Authority has to be engineered. It is never inherited.
Most AI governance work produces a policy. A policy cannot tell you which account performed an action at three in the morning, or whether that action can be reversed. Only the design can do that.
The useful work is a series of explicit decisions about what each system is allowed to do, made before it is connected rather than after something surprising happens.
- AI is in use across the organisation and nobody can list where.
- A team wants to connect a model to real systems and real data.
- An agent is being given the ability to act, not only to answer.
- The board has asked who is accountable when it is wrong.
- Confidential material is moving through tools nobody approved.
- AI spend is growing and nobody can attribute it to an outcome.
Why a policy is not enough
Most organisations arrive at AI governance through a document. The document says use must be responsible, data must be protected, and staff must exercise judgement. None of that is wrong, and none of it survives contact with a system that can act.
The moment software can open records, call tools or change data, the questions become operational. Which identity performed that action. What it was permitted to reach. Whether anyone can reconstruct the sequence afterwards, and whether it can be undone. Those are answered in design, permissions and logging, not in a paragraph about responsible use.
The other reason to do this early is cost. Deciding what a system may do before it is connected takes an afternoon. Establishing it afterwards means unpicking integrations that people already depend on, usually while explaining to somebody why it is urgent.
What is actually running
An inventory of the systems, the people who own them, and the data each one can reach. Most organisations are surprised by this list.
What each system may do
Read, summarise, recommend, prepare, act with approval, act within limits. Six different levels of trust, routinely granted as one.
Where the information goes
Which suppliers are involved, what they retain, in which jurisdiction, and whether any of it trains something else.
What is recorded
Which model answered, which tools it called, what it read, and what changed as a result. Without the last of those, an investigation can describe intent but not effect.
How it stops
Withdrawing an authority, reversing what was done with it, and knowing in advance that both actually work.
What it costs
Which tasks justify an expensive model, which do not, and whether the spend can be tied to anything a finance function would recognise.
- An authority model: what each system may see, suggest, prepare and carry out, and where a human sits in that chain.
- The supplier picture, including what would be involved in replacing one.
- The gaps that matter, ranked, with the ones that are cheap to close now and expensive to close later marked as such.
This is technical and governance work. Where regulation is involved, interpreting it is a job for qualified counsel, and I will say so rather than improvise.
Why me for this
The six levels of authority, and what each one buys and costs, are set out in full on the AI page. It is the framework this work uses.
See the six levels of authorityRelated
The useful time for an independent view is before the decision becomes difficult to reverse.
Two or three lines are enough: what is happening, what decision is coming, and when it matters. You do not need to know which kind of engagement this is. LinkedIn is the single route in, on purpose.