Every leadership team considering AI eventually reaches the same question: which governance framework should we adopt?
It sounds sensible. It is also the wrong place to start.
The AI governance landscape is confusing because very different things share the same label. Some frameworks set ethical principles. Some organise risk. Some define a management system. Some focus on technical security. Some are laws, not frameworks at all. None of them, on its own, tells an organisation how decisions should be made, how controls should fit into delivery, or how responsible AI becomes normal business practice.
Organisations that treat AI governance as a framework-selection exercise often end up with a polished policy, a new committee and very little change in how AI is actually chosen, built, bought or used.
The category error behind the framework debate
The framework debate is often treated as a selection exercise: which one should we adopt? But that creates a category error. The sources being compared are not alternatives. They govern different parts of the problem.
Principles set intent. Risk frameworks help organisations judge exposure. Management standards turn accountability into repeatable practice. Regulation establishes legal obligations. Security guidance addresses technical failure and attack. None can replace the others.
A finance function would never choose between accounting standards, tax law, risk appetite and internal controls. Each plays a different role within one functioning system. AI governance should be approached in the same way.
The first shift in thinking is therefore simple: stop shopping for a single framework to adopt and start designing how the different layers will work together.
What belongs in the governance stack?
The precise combination will depend on sector, geography, business model and risk exposure. But most organisations need six distinct layers.
- Principles and appetite. What does responsible use mean here? What outcomes are we pursuing, and what are we unwilling to accept?
- A management layer. How are policy, accountability, objectives, review and continual improvement made repeatable across the enterprise?
- Risk and impact. How will the organisation understand the intended use, the people affected, the data involved and the possible consequences?
- Legal and sector obligations. Which duties apply because of the organisation’s role, jurisdiction, industry and specific use case?
- Technical assurance. How will systems, models, applications, agents and their supply chains be secured, tested and monitored?
- An operating layer. Who decides, where controls sit in the workflow, what evidence is retained, how people are supported and how value is measured?
This is why NIST and ISO/IEC 42001 are often more useful together than apart. NIST offers an open and adaptable risk language. ISO/IEC 42001 offers a disciplined management-system structure. Legal and sector rules can then be mapped onto that foundation, while security guidance turns broad intentions into technical practice.
The final layer is the one organisations most often underestimate. External frameworks can describe good outcomes. They cannot design an organisation’s decision rights, delivery routes, ownership model or change programme. That work remains specific to the enterprise.
This produces governance theatre: a visible structure that creates reassurance without creating reliable behaviour.
Why policy volume does not create control
Most weak governance designs fail in familiar ways.
- They start with policy before visibility. The organisation writes rules without knowing where AI is already embedded, which teams are experimenting, or which suppliers are introducing AI through ordinary product updates.
- They create a single approval bottleneck. Low-risk experimentation and consequential use cases enter the same queue, so responsible teams wait while shadow usage finds a faster route.
- They separate governance from delivery. Controls are reviewed after the design choices have been made, when changing the process, data or architecture is slower and more expensive.
- They use ‘human in the loop’ as a universal answer. A nominal reviewer adds little protection if they lack time, context, authority or a realistic way to challenge the system.
- They measure activity rather than outcomes. Committee meetings, policies and training completions are counted, while decision speed, adoption, exceptions, incidents, cost and business value remain unclear.
This produces governance theatre: a visible structure that creates reassurance without creating reliable behaviour.
Good governance is less concerned with the number of documents and more concerned with whether the organisation can make a clear, proportionate and evidenced decision at the moment it matters.
Governance should foster enablement, not restriction
The strongest governance systems make the safe path the easiest path.
For an employee, product owner or delivery team, the practical questions are straightforward:
- What can I use AI for?
- What data is safe to use?
- When do I need approval, and who can give it?
- What evidence is expected for this level of risk?
- Where do I go for help when the answer is not obvious?
If those questions are hard to answer, people will either stop useful work or proceed outside the official process. Neither outcome is good governance.
A proportionate model creates different routes for different kinds of use. Low-risk productivity cases should be able to move quickly within clear boundaries. Uses that affect customers, employees, safety, rights or significant financial decisions need more scrutiny. The goal is not to remove judgement. It is to apply judgement where it matters most.
This is also why governance and adoption cannot be separated. Training, approved tools, usable guidance, access to support and feedback from real users are part of the control environment. If governance ignores how people work, it will be bypassed by how people work.
Agentic AI changes the unit of governance
Generative AI made organisations think about the quality and safety of outputs. Agentic AI requires them to think about actions and decisions.
An AI agent may plan a task, call tools, retrieve data, write to systems, trigger transactions or coordinate with other agents. The relevant question is no longer only, ‘Was the answer accurate?’ It becomes, ‘What was the system allowed to do, on whose authority, and could the action be reversed?’
This introduces governance concerns that conventional model reviews do not fully address: agent identity, delegated authority, tool permissions, memory, workflow-level testing, containment, reversibility and continuous monitoring.
Singapore’s 2026 Model AI Governance Framework for Agentic AI is valuable because it addresses these operational questions directly. It emphasises clear limits on what an AI agent can do, meaningful human accountability, technical controls and end-user responsibility. It also recognises a practical reality: continuous human oversight is not realistic at scale. The important design challenge is to place meaningful checkpoints around significant actions and support them with automated monitoring.
The phrase ‘human in the loop’ is no longer enough. Leaders need to know which human, at what point, with what information, holding what authority, and with how much time to intervene.
The phrase 'human in the loop' is no longer enough.
The operating model matters more than the policy deck
Recent research increasingly treats AI governance as a whole-organisation, socio-technical capability.
This is because AI risk does not sit neatly inside a technology function. It crosses business ownership, data, legal, risk, security, procurement, architecture, delivery, operations, change and internal audit. A central AI council may coordinate the system, but it cannot own every decision and it should not try.
The durable model places accountability close to the business outcome while providing shared standards, specialist challenge and enterprise oversight. Controls are embedded into normal delivery and purchasing routes. Data and platform teams provide reusable technical guardrails. Second-line functions define expectations and challenge decisions. Internal audit tests whether the system operates as intended.
Most importantly, the organisation continues to ask whether the AI use is producing a worthwhile result. Governance without an outcome owner can become a permanent exercise in risk discussion. Outcome ownership forces a more useful conversation: what value was expected, what changed in the work, what did it cost, what unintended effects appeared, and should the system continue, change or stop?
That is not a softer form of governance. It is a more complete one.
Seven questions leaders should ask now
- Do we know where AI is already being used? Include embedded vendor features, personal productivity tools and agents, not only systems labelled as AI projects.
- Are decision rights clear? Teams should know who can approve, who can challenge and who can accept residual risk.
- Are our routes proportionate? Low-risk work should move quickly; consequential uses should receive deeper review.
- Are controls part of delivery? Governance should influence design, procurement, testing, release, monitoring and retirement.
- Can we evidence our decisions? An organisation should be able to explain purpose, ownership, risk, testing, approval, change and ongoing control.
- Are we ready for AI that acts? Identity, authority, reversibility and tool access should be governed before agents become operational dependencies.
- Are we measuring value as well as risk? A system that is compliant but unused, unaffordable or ineffective is not a governance success.
The real test of AI governance
Frameworks are necessary. They give organisations shared language, recognised expectations and a way to connect with regulators, auditors, customers and partners. But framework adoption is not the same as governance capability.
The real test is operational: can the organisation move from intent to a timely decision, from a decision to usable controls, and from controls to evidence, adoption and measurable outcomes?
At Ortecha, our starting point is simple. Governance should enable the business. That does not mean lowering the bar. It means making the bar visible, proportionate and achievable.
When people know what they can do, what they should not do, who decides, what data is safe and where support comes from, governance stops feeling like a limiter. It becomes part of how the organisation moves with confidence.
The organisations that get this right will not be the ones with the longest policy. They will be the ones that turn external expectations into clear choices, responsible action and sustained value.
Further reading
Let's do a quick recap
Is there one best AI governance framework?
There is no single AI governance framework that covers every organisational need. Principles, risk frameworks, management standards, regulation and security guidance address different parts of the problem. Effective AI governance combines the relevant sources and translates them into clear decision rights, controls, responsibilities and working practices.
How do NIST AI RMF and ISO/IEC 42001 work together?
NIST AI RMF provides a flexible structure for identifying, assessing and managing AI risk. ISO/IEC 42001 provides the requirements for establishing and continually improving an AI management system. Used together, they can connect practical risk management with repeatable governance, accountability, oversight and organisational improvement.
What is an AI governance stack?
An AI governance stack is the combination of principles, management standards, risk and impact assessment, legal obligations, technical assurance and operational controls needed to govern AI. Each layer performs a different role, allowing an organisation to connect external expectations with the way AI decisions are made and evidenced internally.
What is an AI governance operating model?
An AI governance operating model defines how governance works across the organisation. It establishes who owns AI outcomes, who approves or challenges decisions, where controls sit within delivery and procurement, what evidence must be retained, how incidents are handled and how AI performance, risk and value are monitored.
Why is an AI policy not enough?
An AI policy can describe an organisation’s expectations, but it does not ensure that those expectations influence real decisions. Effective governance must also provide visibility of AI use, proportionate approval routes, clear ownership, embedded controls, technical guardrails, monitoring and practical support for the people building, buying and using AI.
How should organisations govern agentic AI differently?
Agentic AI requires governance to address actions as well as outputs. Organisations need to define agent identity, delegated authority, tool and data permissions, human checkpoints, monitoring and reversibility. Leaders should be able to explain what an agent can do, on whose authority it acts and how harmful or unintended actions can be stopped.
How can AI governance enable innovation rather than restrict it?
AI governance enables innovation when the safe route is also the clearest and easiest route. Low-risk uses should move quickly within defined boundaries, while consequential applications receive greater scrutiny. Approved tools, accessible guidance, proportionate controls and timely support help teams experiment without moving outside the organisation’s control environment.

Sean Russell
Head of AI Enablement, Ortecha