The Goldilocks governance problem with AI, and how to solve it
Most AI governance lands in one of three places: too tight, so capable people route around the queue; too loose, so the first review happens after something has gone wrong; or deliberately vague, so nobody has to be accountable for it. The way out is a named governance network running at three speeds, sized to what is actually at stake in each decision.
Yesterday, as I chatted with an AI platform leader at a Fortune 500 utility, he shared that his team is scaling toward 200 AI agents a quarter. (Two hundred!) He clearly wants, and needs, to move fast.
Meanwhile, their governance lead is asking him: who owns an agent after it ships? What happens when the person who built it leaves? Who notices when it drifts? And every question, despite its validity, feels like friction against his pipeline target.
The friction is what makes this worth writing about.
Like so many organizations I talk with, their organization is paying attention to governance. But the governance looks much like it did ten years ago, slow, steady, measured. AI doesn't wait for slow, steady and measured. So, how do we find the balance? The answer, I posit, is named governance networks.
Going too fast or too slow
Before we answer that, let's look at the Governance Goldilocks problem. Some organizations make governance too tight. You had an incident, or you read about someone else's, so you build an AI council with real authority and route every AI decision through it. It feels like rigor, but you've built a queue.
And who wants to wait in a queue?
Certainly not the most capable AI practitioners you have. The ones who were building things before anyone gave them permission. They route around it, or they stop. One survey found 69% of security leaders have evidence, or strong suspicion, of employees using unsanctioned AI tools at work. That's what routing around looks like.
The second position is keeping governance too loose. Governance sitting on a slide, good intentions, and nothing sitting between an idea and production. The first review happens after something has gone wrong.
The leader I was talking to identified a third position, and it wasn't "just right." It was staying vague on purpose. Admit you have questions around governance and you become accountable for having it. So some organizations write nothing down and hope. Yikes.
Using real-world decisions to guide governance
Before setting your governance in stone, have your (hopefully cross-functional) AI governance committee take ten real AI decisions you've faced this quarter and rank them. How much is at stake if this goes wrong? And how hard is it to undo?
An agent that drafts internal meeting summaries? Low stakes, easy to reverse. A practitioner can decide that on the spot. An agent that talks to customers about their bills? High stakes, hard to walk back. That one belongs at the center.
My favorite moment in this exercise is when the room counts what landed in the high-stakes, hard-to-undo corner. That pile is usually smaller than people expect. Yet it represents the workload of the governance committee. Everything else? A decision someone closer to the work could be making, if they were empowered to do so.
The impact of building a named governance network
McKinsey surveyed about 500 organizations on AI trust this year. Those with named governance owners throughout the organization scored an average maturity of 2.6 out of 5. Without it? 1.8. Like so much dealing with AI, moving from a Wild West approach to named roles and responsibilities is a hallmark of maturity.
The shape I coach organizations toward is a series of governance networks running at three speeds:
Cross-functional AI councils where they make sense. Decide where you need them. Per business unit? Per initiative? They are the ones that set purpose, understand risk appetite, and meet on a cadence that matches the speed of AI.
Functional AI councils that interpret those principles for their part of the business, monthly. Marketing's data questions aren't engineering's.
Guardrail keepers, named, front-line, who answer the day-to-day questions in the moment, at the speed of work. (Are your AI leads equipped to do this?)
Different parts of the business often require different governance. The utility leader pointed out that 9,000 employees on Copilot need a different shape than 50 engineers building custom agents. He's right.
Building your governance network shifts the conversation. Instead of spending energy debating whether AI governance should be strict or permissive, we build a flexible system that operates within the guardrails, tailored for that area of the business. Without this named system, people operate in ambiguity. We've got the licenses, we're building the agents. It's time to invest in the human infrastructure AI needs to run, with names in the seats.
Sources and further reading
- State of AI trust in 2026: Shifting to the agentic era (McKinsey).
- AI approval cycles are slowing enterprise AI adoption (NHI Management Group, citing WitnessAI).
- Where you're stuck:How do we govern the AI we've already built?
- The workshop that draws the network and designs the first layer
- Get oriented in two mornings:Running Hyperadaptive Organizations