AI Governance: How to Govern AI Before It Governs Us
Most boards are still debating whether to adopt AI. Meanwhile their staff are already using it to draft emails, summarise reports and shape decisions. That gap is the whole problem. The question isn't whether AI is coming into your organisation. It's already here. The real question is whether anyone is actually governing it.
In Episode 10 of The Future State, we sat down with an AI governance and cyber security consultant with over 15 years across IT audit, risk, security operations and AI security. He's the author of Governing AI Before It Governs Us, and his argument is simple: accountability for AI cannot be outsourced. Not to a vendor, not to your technical teams, not to a policy you wrote once and forgot about.
What does AI governance actually mean?
AI governance is about putting structures, policies, accountability and oversight in place before AI systems get adopted, deployed or scaled. It means defining what an AI system is allowed to do, what it must never do, who owns its outcomes, how those outcomes get monitored, and when the thing should be switched off.
That's it. It's not a philosophy exercise. It's a set of questions you answer before deployment:
- What problem are we trying to solve with AI, and is AI even the right tool?
- What data are we training it on?
- Who is affected by the decisions this system makes?
- Can we explain the decisions it produces?
- How do we know when it's doing the wrong thing?
- Who is accountable if it causes harm, and when do we review it?
Here's what leaders miss. Governance is not anti-AI. It's pro accountability. Think of a Formula One car. Nobody wants a car that's all brakes and goes nowhere. But a car with no braking system is a disaster waiting to happen. A safe, fast car has both. AI governance is the braking system.
Why AI governance is a board-level job, not a technical one
In too many organisations, AI governance is an afterthought that gets handed to technical teams. But those teams often aren't skilled in governance, and honestly it isn't their responsibility either. Governance has to live at the board and executive decision-making level.
That means AI risk needs to be explained in non-technical language. The board doesn't need to understand transformer architecture. They need to understand the risk clearly enough to govern responsibly and drive compliance across technical, legal and operational teams. Governance drives the decisions. It drives the technology response and the outcomes you get.
The machine that moved in without knocking
AI enters organisations in two ways. Sometimes it's deliberate. A CEO comes back from a conference where vendors pitched efficiency gains, cost reduction and better fraud detection, and Monday morning the instruction goes out: we're implementing AI. Cost and efficiency become the success factors, and everything else gets rushed.
The second way is quieter, and more dangerous. AI is already baked into the everyday tools your people use: word processors, spreadsheets, email, productivity software. On top of that, staff have gone and bought paid versions of popular AI tools out of their own pockets just to get their work done faster. Nobody signed off on it. Leadership doesn't even know it's happening.
That's shadow AI.
What is shadow AI, and why should leaders care?
Shadow AI is when AI is being used inside your organisation and you have no track of it. It's different from traditional shadow IT in one important way. Most old shadow IT tools are deterministic: same input, predictable output. AI is non-deterministic, and it runs on data. Constantly.
So if you've got shadow AI, you can't track the extent of data leaving your organisation, and you don't know where it's being stored. For a regulated business, that's a serious problem. Under GDPR and similar data protection rules, some data is only allowed to sit in certain jurisdictions. Feed it into a random AI tool and it can quietly move across borders, and now you've got regulatory and legal exposure you never agreed to.
The real dangers of ungoverned AI
A few things go wrong fast when nobody's watching.
Privacy breaches. A staff member who's had no training on AI ethics just wants a nicely formatted email. So they paste in company data, maybe personal identifiable information, maybe confidential material, into a public tool. That information has now left your control. If you hold it under non-disclosure or privacy agreements, that's a breach.
Automation bias. People start treating AI output as gospel. They don't realise the output can contain errors, so they make real business decisions off it without checking. That quietly poisons the quality of decisions across the whole organisation.
And remember how fast this arrived. Mobile phones took 16 years to reach 100 million users. The internet took about seven. ChatGPT did it in two months. AI is moving at a speed we've never seen before, and because of the kinds of decisions it influences, we need our thinking caps on.
Should you just ban it all?
When leaders finally wake up to shadow AI, the instinct is often to ban everything. No ChatGPT, no Gemini, nothing. That's the wrong move. AI is a necessity now, and an outright ban just pushes usage further underground.
This is exactly where governance earns its keep. Instead of banning, you decide as an organisation what you actually need AI for, how it should support your processes, what type of AI is appropriate, and what guardrails apply. Then you train people, set the rules, and monitor. You wake up and smell the coffee: AI is already in the building. Your job is to give it a licence to operate on your terms.
The takeaway for leaders
The title of the book is deliberate. It's not saying AI might govern us one day. It's saying AI is already shaping decisions, choices, processes and opportunities right now, and the open question is whether leadership has caught up.
So start with ownership. AI accountability sits with you, not with a vendor or a technical team. Explain the risk in plain language. Find your shadow AI. Decide what you're using AI for and why. And build the braking system before you go full speed.
If you lead an organisation and you're not sure who's actually accountable for your AI systems, that's your answer. Nobody is. Yet.
Listen to Episode 10 of The Future State for the full conversation, and subscribe at thefuturestate.net for more on AI governance, law, leadership and the decisions shaping our institutions.
Frequently asked
What is AI governance in simple terms?
AI governance is the set of policies, controls and accountability that decide what an AI system is allowed to do, who is responsible for its outcomes, and when it should be stopped. It's put in place before AI is deployed, not after something goes wrong.
What is shadow AI and how is it different from shadow IT?
Shadow AI is the use of AI tools inside an organisation without leadership's knowledge or approval. Unlike traditional shadow IT, AI is non-deterministic and runs on data, so you often can't track what information is leaving the business or where it ends up, which creates privacy and regulatory risk.
Should organisations just ban tools like ChatGPT and Gemini?
Banning everything usually backfires and drives usage underground, and AI has become a practical necessity. A better approach is governance: decide what you need AI for, set clear rules and guardrails, train staff, and monitor usage rather than pretending it isn't happening.