← Back AI

AI: The Serious Phase | Part 2

25 September 2026 · amy_doughty26 · 9 min

AI Governance

AI needs its own SDLC

Drowning in manual, repetitive work? Tell us the task and we’ll show you what to automate.

Structural AI governance is less comfortable than policy governance, because it’s specific and involves skills and experience that most businesses are still acquiring. A policy can stay vague forever. Let’s face it, the term “Use AI responsibly” doesn’t offend anyone and doesn’t really commit anyone to anything much. Whereas actual configuration forces decisions such as: which tool can access what data; which agent can take what action; which accountable person owns which outcome. You first have to make those decisions in the configuration stage, and then somebody has to be able to defend them later.

That’s exactly why most businesses haven’t done it yet. It’s genuinely easier to write a policy than it is to configure and enforce one. But easier isn’t the same as sufficient, and those that get caught out won’t be the ones without a policy. They’ll be the ones who had a very well-written policy but their systems didn’t actually uphold any of it.

If the AI exploration phase was about proving the tools could work, governance is where the serious phase actually begins. It’s the first pillar for a reason: none of the other four, literacy, tokenomics, lifecycle, orchestration, mean very much if you can’t answer basic questions about what your AI is allowed to do and who’s accountable when it doesn’t.

The policy document isn’t wrong. It’s just nowhere near enough.


← Back