The AI Decisions You're Already Making

Part 1: Why you're doing this, and who's actually deciding

Most businesses don't lack AI governance because nobody's thought about it. They lack it because several reasonable decisions get made separately, by different people, each one sensible on its own, with nobody stepping back to check whether they add up to a coherent position.

This is the first of three short pieces working through that idea. Not a checklist, and not a warning about AI itself; just a set of questions worth asking honestly, because the answers are usually more interesting than "we haven't really discussed it."

Why is your business actually doing this?

Ask several people on a leadership team why AI matters to the business, and you'll likely get several different, perfectly genuine answers. One is responding to pressure from above, a parent company, a board, an expectation that's already been set, whether or not they'd have chosen this path themselves. Another is watching competitors and partners move and doesn't want to be left behind. Another is looking at a stretched team and a tight budget and sees a way to do more with what they've got. Another is just genuinely excited about what this could become.

None of these people are wrong, and none of them are lying. But "keep up with competitors," "do more with a smaller team," and "this could be transformative" point toward different decisions when it actually matters: different risk tolerances, different timelines, different definitions of what success even looks like.

A board mandate and genuine enthusiasm can sit in the same person at once; pressure from above doesn't make someone's belief in the work any less real. But it's still worth knowing which one is actually steering, because a plan built to satisfy a mandate looks different from one built to chase a competitor, which looks different again from one built to free up a stretched team.

If a leadership team has never compared answers to this out loud, it's worth doing before the next AI decision gets made. Not because any answer is wrong, but because a business moves differently depending on which one is actually in charge.

Who's actually deciding when AI gets to act?

Most businesses already have an answer to "does a human check this before it happens." A plan gets reviewed before anything's built. A person triggers the final step before anything reaches production. AI can read what it needs to, but writing or changing something usually still needs a person to approve it, or is deliberately kept out of reach altogether.

That's a sound starting position, and it's more thought-through than it might sound. But it usually rests on one assumption: that AI fits into the same accountability structure already used for people. Someone owns the system. Someone's accountable if a person uses a tool badly. The assumption is that this holds just as well once the thing acting isn't a person checking each step, but something making the step itself.

Plenty of leadership teams treat fully autonomous action as a future conversation, one worth having properly once it's actually relevant, not yet. That's a reasonable instinct. The honest follow-up question is whether it's still as far off as it was when that decision got made, because the technology isn't waiting for the next time it comes up on an agenda.

None of this means slamming the brakes on every AI tool that can take an action. It means being honest about where the line currently sits, who actually agreed to it, and putting a date on when someone looks at it again, rather than leaving "we'll deal with that later" to become "we already did, without meaning to."


Next: where the risk actually hides → Part 2: The risk isn't where you're looking


Ed Ball is Head of Data, Security & Service Management at a regulated UK lender, and the founder of Sapien Solutions.

Previous
Previous

The AI Decisions You're Already Making