Who Decides on AI? Three Operating Models for AI Governance
· 7 min read · Daniel Ostner
Most governance discussions start with policies and forms. The real fork in the road comes earlier: who decides whether an AI initiative goes ahead — and who carries the responsibility when it goes wrong? Three operating models have emerged. None is inherently better, but each fails in its own particular way.
Governance is an organizational question, not a document question
In many organizations, AI governance emerges as a by-product of a compliance requirement. Someone asks for a policy, someone writes it, and the document lands on the intranet. Six months later, initiatives still start outside the policy — not out of bad faith, but because nobody ever settled who is actually accountable.
A policy describes what should apply. An operating model describes who decides, who reviews, who escalates, and how long that takes. Without the second, the first has no consequences. The operating model question reduces to three basic patterns.
Model A: Central center of excellence
A named unit concentrates AI expertise, assesses every initiative, and approves it. Business units submit ideas; the center decides on prioritization, risk class, and delivery path.
Fits when AI expertise is scarce and you need consistent risk assessment across very different business units.
Fits when regulatory pressure is high and evidence needs to be consolidated in one place.
Typical failure: the center becomes a bottleneck. The queue grows, business units route around it, and a shadow AI landscape appears that nobody can see any more.
Model B: Federated with a central rulebook
A small core team defines rules, risk classes, and minimum requirements. Business units decide for themselves — as long as they stay within the classification. Central review only kicks in above a defined threshold.
This model depends on the threshold being genuinely sharp. If "high risk" is only loosely described, you get either a permanently overloaded core team or quiet rubber-stamping.
Fits when business units have their own delivery capacity and speed matters.
Typical failure: self-classification becomes a formality. Almost everything ends up in the lowest class, because the higher class means noticeably more work.
Review the distribution of self-classifications after six months. If more than ninety percent of initiatives land in the lowest risk class, that rarely says something about the initiatives — it says something about the incentives built into the classification.
Model C: Embedded in existing committees
AI initiatives go through no dedicated body, but through existing paths: architecture board, data protection review, investment approval. The only addition is AI-specific checkpoints inside existing checklists.
The appeal is low setup cost and acceptance — nobody has to recognize a new committee. The price is missing visibility: without one place that knows the overall portfolio, it is hard to answer how many AI systems the organization actually runs.
Fits with a small AI landscape and existing committees that already work well.
Typical failure: there is no inventory. At the first external inquiry, nobody can say which systems are affected.
How to recognize the model that fits
The choice depends less on company size than on two variables: how delivery capability is distributed, and how high regulatory pressure is. Central capability plus high pressure makes model A consistent. Distributed capability plus high pressure points to model B. If both are low, model C is enough for now — as long as an inventory is maintained.
More important than the initial choice is naming the model explicitly at all. The most expensive variant is the unspoken model, where every participant holds a different assumption about who is accountable.
Three things must be settled regardless of operating model: an inventory of all AI systems, a named accountable person per system, and a defined escalation path. If one of them is missing, even the best-designed model will not help.
Put this into practice
Whether an AI use case may go live is decided by data protection, transparency and risk — not by the model. Without a structured check you risk stop signs only shortly before go-live.
Start the AI Governance Check →Daniel Ostner
Author of the Enterprise AI Guide
AI-assisted draft, editorially reviewed on 02 August 2026.
Go deeper in the guide
Building AI Governance
Solid AI governance runs on three levels: strategic, tactical, operational. A minimal model with 5 roles and 6 core decisions is enough to get started.
Governance Decision Tree
Five questions determine whether an AI use case gets approved. Following the decision tree cleanly means approval in 5 business days instead of 5 months.