AI governance exists only when you can answer one specific question about every system in production: who, by name and role, answers for what it recommends?
If the answer takes a while, involves a committee, or ends at "the technology team," there is no governance. There is a principles document, a different thing, and one that protects nobody.
Why a principles policy isn't enough
Most organizations that "already have AI governance" actually have a list of adjectives: responsible, transparent, fair, human-centered use. Nobody is against any of it. That's exactly why it doesn't work.
Principles everyone agrees with do nothing for the moment two principles collide, which is the only moment governance is needed. Accuracy versus explainability. Speed versus review. Personalization versus privacy. Governance is the mechanism that decides which one yields, and who decides.
The four minimum elements
1. A named owner per system. Not a department: a person. With formal authority to suspend the system and an obligation to record in writing when they choose not to.
2. Classification by consequence, not by technology. What sets the level of control isn't whether the system uses a language model or a regression. It's what happens to a person if it's wrong. A model suggesting the next article and one screening résumés call for different regimes.
3. A record of the human decision, not just the output. Storing what the model recommended is easy and insufficient. What matters in an audit is what the person did with the recommendation and why, especially when they disagreed.
4. A contestation path that actually works. Anyone affected by an automated decision needs to be able to request human review and get an answer within a defined window. It's a right under Brazil's LGPD and, in practice, the most honest test of whether governance exists off the page.
If nobody has ever overridden a system, that isn't evidence the systems are good. It's evidence the override doesn't exist.
The mistake of outsourcing conscience
There's a recurring pattern: the company hires a vendor, the vendor presents its own compliance report, and the organization considers the matter closed.
It isn't. Accountability to the customer, the regulator, and the affected employee is not transferable by contract. The vendor answers to you; you answer to the world. A well-drafted contract distributes financial loss, it does not distribute responsibility.
The board's specific job
Boards don't write AI policy and shouldn't. What belongs to the board is asking three questions, regularly, and refusing vague answers:
- Which systems in production influence decisions about people, customers, candidates, employees, and who answers for each?
- In how many cases over the past year did a human reverse the automated recommendation? And what happened next?
- If one of these systems causes harm tomorrow, what is the sequence of actions in the first 48 hours?
The third question is the one that most disrupts meetings. It's also the only one that reveals whether there's preparation or just confidence.
The underlying point
Automating decisions is legitimate and, in many cases, better than isolated human judgment. What isn't legitimate is automating accountability along with it.
Systems have no fault, no intent, and cannot be held responsible. Every time an organization speaks as though the model decided, someone declined to decide, and that is the governance failure, not the model's error.
Sharing is welcome with credit and a link back to the original source.

