Everybody Agreed. Nobody Started.
Why the AI governance framework you adopted is still not running?
87% of organisations say they have a clear AI governance framework. Fewer than a quarter have implemented the controls described in the framework.
That gap is the subject of this essay, and it is not a gap of conviction. Nobody in those organisations is against fairness. Nobody argued for opacity or against giving people a way to challenge a decision that ruined their week. The framework was written by capable people, reviewed by capable people, and approved by a committee that agreed with every word of it.
And then, for the most part, nothing happened.
87% vs 25%
The share of organisations claiming a clear AI governance framework, against the share that has actually implemented the controls to manage bias, transparency, and security risk.
IBM, cited in AI governance benchmarking, 2026
The Finding That Explains the Gap
A study of 3,000 companies, published by UNESCO and the Thomson Reuters Foundation, sought to uncover the mechanics behind the adoption statistics. Two of its findings sit together in a way that should stop anyone who has ever signed off on a governance framework.
Only about one in six or seven companies could identify the person within their organisation responsible for the ethical risks arising across the AI lifecycle.
And for roughly three-quarters of companies, there was no evidence of a policy on the quality of the training data used by their AI.
Put those together. Most organisations cannot name who is accountable, and most have not addressed the thing the previous essay in this series called the ground on which other controls stand. These are not separate failures. The second is a consequence of the first. Data provenance did not get done because it was nobody’s — and a task that belongs to everybody, in an organisation of any size, belongs to no one at all.
A responsibility distributed across four functions is not shared. It is lost. Everyone assumes it sits slightly to their left.
The Shape of the Thing That Doesn’t Get Done
Watch how a governance framework typically arrives, because the failure is built into the delivery.
It is a single document, or a suite of them, covering the whole territory: principles, risk, data, fairness, explainability, human oversight, incident response, procurement, monitoring, board reporting. It is comprehensive. Comprehensiveness is the thing it is most proud of, and the thing that will kill it.
Because when it lands, every function reads the section that concerns it and correctly concludes that it cannot act alone. Data governance needs engineering. Engineering needs the model standard. The model standard needs the risk appetite. The risk appetite needs the board. The board needs a paper from the executive who is awaiting the operationalisation of the framework. Everybody is waiting for a prerequisite that belongs to someone else, and every one of them is being reasonable.
So the framework is adopted in the specific sense that a committee has agreed on it and it now exists. And nothing about how any decision gets made on Tuesday has changed.
This is what I mean by a monolith. Not that it is long — length is fine — but that it has no entry point. It cannot be started, only completed, and so it is never started.
Divide by Owner, Not by Topic
The instinctive fix is to break the framework into pieces, and organisations do this constantly. They almost always break it the wrong way.
The wrong way is by topic. A fairness workstream, an explainability workstream, a data workstream, a monitoring workstream. It looks like decomposition, and it changes nothing because a topic is not something anybody owns. Fairness is not a department. It has no budget, no head, no seat at the executive table, no line in anyone’s objectives. A fairness workstream is a coordination problem with a name — it needs the data people, the modelling people, the risk people, the legal people, and the business owner, none of whom report to it. You have not divided the work. You have divided the document and left the work exactly where it was.
The right way is by an accountable owner. Cut the framework along the seams that already exist in the organisation — the places where authority, budget, and a named executive already sit. Not fairness and explainability, but the thing the board must decide and cannot delegate. The thing the risk function enforces before deployment. The thing the technology function builds into the pipeline. The thing the general counsel owes to a regulator. The thing procurement must extract from a vendor before signing. The thing that the operating business runs every day.
Each of those already has a name associated with it. Each has a budget. Each can begin on Monday without waiting for the others, since the owner has the authority to start.
Divide governance by topic, and you get a coordination problem nobody owns. Divide it by owner, and you get a set of programmes that can each begin on Monday.
Why the Seams Matter More Than the Content
This is not an argument about how to organise a filing cabinet. The seams determine whether anything moves, and they do so for three reasons unrelated to the quality of the governance content.
Different owners move at different speeds. A board sets risk appetite annually. A technology function ships fortnightly. A procurement cycle turns over when a contract renews. A framework that requires all three to move in lockstep moves at the pace of the slowest, which in practice means it does not move. Cut along the ownership seam, and each part runs at its natural clock. The board can ratify a prohibition list while engineering is still building the logging standard, and neither is blocked by the other.
Different owners respond to different pressures. The general counsel is under pressure due to regulatory exposure. The technology executive is driven by delivery. The chief risk officer is pushed by the board. These pressures are real, and a framework that ignores them fails; a framework that follows the ownership seams can attach each obligation to the pressure that will actually cause it to be honoured.
And an owner can be held to it. This is the decisive one. The whole series has argued that governance without a named accountable human is theatre — the royal commission that had to excavate who was responsible; the vendor’s data scientist who chose the fairness metric; the reviewer with no authority to overturn. A framework divided by topic reproduces exactly that failure at the level of the framework itself. It creates obligations with no owner and then expresses surprise when they are not met.
Separable, Not Fragmented
There is an obvious objection here, and it is the right one: this sounds like a recipe for fragmentation. Six separate programmes, six owners, six interpretations, six sets of thresholds, and an organisation whose AI governance is a patchwork that agrees with itself nowhere.
That objection is correct about the risk, and it identifies precisely what has to be got right. Separability without a spine is fragmentation. What prevents it is that the division occurs in only one layer.
Divide the doctrine. Unify the enforcement.
The constitutional layer — what the organisation will not do, what its risk appetite is, who is ultimately accountable — is single, board-owned, and a prerequisite to everything else. It is not one of the divisible pieces. It is the root from which the divisible pieces derive their authority, and no workstream may contradict it or reinterpret it locally.
And at the other end, the enforcement point is single too. One gate that a system must pass before it goes into production. One register of what is deployed and under whose authority. One escalation path when something breaks. One board line where it is all reported. The workstreams feed that gate; they do not each build their own.
What is divisible is the middle — the standards, the processes, the tooling, the day-to-day machinery of each domain. That can proceed at six different speeds, under six different owners, with six different budgets, and still compose, because everything at the top is common and everything at the bottom converges.
Divide the doctrine, unify the gate. Anything that divides the enforcement point does not decompose the framework. It has abandoned it.
What This Buys You
Consider what becomes possible once the division follows ownership.
An organisation can start where its pain is. A general counsel exposed to regulatory explainability can build that, alone, now, without waiting for the fairness programme to be scoped. A technology executive who knows the deployment gate is the real problem can build the gate. A board that has looked at the last three essays in this series and gone slightly pale can ratify a prohibition list and a set of accountability assignments in a single meeting, and that ratification is immediately load-bearing for everything built afterwards.
And they can run in parallel, because none of them is a prerequisite for the others except the constitutional layer, which is a prerequisite for all of them and takes a board meeting rather than a programme.
This is the difference between a framework that yields value on a horizon of weeks and one that yields nothing until the day it is finished — which, since it is never finished, is never. The evidence bears this out plainly: the organisations with the highest governance maturity are consistently those with clear, assigned ownership. Not the ones with the best documents. The ones where somebody’s name is against the thing.
The Honest Cost
This approach has a price, and a framework author who claims otherwise is selling something.
Six owners mean six interpretations to reconcile, and reconciliation is work that a monolith does not require. There will be duplication at the boundaries — two workstreams both touching model documentation, two both touching vendor obligations — and someone senior has to arbitrate when they collide. The common layer at the top and the common gate at the bottom have to be maintained against six programmes that will, under delivery pressure, each be tempted to build a local variant that suits them better. That temptation has to be refused every single time, because the first exception is the end of the architecture.
That is real overhead, and it is the price of adoptability. The monolith has none of it — no boundary disputes, no reconciliation, perfect internal consistency — and it achieves this by never being implemented. An internally consistent framework that nobody has started is not a superior artefact. It is a document.
Everybody Agreed
Return to the number this essay opened with, because it is not really a statistic about frameworks. It is a statistic about how organisations fail to act on things they sincerely believe.
Eighty-seven per cent have the framework. Fewer than a quarter run it. Nobody in that gap is a villain — and by now that sentence should sound familiar, because it has been true of every case in this series. Nobody at 7-Eleven decided to conduct biometric surveillance on 1.6 million customers. Nobody at Northpointe set out to double the false-positive rate for Black defendants. Nobody in the Dutch tax authority intended to take 1,600 children from their parents. Nobody downloaded child abuse material on purpose.
In every case, the harm occurred through a gap where a named human being should have been standing, and in every case, the organisation had documents stating otherwise.
The framework is not the governance. The framework is a description of governance that someone still has to build — and they will only build it if the thing they were handed can be started by someone with the authority to do so on a Monday, without permission from four other people who are all waiting for each other.
Everybody agreed. That was never the hard part. The hard part is that agreement, distributed evenly across an organisation and attached to nobody in particular, is indistinguishable from nothing at all.
References
This piece draws on published survey research into AI governance adoption and implementation.
UNESCO and Thomson Reuters Foundation. Responsible AI in Practice: 2025 Global Insights from the AI Company Data Initiative. Based on public data from 3,000 companies, collected July–November 2025.
McKinsey & Company. State of AI Trust in 2026: Shifting to the Agentic Era. AI Trust Maturity Survey, approximately 500 organisations, December 2025 – January 2026.
PwC. 2025 US Responsible AI Survey. Survey of 310 US business leaders, September–October 2025.
AuditBoard. From Blueprint to Reality: Execute Effective AI Governance in a Volatile Landscape. Survey of over 400 GRC and audit professionals, 2025.
Stanford Institute for Human-Centered AI. AI Index Report 2026, Responsible AI chapter.


