By Barry Lewington | Bushey
There is a pattern I have watched repeat itself throughout my career.
A technology ‘fad’ arrives and the early adopters make compelling noise, the boardroom takes notice, budgets get unlocked, and everyone starts running. The problem is that most organisations run before they have decided where they are actually going, or who is responsible if they fall.
We are living through exactly that cycle right now with artificial intelligence, and the stakes are considerably higher than they were with previous waves of technology.
Let me be direct about something.
The question for most organisations in 2026 is no longer whether to use AI.
That debate is largely settled and has sailed into the sunset.
The real question is who owns it when something goes wrong, and the honest answer, in more organisations than I would like to admit, is nobody. They will always find someone and he/she is probably running IT just now.
Spending on AI tools has accelerated sharply, with deployments moving into the pilot stage.
Teams across finance, HR, customer service, legal, and operations are using AI-assisted tools daily, often without any coordinated oversight from above, driven by the promise of quick wins against competitors even if the risk is increased.
On the surface, this looks like innovation.
Look a little closer and what you frequently find is a collection of ungoverned, unconnected AI initiatives operating beneath whatever formal policy the organisation has managed to put on paper.
I have spoken with technology leaders at organisations of all sizes over the past 18 months, and a consistent theme emerges. They know AI is being used more broadly than they have sanctioned, and they know data is flowing into third-party models in ways that may not be consistent with their privacy obligations.
They are fairly certain that some of those AI outputs are being used to support decisions without any human review, and yet the pace has not slowed, because the pressure to deliver results with AI is coming from the very same people who should be asking the harder governance questions.
That is the gap.
Not a gap in ambition or capability, but a gap between the speed of deployment and the maturity of the controls surrounding it.
Now, governance is one of those words that gets used so broadly it risks becoming meaningless. In the context of AI, I think about it in three practical dimensions – accountability, auditability, and alignment.
Accountability means that for every AI system in production, there is a named individual whose responsibility it is to understand what that system does, what data it uses, what decisions it influences, and what the consequences of failure look like.
Not a committee, but a person, and if that person leaves then that role is reviewed and redefined.
Auditability means that you can, at any point, reconstruct why an AI-assisted decision was made, trace the inputs that shaped it, and demonstrate that the process met your stated standards.
In regulated industries this is not optional, but even outside of regulation it matters enormously.
When a customer, an employee, or a regulator asks you to explain an outcome, ‘the model suggested it’ is not an answer that will serve you well.
Alignment means that your AI systems are actually doing what you think they are doing, and that what they are doing reflects your organisational values, your risk appetite, and your obligations to the people affected by those decisions.
Alignment is the hardest of the three because it requires ongoing attention, and Models continually drift.
Data changes.
The world changes. An AI system that was aligned six months ago may not be aligned today, without active monitoring you will not know until something has already gone wrong. Business operational decisions about the implementation of AI in the business are being made based on an understanding of traditional applications and not on the sound understanding of agentic AI.
One of the more encouraging shifts I have observed recently is AI governance beginning to find its way onto board agendas. For a long time it lived entirely within IT, or within a small AI team, or within legal and compliance as a secondary concern. That was never sustainable.
Board-level ownership matters for a straightforward reason. The risks that emerge from ungoverned AI are not technical risks. They are reputational risks, regulatory risks, and ethical risks. They are exactly the kind of risks that boards exist to manage. A data breach caused by an AI system that was processing personal information in ways the organisation had not approved is not a technology problem. It is a governance failure.
The same is true of bias. If an AI system used in recruitment, credit assessment, or resource allocation is producing outcomes that disadvantage a particular group, and no governance mechanism exists to detect and challenge that, the organisation is exposed. The fact that a machine made the decision does not provide cover.
Here is what I genuinely believe will separate the organisations that succeed with AI at scale from those that do not. It is not the sophistication of the models they use. It is not the size of the data sets they have access to. It is the maturity of the framework they have built around their AI investments.
Governance is not a brake on AI adoption. Done well, it is an accelerant. Organisations that can demonstrate to their customers, their partners, their regulators, and their own employees that AI is being used responsibly will move faster and with more confidence than those that cannot. They will have fewer costly incidents to manage. They will face fewer regulatory obstacles as AI legislation matures across different markets. They will be trusted with more sensitive use cases because they have earned that trust.
So where do I start?
If your organisation is somewhere in the middle of this, you have deployed AI broadly but your governance has not kept pace, the starting point is an honest inventory. Know what AI systems are in use, who is using them, what decisions they are influencing, and what oversight exists. From that baseline you can start to build the accountability structures, the monitoring processes, and the policies that turn a collection of individual AI experiments into a coherent, controlled programme.
This is not a small task. But the alternative of continuing to scale AI faster than you can control it and hoping the gap does not catch up with you is a risk that no board should be comfortable accepting.
The gap is real. The question is whether you close it deliberately, or whether something closes it for you.
Barry Lewington is a technology strategist and Managing Director at Bushey, working with organisations across the UK to align their technology investments with business outcomes. He has been writing and speaking about enterprise technology for over 25 years.

Comments are closed