Theme A | How to design AI governance
Who may decide what, and how far, about AI?
Should adoption of generative AI be left to field-level judgment, or governed across the company? Many executives are now stopped between these two choices. But the real issue is not whether to use it. It is governance design: which decisions are subject to whose approval. Get the design of decision rights wrong before technical evaluation, and AI becomes a fait accompli behind expense claims.
Case 02 | Telecommunications Carrier — Independent audit of an AI-model evaluation The better the numbers, the earlier they should be questioned.
Should investment in AI be evaluated only by technical precision? The issue was an evaluation of a churn-prediction AI model, but there were questions to confirm before that: overfitting risk, separation of seasonality, and data freshness. These three points were challenged first. A simple hit-rate evaluation not linked to the effect of the initiative was rejected, and a validation method was proposed on the spot.
Another issue was how to interpret the favorable figure that “customers who moved to the new pricing plan have low churn-risk scores.” If the population is limited to recent movers, the figure may be statistically unsurprising. Customers who have just moved do not churn.
A premature declaration of success was therefore put on hold. The role of questioning numbers produced by AI cannot be entrusted to AI.
Case 06 | Media Company — Designing governance gates for AI adoption An expense claim is not consent.
Adoption of a new generative-AI coding tool was becoming a fait accompli through expense claims. No one had explicitly approved it, yet it was beginning to be used. This is one of the most common governance gaps in the AI era. Before allowing the new tool to touch confidential data, the work was stopped.
Review of live code and live repositories was directed to an existing approved AI bot, while the new tool was limited to writing assistance that contained no confidential information. After designing that division of roles, the practice of treating adoption through an expense claim as “consent” was explicitly rejected.
Data scope, security, and contract terms: until the tool passed all three gates in writing, it could not touch live data. What AI may decide and what people must continue to decide: this is precisely where the boundary is drawn.