Where you're stuck

How do we govern the AI we've already built?

In most organizations, the building came first, and governance shows up after the apps and agents are already running. What catches up is a dynamic governance model: a network of people close to the work who apply guardrails to what's already built and keep them current as the models change.

Meanwhile the pile keeps growing. Teams ship new agents every week, the models change every few months, and each one widens the gap between what's running and what anyone has decided about it. Closing that gap is smaller work than it looks: one 90-minute session puts real names in the seats of your governance network, and you can announce it Monday.

What you've built

You have an AI policy, probably a council, and training your people completed. Legal signed off. That took work, and it gives you a place to start.

The thing most likely holding you back

Governance has everyone a little frozen. Builders aren't sure what they're allowed to ship. The people asked to govern are looking at hundreds of apps and agents that already exist. The usual playbook would stop the building cold, so nobody wants to start there. Meanwhile, the agents keep shipping.

Try it

Where do AI decisions get made in your organization?

Pick the one that's true today, then send this page to five colleagues and ask them the same question.

What I hear from AI leaders

Questions AI leaders are asking about governance

Who's in charge of that agent, and where's the audit log?

Which AI uses can a team approve on its own?

How do we keep the rules current when the models change every few months?

When everything waits in one queue

The usual fix is the governance you already know: write the policy, stand up a council, add an approval step. Point that at hundreds of apps and agents that already exist and everything waits in one queue. Builders either stop or go around it (wouldn't you?).

Governance platforms help, and you'll probably want one. They record what exists and enforce what's already been decided. Someone in each business area still has to decide whether a new use is low-risk or needs a closer look, and that person needs the context to make the call.

What waiting costs

One in five organizations reported a breach caused by shadow AI. Organizations with high levels of shadow AI paid an average of $670,000 more per breach. Source: IBM Cost of a Data Breach, 2025 (600 organizations, Ponemon Institute)

A quarter of large US public companies can't detect unauthorized AI agents running inside them. Source: EY US AI Risk and Governance Survey, September 2026 (200+ senior AI decision-makers)

Nearly every large US public company (98%) has a formal AI governance policy, and 47% have bypassed their governance process for urgent deployments. Source: same EY survey

The upside: organizations with clear ownership for responsible AI average a maturity score of 2.6, against 1.8 for those without it. Source: McKinsey, State of AI trust in 2026, March 2026 (about 500 organizations)

From the field

Governance arriving after the build

A platform and site reliability engineering lead at an IT Revolution roundtable described governance arriving uninvited, after his team had already built 15 apps.

A Fortune 500 utility has more than 6,000 agents in production, and someone there is just now starting to think about governance.

A fintech payments platform drew its own line: teams run their own use cases freely, and changes to core processes go to the steering board. They designed that threshold themselves, and that's dynamic governance.

Try this with your governance group

Sorting AI decisions by stakes

Take ten real AI decisions your organization faced this quarter and rank each one on two questions. How much is at stake if it goes wrong? How hard is it to undo?

An agent that drafts internal meeting summaries is low stakes and easy to reverse, so someone close to the work can decide on the spot. An agent that talks to customers about their bills is high stakes and hard to walk back, so it goes to the Central AI Council.

The high-stakes, hard-to-undo pile is usually smaller than people expect. That pile is the council's workload, and the rest can be decided closer to the work.

Sorting AI decisions by stakes and reversibility A two-by-two grid. The vertical axis runs from low to high stakes, the horizontal axis from easy to hard to undo. Only the high-stakes, hard-to-undo corner goes to the Central AI Council. High-stakes decisions that are easy to undo stay with a function, with a check-in. Low-stakes decisions that are hard to undo stay with a function. Low-stakes, easy-to-undo decisions are answered by a practitioner on the spot. An agent that drafts internal meeting summaries sits in the low, easy corner. An agent that talks to customers about their bills sits in the high, hard corner. CENTRAL AI COUNCIL A function holds it, with a check-in A practitioner answers on the spot A function holds it Agent that talks to customers about their bills Agent that drafts internal meeting summaries Easy to undo Hard to undo Low stakes High stakes
From The Goldilocks Governance Problem with AI

Start here

Give governance a network

Right now

Hundreds of apps and agents are running, governance is just getting started, and everyone's waiting to see what the rules will be.

With this move

A Central AI Council sets the guardrails, Functional AI Councils translate them for each part of the business, and Guardrail Keepers on every team answer questions in the moment. The rules get refreshed as the models change.

The governance network Three layers. A Central AI Council at the top sets the guardrails. Below it, Functional AI Councils for areas such as marketing, finance, operations and HR translate the guardrails for their part of the business. At the bottom, Guardrail Keepers on every team answer questions in the moment. Lines connect each layer to the one below. Central AI Council Marketing Finance Operations HR Sets the guardrails Functional AI Councils Translate them Guardrail Keepers Answer questions in the moment Functional areas shown as examples

The Governance Network Workshop

In 90 minutes, your team sorts the AI decisions you're facing by stakes, puts real names in each seat of your governance network, and drafts the announcement before anyone leaves the room. You walk out with a named network on one page and a date for its first checkpoint. Later, the same network carries AI learning and the agent lifecycle through the 90-Day Activation Hub.

Designed by Melissa Reeve, delivered by a Hyperadaptive delivery partner.

Questions about governing AI

What is AI agent governance?
It's how an organization decides who can build, use and change each AI agent, how its output gets checked, and when a new use needs a closer look. It works best as a network: a Central AI Council sets the guardrails, and people in each part of the business apply them to the agents their teams run.
How do you govern AI agents that are already in production?
Give each one an owner in the business that uses it, then sort them by risk. Low-risk agents keep running under the guardrails, and anything that touches a core process gets a closer look.
Do we still need an AI policy?
Yes. The policy gives the guardrails their starting point. The network puts it to work in each team and tells you when it needs to change.
How does governance keep up when the models change every few months?
The refresh is built into the network. People close to the work spot new uses as they appear and send them up for a decision, so nobody waits for the next policy review.