In AI, Technology Keeps Changing. Governance Cannot

By Junaid Sharif.

AI is moving fast. Governance isn’t meant to.

That tension is starting to show, across banks, insurers and large enterprises trying to balance innovation with control. In this blog, Junaid Sharif challenges the idea that governance should be built around tools, and instead reframes it around behaviour, operating models and risk.


I had an interesting discussion recently with a fintech bank CTO who was wrestling with a problem we are seeing many organisations now facing.

How do we define AI governance when the technology keeps changing faster than the governance process itself?

It is a fair question.

One month the focus is Copilot. Then it shifts to ChatGPT, Gemini, Bedrock, Claude, agentic frameworks, reasoning models, or internal LLM deployments. New capabilities appear almost weekly. New risks appear just as quickly. By the time governance teams assess one wave of technology, the next wave has already arrived.

This is creating a very real enterprise problem.


The chicken-and-egg problem of AI governance

If organisations move too quickly with AI technology adoption, governance struggles to keep up. If they want to fully define AI governance before adopting technology, adoption stalls and the learning cycle falls behind the market. Most firms are stuck somewhere in the middle, trying to balance innovation with control while both targets continue moving.

The more I thought about it, the more I realised that many organisations may be approaching the problem from the wrong direction entirely. The issue is not simply that AI is evolving quickly. The issue is that governance is often being anchored directly to the tooling.

Should we allow ChatGPT? Should we use Copilot? Should we block external LLMs? Should prompts be retained? Should developers use AI assistants? Should customer teams have AI embedded inside productivity tooling? These are important questions, but they are downstream questions. They are not the starting point.


Start with behaviour, not tooling

The starting point should be much more fundamental.

What behaviour is the organisation actually trying to create?

That changes the discussion completely. Take two organisations with entirely different operating models.

  • A Microsoft-heavy enterprise using Teams, SharePoint, Outlook and Office 365 may find Copilot a natural extension of how teams already work. AI becomes embedded into meetings, documents, collaboration and communication.
  • But a heavily regulated bank may decide the opposite. They may deliberately avoid deeply embedded enterprise-wide AI access because they want tighter control of context, information boundaries, auditability and data exposure. In that case, a more isolated AI pattern may make more sense, where users explicitly provide context into controlled environments rather than allowing broad organisational discovery.

Neither approach is universally right or wrong.

The decision depends on the organisation’s operating model, regulatory exposure, collaboration patterns, security posture and business priorities.


AI in Business and Customer-facing Teams

The same thinking applies to business teams.

A customer service function may want AI to reduce response times, summarise customer history, suggest next-best actions or support agents during live conversations. But the governance question is not simply which chatbot or model to use.

The real questions are different.

Should AI respond directly to customers, or only assist human agents? Should it access full customer history, or only selected and approved information? Should it make recommendations, or simply summarise context? What needs to be logged, reviewed and explainable? Where does human approval remain mandatory?

Finance, risk and operations teams face similar questions. AI may help with reconciliations, exception handling, reporting, controls testing, policy interpretation or document review. But each use case carries different requirements around accuracy, auditability, segregation of duties, approval thresholds and regulatory exposure.

That is why the business problem has to come before the AI tool.

A chatbot, Copilot, Gemini, Bedrock or internal LLM may all be valid options. The right answer depends on the behaviour the organisation wants, the data being used, the level of automation allowed, and the risk that needs to be managed.


This same applies beyond productivity tools

The same applies to engineering and platform teams.

A Databricks-heavy organisation may prefer AI capabilities embedded directly into governed data workflows. An AWS-native engineering organisation may optimise for developer productivity across infrastructure and application delivery. A Google Workspace organisation may focus on AI embedded into collaboration and document workflows. Again, these are not purely technology decisions. They are operating model decisions.

That is where I think many organisations are getting trapped. They are trying to define governance for AI tools before defining the organisational principles those tools are supposed to support.


Governance needs to outlive the tooling

The AI landscape has become a moving goalpost. Governance keeps chasing it. Policies become reactive. Adoption becomes fragmented. Shadow AI inevitably appears.

Perhaps the real objective should not be to govern specific AI technologies at all.

The objective should be to define stable organisational principles, operating boundaries and desired behaviours that remain valid even as the tooling changes underneath.

That would fundamentally change how organisations approach AI adoption.


What’s next

I will explore this further in Part 2, particularly around how governance can become adaptive rather than reactive, why operating model matters more than model selection, and how organisations can separate stable governance principles from rapidly evolving AI tooling.

Because I increasingly believe the problem is not that AI is moving too quickly. It is that many organisations are governing at the wrong layer.

Happy to pick up your thoughts as well if you are living the same problem and if you think we need to have more considerations to the solution ?

Continue the conversation

If you’re navigating the same challenge, balancing AI adoption with governance, we’re seeing it across the organisations we work with. Speak to a data & AI specialist.