ModelCensusopen-source ai reliability harness
Blog2 Sept 2026enterprisegovernancepositioninghot-take

AI governance made the board agenda this year. Your governance stack can't answer its questions.

First year CDAOs name AI governance as critical. Most programmes were built to catalogue data, not to evidence behaviour.

This is the first year AI governance shows up as an explicitly critical priority in the CDAO leadership survey. Data governance has been there for a decade; AI governance arriving as its own line is new.

The uncomfortable part: most governance programmes were built to answer questions about data at rest. The board is now asking questions about behaviour.

Why the existing stack accumulates debt

A data catalogue answers where something came from, who owns it, and who may see it. Good questions. None of them is the question a board asks after an incident.

The board asks: how often does this happen, is it getting worse, and what did we do about it last time. Those are measurement questions, and a catalogue cannot answer any of them.

Data governance answersWhere did this come fromWho owns itWho may see itvs.AI governance is askedHow often does it failIs it getting worseWhat did we changeand did it work

The reality on the ground

AI governance that works looks less like a policy and more like an instrument: named failure modes, rates with intervals, a controlled comparison showing whether a mitigation moved anything, and provenance from the number back to the raw output.

That is not a documentation exercise. It is a measurement function, and it usually needs to sit closer to engineering than to risk.

Where policy-first is right

Regulatory exposure is genuinely a policy problem. If you operate under a regime with documentation requirements, you need the documents and no amount of measurement substitutes.

But documents describe intent. The board's question is about outcome, and the two have to be built separately or the documentation quietly becomes the evidence — which it is not.

A policy says what should happen. A measurement says what did. Your board is asking the second question.

When your board next asks how often your AI gets something wrong — which system produces that number today?

Every figure here describes something measured and committed. See the measurements · read the method