
There were several aha moments, including a conversation where we discussed the responsibility of an outcome from the agent which was building a prototype for the students. This prompted me to reflect on a broader question: as AI systems become increasingly autonomous, how do organisations ensure they remain accountable for the outcomes.
When I was a budding information technology student, the BOFH (from the website of The Register (UK)) was a fascinating character. There were many funny tales about the divide between knowledgeable system administrators and clueless users; and a common theme was how, as far as computer issues are concerned, the error is often located between the chair and the keyboard. Indeed, system users can find fascinating ways to use technology resources, which readers will find to be an excellent transition to the specification and design: surely, if business analysis, solution architects and system designers implement all possible guardrails, then material issues will not happen.
Even if this was true – what about basic tools available in any corporate organisations, such as an access to the Internet and Excel? Safeguarding in this case comes with governance and risk controls on acceptable behaviours. Those controls were intended not to stifle innovation, but to establish the defence of the perimeter for the organisation.
The parallel is easy to make with AI – conceptually a powerful tool, how can we make sure that it is wielded safely? Traditional governance and project management practices used throughout software delivery lifecycle are still useful, but not sufficient to address the potential risks coming from using AI:
The extent to which effective governance should be built has to correspond to the risk appetite of the organisation. Organisations which are using sophisticated decision-making or classification AI models, or using GenAI to derive insights from internal data will need solid guardrails and governance. On the other hand, if the organisation allows use only for brainstorming and productivity, governance needs will be lighter touch, just focusing on appropriate usage of tools and data classification.
There was a saying years ago that “Machine Learning is usually coded in Python, AI in Powerpoint”. Since then, AI capabilities have developed at a furious speed; and using them in the corporate world can be a significant competitive advantage in many situations such as reacting quickly to events or having a more meaningful relationship with customers – that is, as long as its use is governed effectively and its adoption is anchored in a strategy which evaluates any other commitments and impacts on risks, such as conduct, privacy or climate risk.
Perhaps the biggest misconception about AI governance is that it is something entirely new. In reality, many of its foundations, accountability, controls, risk management and oversight have existed for decades. What has changed is the scale, speed and autonomy with which AI systems can operate. The challenge for organisations is not to reinvent governance, but to adapt it.

There were several aha moments, including a conversation where we discussed the responsibility of an outcome from the agent which was building a prototype for the students. This prompted me to reflect on a broader question: as AI systems become increasingly autonomous, how do organisations ensure they remain accountable for the outcomes.
When I was a budding information technology student, the BOFH (from the website of The Register (UK)) was a fascinating character. There were many funny tales about the divide between knowledgeable system administrators and clueless users; and a common theme was how, as far as computer issues are concerned, the error is often located between the chair and the keyboard. Indeed, system users can find fascinating ways to use technology resources, which readers will find to be an excellent transition to the specification and design: surely, if business analysis, solution architects and system designers implement all possible guardrails, then material issues will not happen.
Even if this was true – what about basic tools available in any corporate organisations, such as an access to the Internet and Excel? Safeguarding in this case comes with governance and risk controls on acceptable behaviours. Those controls were intended not to stifle innovation, but to establish the defence of the perimeter for the organisation.
The parallel is easy to make with AI – conceptually a powerful tool, how can we make sure that it is wielded safely? Traditional governance and project management practices used throughout software delivery lifecycle are still useful, but not sufficient to address the potential risks coming from using AI:
The extent to which effective governance should be built has to correspond to the risk appetite of the organisation. Organisations which are using sophisticated decision-making or classification AI models, or using GenAI to derive insights from internal data will need solid guardrails and governance. On the other hand, if the organisation allows use only for brainstorming and productivity, governance needs will be lighter touch, just focusing on appropriate usage of tools and data classification.
There was a saying years ago that “Machine Learning is usually coded in Python, AI in Powerpoint”. Since then, AI capabilities have developed at a furious speed; and using them in the corporate world can be a significant competitive advantage in many situations such as reacting quickly to events or having a more meaningful relationship with customers – that is, as long as its use is governed effectively and its adoption is anchored in a strategy which evaluates any other commitments and impacts on risks, such as conduct, privacy or climate risk.
Perhaps the biggest misconception about AI governance is that it is something entirely new. In reality, many of its foundations, accountability, controls, risk management and oversight have existed for decades. What has changed is the scale, speed and autonomy with which AI systems can operate. The challenge for organisations is not to reinvent governance, but to adapt it.