Ask a board how mature its AI governance is and you will get a noun back: a policy, a framework, a slide with a maturity score on it, usually somewhere around 7 out of 10, because nobody ever marks their own governance a 4.
Governance is not a thing an organisation has, it is a thing an organisation does, specifically what it does the next time an AI system creates a problem nobody planned for.
Business ethics research on corporate responsibility gives a useful four-step ladder for what that doing actually looks like.
- Reaction is denying there is a problem until the evidence makes that impossible.
- Defence is doing the minimum required to make a specific complaint go away, then moving on.
- Accommodation is complying once a rule requires it, no earlier, no further.
- Pro-action is getting ahead of the obligation before anyone forces the issue.
Most of the organisations we meet believe they are somewhere near the fourth rung. Most of them are actually running a fairly disciplined version of the second…
Current only flows one way in a defensive posture: everything is wired to limit exposure, nothing is wired to actually conduct the judgement well. You can tell the difference from the outside faster than you would think.
- A pro-active function can describe, unprompted, the last AI decision it changed its mind about.
- A defensive one can only describe the last complaint it closed.
Our free self-audit’s four bands, no function yet, informal and exposed, defined but not evidenced, established, map onto roughly the same ladder, and the Organisation Toolkit is the fastest route: not because a document makes you pro-active, but because a charter, a reporting line, and a named owner are what pro-action actually requires in order to happen.