A pilot needs enthusiasm — an operating model needs governance
What does an AI governance model mean in practice? Three things: clear ownership, ground rules that are actually followed, and a division of responsibility when things go wrong. Without them, the benefits stay locked in individual teams and the risks scale quietly. And by August 2026 at the latest, governance becomes a legal obligation — no longer just a sign of maturity.
Most organizations already know how to use AI, but far fewer know how to scale it productively. The difference between the two lies neither in technology nor in enthusiasm. It lies in governance. A pilot is born when one team gets excited. An operating model is born only when that enthusiasm gets structure: an owner, ground rules, and a division of responsibility. Without them, every success remains a local experiment and every risk scales quietly.
Over the past year we have met dozens of companies where AI is used daily, yet hardly any can answer three questions: who owns it, what may it be used for, and who is accountable for mistakes. The same pattern shows up in research. According to MIT’s GenAI Divide report (NANDA, 2025), only about 40 percent of companies have an official AI tool, yet in over 90 percent of companies employees use AI tools regularly on their own. This is not governance. This is a governance vacuum — one into which both unrealized benefits and invisible risk keep draining.
Governance does not have to mean bureaucracy or killing enthusiasm. Nor does it mean a separate AI strategy — quite the opposite. We encourage weaving AI into the business strategy itself, because unlike, say, an ERP project, which is justifiably its own undertaking, AI cuts across all operations at once. Without these three — ownership, ground rules that are followed, and a division of responsibility — no experiment ever turns into an operating model. Governance is the foundation on which a working practice can be transferred from one team to the whole organization.
What does governance look like in practice? When one salesperson finds a way to use AI to produce proposals a third faster, the benefit stays local for as long as it remains one person’s way of working. Only when the practice is documented and people are trained in it does the benefit start to show in the productivity of the entire sales organization. At the same time, the risks — such as potential pricing errors — stay under control. Without governance, the benefit belongs to one person, not the company — but the risks belong to the company, not to one person.
Why does an AI governance model solve scaling?
First, AI is still on no one’s desk. In a study covering nearly 300 executive team members (Lifted, 2026), 54 percent did not feel that AI was part of the leadership team’s shared work, and the use of AI and data received the weakest score in the entire study. When ownership is scattered between IT and a few enthusiastic individuals, no one is accountable for scaling — or for risk. What no one owns rarely moves forward.
Second, regulation has already turned governance from an option into an obligation. The Digital Omnibus package approved in June 2026 lightened the EU AI Act and shifted its timelines, but the relief mainly concerns high-risk systems. Two obligations still apply to every organization using AI professionally. AI literacy is the first: organizations must continue to actively promote AI competence in proportion to how and for what AI is used — an obligation that has been in force since the beginning of 2025. Transparency is the second: from August 2026 onwards, people must be told when they are interacting with AI, and AI-generated content must be labeled. Enforcement begins on the same date, and non-compliance can lead to fines of up to 15 million euros. Governance is no longer a sign of maturity — it is a condition for operating.
Third, governance has become a sales argument. The world’s first certifiable AI management system standard, ISO/IEC 42001 (2024), turns governance into trust and trust into competitive advantage. As organizations’ competence and understanding grow, expect customers to ask more and more often in competitive tenders how your AI is governed. The one who can answer builds trust. And trust should not be taken for granted: the Edelman Trust Barometer 2026 shows trust retreating into ever smaller circles. Acceptance of AI is not given for free — it is earned by demonstrating that its use is under control.
“Doesn’t governance slow things down and kill experimentation?”
This is the most common objection, and it misses the point on two levels. It misunderstands both what governance is and what actually stops scaling. Governance is not a brake — it is what lets you accelerate safely, because without brakes you don’t drive fast, you drive cautiously. And what stops scaling is precisely the lack of governance. Without ground rules and ownership, the benefits stay in one team, because no one dares — or knows how — to transfer the practices behind them anywhere else. An experiment without governance is fast. An operating model without governance is impossible.
Getting started doesn’t require heavy machinery either. In an SME, governance can initially amount to three decisions: 1) the CEO names an owner for the AI transformation — preferably themselves, 2) the company defines which tools are allowed for now, and 3) a responsible person is named for every AI solution taken into use. Once these urgent first-phase decisions are made, AI is brought calmly into everything else the company does. Impacts are assessed in the normal rhythm of risk management, metrics live in the same reporting as the rest of the business, and the ground rules are updated as use expands. Governance is not a separate project that one day gets finished — it is a management routine.
Three questions worth asking right away
We encourage leadership teams to ask themselves three questions:
- When AI makes an expensive mistake next quarter — a pricing error, a wrong recommendation, a data leak, a discriminatory output — who is accountable? If you cannot name the accountable person today, responsibility has not been assigned.
- Do you have an AI policy that is actually followed? If in doubt, test it by asking three employees what data they are allowed to feed into an AI tool. If you get three different answers, you don’t have a policy.
- Is AI a standing item on your leadership team’s agenda, with an owner and metrics — or is it still “that IT thing a few individuals take care of”?
Governance is one of the four reasons why every strategy question is ultimately an AI question — alongside competence, workflows, and cost structure. And beneath them all lies the same foundation: sustainable advantage is not in the tool but in people — in their skills and in how well their work is led.
Astu Labs helps leadership teams build an AI governance model that carries them through scaling — ownership, a policy people actually follow, and an ISO 42001-level management system — so that governance becomes an enabler, not a brake. If you want to know whether your governance would survive its first big mistake, get in touch. We respond within one business day.
Sources
- European Parliament and Council (2024). Artificial Intelligence Act (EU) 2024/1689, Art. 4 (AI literacy, applied from 2 Feb 2025), Art. 50 (transparency obligations, applying from 2 Aug 2026) and Art. 99 (penalties). The so-called Digital Omnibus amendment package, approved in June 2026, postponed the obligations for high-risk systems until 2 Dec 2027 (Annex III) and 2 Aug 2028 (Annex I), but the Article 50 transparency obligations enter into application on the original schedule; the only exception is the transition period granted to systems already on the market for machine-readable labeling (Art. 50(2)), running until 2 Dec 2026. See the Council press release of 7 May 2026: consilium.europa.eu
- Challapally, A., Pease, C., Raskar, R. & Chari, P. (2025). The GenAI Divide: State of AI in Business 2025. MIT NANDA, July 2025. (Shadow use: only about 40% of companies have purchased an official LLM subscription, yet in over 90% of the surveyed companies employees report regularly using personal AI tools for work tasks.)
- ISO/IEC 42001:2024. Information technology — Artificial intelligence — Management system. The world’s first certifiable AI management system standard, published in 2024.
- Lifted Oy (2026). Suuri Johtoryhmätutkimus 2026 [The Great Finnish Leadership Team Study 2026]. Report: lifted.fi/materiaalit
- Edelman (2026). Edelman Trust Barometer 2026. Nearly 34,000 respondents in 28 countries; key finding: trust retreating into ever smaller circles (“insularity”). edelman.com/trust/2026

