name, last quarter’s override log, and the date the shutdown was last tested.
4. Rehearse the stop. A kill switch nobody has ever pulled is a bookmark. Pick your two most consequential AI systems this quarter and run the drill end to end: who calls it, how long the halt takes, what breaks downstream, what the customer sees. Twelve percent is not a statistic to sit comfortably inside. Try this: schedule it like a fire drill, on a real date with a named caller, and write down what you learn when it takes three times longer than anyone predicted.
Attention follows novelty, and something will eventually be newer than AI. What you institutionalize in the next twelve months is what survives when the spotlight moves. Spend the urgency while you have it.
That’s what I see. Now I’m curious what you see, because the organizations getting this right are rarely the ones writing about it.

