The AI Governance Question COBIT Answered 30 Years Ago

My grandmother’s cast-iron skillet outlived three microwaves, two bread machines, a fondue set, an air fryer, and one very ambitious juicer that now lives in the garage next to the treadmill. Every few years, a shiny new appliance arrived promising to change dinner forever. And every few years, the skillet just kept making dinner. Keep that skillet in mind. It’s about to become relevant.

Everyone wants an AI governance playbook right now. Boards are asking for one. Regulators are drafting them. Every conference agenda I’ve seen this year has at least three sessions promising one. So fine, here’s mine. My top ten governance recommendations for the technology reshaping the enterprise. Read them carefully, because there’s a catch at the end.

  1. Governance starts in the boardroom, not the server room. If your board treats this technology as an operational detail delegated to the CIO, you don’t have governance. You have abdication with extra steps. Direction, risk appetite, and investment priority are board-level decisions. ALWAYS.

  2. Assign accountability before deployment, not after the incident. When something goes wrong (and something will), “the system did it” is not an answer any regulator, court, or shareholder will accept. A named human owns every consequential decision. If you can’t name that person today, stop deploying and go find them.

  3. Tie every investment to enterprise value. Not to hype. Not to FOMO (fear of missing out). If you cannot articulate the business capability this technology serves, you’re not investing, you’re accessorizing.

  4. Manage the risk at the enterprise level, not in a silo. Technology risk that lives in its own corner isn’t managed. It’s hidden. Integrate it into your enterprise risk profile with the same discipline you apply to financial and operational risk.

  5. Demand transparency into how decisions get made. If your teams cannot explain how an outcome was produced, in language a director can actually interrogate, you have a control gap. “Trust us, it works” is not assurance. It’s hope with a budget.

  6. Keep humans accountable inside automated processes. Automation without defined human oversight points isn’t efficiency. It’s an incident report waiting for a date.

  7. Govern your data before you get clever with it. Ownership, quality, lineage, retention. Insight built on ungoverned data is just confident guessing at scale.

  8. Remember that third parties don’t absorb your accountability. You can outsource the work. You cannot outsource the responsibility. Your vendor’s failure will carry your logo.

  9. Measure outcomes, not activity. Counting deployments, pilots, and proofs of concept tells you how busy you are. It tells you nothing about whether the enterprise is better governed, better protected, or better positioned.

  10. Treat governance as a lifecycle, not a launch checklist. Evaluate. Direct. Monitor. Then do it again, because the technology you governed last quarter is not the technology running in production today.

Now, the catch. Go back and reread that list. Not one of those ten recommendations was written for AI. I never said AI. Not once.

These are the same IT governance tenets I’ve been advising boards on for years. Decades, actually. I didn’t adapt them for AI. I didn’t modernize them. I copied my own playbook, and you nodded along thinking it was purpose-built for the moment.

That’s not a gotcha. That’s the point.

These principles have already survived every “unprecedented” technology wave. Think about what enterprise IT has absorbed since the mid-1990s: the client-server shift, Y2K remediation, the dot-com surge and collapse, ERP megaprojects, offshoring and outsourcing, virtualization, cloud computing, mobile and BYOD, big data, IoT, blockchain, DevOps, the pandemic-era digital acceleration and now AI. Every single one of those arrived with the same breathless claim: “this changes everything, the old rules don’t apply.”

The technologies changed everything. The governance principles didn’t flinch. Accountability, value alignment, enterprise risk integration, transparency, oversight, data stewardship, third-party responsibility, outcome measurement, and lifecycle discipline governed the mainframe era, and they govern the model era. The load-bearing structure held. Only the decorations changed. (The skillet keeps making dinner. The juicer is in the garage.)

Which brings me to a birthday worth celebrating. COBIT turns 30 this year. ISACA released the first version in 1996 as an audit-oriented framework, and it has evolved deliberately ever since. Thirty years of emerging and disruptive technology, and the framework’s core logic hasn’t needed rescuing once. That’s not because it got lucky. It’s because COBIT was built on principles about how enterprises govern information and technology, not on assumptions about which ones they’d be governing.

That matters more right now than at any point in those thirty years, because the next wave is already visible.

So here’s my real question: do these tenets still hold water for what’s coming? Quantum computing will break and rebuild our assumptions about cryptography, computation, and risk timelines. Space-based infrastructure is moving from science project to supply chain dependency. Ambient and autonomous systems will make “where does technology end and the enterprise begin” a genuinely hard question. And somewhere beyond those is the technology none of us has even dreamed about yet… the one that will arrive with its own breathless claim that the old rules don’t apply.

My position is this: the tenets hold. Governance principles anchored to accountability, value, and risk (rather than to any technology) don’t expire when that technology does. COBIT governed I&T like it always has, it’s governing AI right now whether the vendors admit it or not, and it’s poised to do the same for whatever comes next.

Unless you can prove me wrong.

Final Thoughts

  1. If your “AI governance program” is your I&T governance program with a new cover page, that might be a feature, not a bug. The question isn’t whether the principles are new. It’s whether they’re load-bearing and not decorative.

  2. Stop waiting for a purpose-built framework before you govern emerging technology. The tenets above have thirty years of evidence behind them. Apply them now; refine them as the technology matures.

  3. Audit your governance for technology assumptions. If any of your governance structures would collapse when the underlying technology changes, they were never governance. They were configuration.

  4. Celebrate COBIT’s 30th by actually using its governance model. Evaluate, Direct, Monitor is not a slogan. It’s a discipline, and it’s aging better than most of the technologies it has governed.

  5. Keep a radar, not just a framework. Quantum, space infrastructure, autonomous systems… the principles hold, but only if someone is scanning the horizon and asking whether they still do. That someone should be you. And me.

My Call to Action

So prove me wrong. Name a future technology scenario where these ten tenets genuinely break down. Not “get harder to apply” because every wave makes them harder to apply. I mean a scenario where the principle itself fails. Drop it in the comments, and I’ll add it to my radar and write about it. That’s how governance thinking should work: pressure-tested in the open, not preserved under glass.

And if you can’t break them? Then stop building a brand-new governance program from scratch every time the technology changes. Reach for my grandmother’s skillet.

As always, thank you for reading and I look forward to your comments.