AI Governance

You Cannot Govern Air Travel with Road Rules

AI is moving from experimentation into consequential work. Its governance must evolve from static gates to risk-based, adaptive control.

AI adoption in many organisations has reached a tipping point.

The conversation is no longer primarily about summarising emails, drafting meeting notes or generating an occasional image. Those uses helped people become familiar with the technology, but they were only the opening act.

AI is now entering the machinery of the enterprise: software delivery, customer service, operational decision-making, knowledge management, product design and the work of professionals whose judgement carries real consequences. Organisations are pursuing greater speed, more capacity and—hopefully—lower cost.

This creates a peculiar mixture of excitement and apprehension. The opportunity feels too significant to ignore, while the technology changes too quickly to make anyone feel fully prepared.

The governance mismatch

Most enterprise governance was designed for a more predictable world. A proposal could be defined, assessed, approved, delivered and periodically reviewed. Architecture standards assumed that the important characteristics of a system would remain sufficiently stable while people evaluated them.

AI disrupts that rhythm. Models change. Capabilities emerge between planning cycles. Behaviour can be probabilistic rather than deterministic. A seemingly modest change in context, data or orchestration can alter both what a solution can do and the risks it creates.

The instinctive organisational response is often to add another approval, another checklist or another committee. These actions can create the appearance of control, yet they may do little to address the actual risk.

Installing more traffic lights and painting more zebra crossings will not make air travel safer.

Road rules are valuable—for roads. Aviation became dependable through controls designed for aviation: airworthiness standards, trained operators, flight plans, maintenance regimes, incident investigation, real-time monitoring and clear authority when conditions change.

AI needs the same conceptual shift. It cannot be governed well merely by increasing the quantity of controls inherited from conventional technology delivery. It needs mechanisms designed for its own operating characteristics.

When the machinery cannot match the pace

This mismatch is creating tension inside organisations. Technology teams see capabilities becoming available in weeks. Risk, legal, procurement, security and architecture functions are often asked to respond through processes calibrated for changes measured in quarters or years.

Neither side is necessarily wrong. Moving quickly without adequate safeguards can create harm. Moving so cautiously that useful learning becomes impossible creates a different form of risk: competitors learn faster, employees adopt tools unofficially and decisions are made without the evidence that controlled experimentation could have produced.

In the absence of a meaningful mechanism, organisations can find themselves building speed humps while the aircraft is already on the runway.

The goal should not be frictionless adoption. Some friction is deliberate and essential. The goal is intelligent friction—strong where consequences are serious, light where exposure is limited, and capable of changing as evidence accumulates.

Three mindset shifts

01

Accept the speed of change

AI will not become conveniently stable once organisations finish writing their policies. Governance must therefore become a living capability: regularly refreshed, informed by actual use and able to respond without starting from zero each time the technology moves.

02

Govern in proportion to risk

A tool that helps an employee brainstorm carries a different level of consequence from one that recommends operational actions, handles sensitive data or communicates autonomously with customers. Applying the same process to all of them wastes attention on low-risk activity and can leave too little capacity for the cases that deserve genuine scrutiny.

03

Start before every detail is known

Responsible action does not require false certainty. Define a bounded use case, establish clear ownership, constrain data and permissions, observe behaviour and decide in advance what would cause the experiment to stop. Then learn. Progress comes from putting one foot in front of the other, not from waiting for the entire road to reveal itself.

From approval gates to a control system

Good AI governance should function less like a single toll gate and more like an air-traffic control system. It should understand what is moving, where it is operating, the conditions around it and when human intervention is required.

That means maintaining visibility of AI use across the organisation; assigning accountable owners; classifying uses by impact and reversibility; protecting data and access; testing behaviour before release; monitoring outcomes in operation; and learning from incidents and near misses.

Architecture has an important role here, but not as a source of elaborate diagrams or universal prohibitions. Its contribution is to make risk visible and create reusable pathways for responsible adoption. Approved patterns, well-defined interfaces, governed knowledge sources, observable agent actions and clear boundaries between recommendation and execution can allow teams to move faster precisely because they do not need to reinvent safety each time.

This also changes the meaning of control. A design review conducted once, before launch, is not enough for a system whose behaviour depends on changing models, prompts, data and context. Some assurance must move into the operating environment through evaluation, telemetry, auditability and feedback.

Safety is something we build

Early aviation was dangerous. The response was not to declare flight inherently unacceptable. Nor was it to pretend that enthusiasm would make aircraft safe. Society invested in engineering, standards, training, operating discipline and institutions that learned from failure.

AI deserves the same seriousness. Its advocates should not dismiss legitimate risk, and its critics should not mistake refusing to move for a durable strategy.

Economic and competitive forces mean the aircraft will take off—with us or without us. Employees, customers, suppliers and competitors are already changing how work gets done. The relevant choice is whether organisations participate deliberately and develop the capability to shape the journey.

We can spend our energy arguing that flight is unsafe, or we can invest it in making flight safer. The organisations that thrive will be those that learn to do both things at once: move with purpose and govern with intelligence.

Discussion

Continue the conversation.

Comments and reactions are powered by GitHub Discussions via Giscus.