The first wave of AI governance was about saying the right things: principles, acceptable-use policies, steering committees, and risk statements. Those are useful, but they do not govern models. Models are governed by decisions: who can approve a use case, what evidence is required, what data is allowed, what gets monitored, and who has authority to stop the system when it drifts.

NIST's AI Risk Management Framework and generative-AI profile have pushed the conversation in the right direction: govern, map, measure, and manage. The operating question is how to make those verbs part of delivery rather than a document that sits beside it.

Policy is not enough

The reason policy-only governance fails is structural. AI systems change after launch. Prompts change. Data changes. Users find workarounds. Vendors update models. A governance model that only approves the launch misses the thing that actually matters: the lifecycle.

Exhibit 1
AI control stack
Controls that need to exist before production use
Use-case approval
Gate
Data rights and lineage
Control
Model evaluation
Evidence
Human override
Safety
Post-launch monitoring
Lifecycle
Source: Kaya Development synthesis of NIST AI RMF, NIST GenAI Profile, and OECD AI governance work

The lifecycle is the unit of governance

A serious operating model creates gates before build, before pilot, before production, and after launch. Each gate asks a different question. The early gate asks whether the use case is worth doing. The production gate asks whether the system can be trusted in context. The monitoring gate asks whether the system still deserves to run.

Exhibit 2
Model lifecycle gate map
What each control point should decide
Use-case intakeBusiness value, user impact, risk tier
Approve to explore
Data and vendor reviewRights, privacy, security, dependencies
Approve to build
Evaluation and red-teamAccuracy, bias, robustness, misuse
Approve to pilot
Production readinessOwner, SLA, monitoring, fallback
Approve to launch
Live monitoringDrift, incidents, user behavior
Keep, change, stop
Source: Kaya Development AI operating-control framework

Ownership is where governance becomes real

Every AI system needs three owners: a business owner who is accountable for the decision, a technical owner who is accountable for the system, and a risk owner who can challenge the evidence. If any one of the three is missing, governance becomes ceremonial.

Exhibit 3
AI risk ownership matrix
Where accountability should sit
Risk-led blockHigh scrutiny, low business ownership. Decisions stall.
Balanced controlBusiness owns value; risk and technology own challenge and evidence.
Shadow AINo clear owner. Usage grows without visibility.
Delivery biasStrong business pull, weak independent challenge. Incidents accumulate.
Business ownership →
Independent challenge →
Source: Kaya Development AI governance diagnostics

What leaders should do next

Start by inventorying live and near-live AI systems. Do not begin with a new committee. Begin with the actual decisions being made by AI or with AI assistance. Then assign owners, set gates, and define the evidence each system needs to keep operating.

Minimum viable AI governance
  1. A use-case registry with risk tiers.
  2. Named business, technical, and risk owners for every production system.
  3. Lifecycle gates that can stop or change a system after launch.