By Junaid Sharif.
AI isn’t slowing down. But many governance models are still being built as if it will.
In Part 1, I argued that many organisations are trying to govern AI at the wrong layer.
The problem is not simply that AI technology is evolving quickly. The problem is that governance is often being anchored directly to the tooling itself.
That creates a losing battle. New models appear. New capabilities emerge. New risks are identified. Organisations react by updating policies, restricting tooling or restarting governance conversations from scratch. Meanwhile, adoption continues moving underneath them.
I increasingly believe the answer is not tighter control of individual AI tools. The answer is to move governance up a level.
Start with vision and operating model, not tooling
Most organisations begin AI adoption discussions with questions like:
- Should we allow Copilot?
- Should we use ChatGPT Enterprise?
- Should we block external LLMs?
- Should we use Bedrock, Gemini or Claude?
- Should developers have AI coding assistants?
Those are important decisions, but they should not come first. The starting point should be much more fundamental.
- What is the organisation trying to achieve?
- What behaviours are we trying to encourage?
- What risks are unacceptable?
- What level of autonomy are we willing to allow?
- What must always remain explainable, auditable or human-approved?
Once those organisational principles are understood, technology selection becomes far easier and far more stable. The starting point should not be the AI tool. It should be the business vision and the outcomes the organisation is trying to achieve. Those outcomes then shape the objectives through which success will be measured. Improving customer satisfaction, reducing onboarding friction, increasing operational efficiency, reducing manual controls, accelerating engineering delivery or improving decision-making all lead to very different operating priorities.
Those priorities then define where AI can realistically create the most value. Only at that stage do the technology decisions become meaningful.
An organisation focused on collaboration-heavy workflows may benefit from deeply embedded AI within productivity tooling. A highly regulated environment may prioritise isolated and tightly controlled AI interactions. A data-driven engineering organisation may focus on governed AI embedded directly into analytics and platform workflows.
In other words, AI tooling should adapt to the organisation’s governance and operating model, not the other way around.
The same applies to data and engineering teams
The same challenge exists across engineering, platform and data organisations, although the objectives are often different. Here, the focus may be less about customer interaction and more about improving engineering velocity, accelerating delivery, strengthening governance, improving platform reliability and enabling faster access to trusted enterprise data.
Again, those are not purely AI tooling decisions. They are organisational and operational decisions.
- A Databricks-centric organisation may choose to embed AI directly into governed analytics, data science and enterprise data workflows, with strong emphasis on governed self-service, trusted analytics and controlled interaction with enterprise data products.
- A Microsoft-heavy enterprise may focus more heavily on collaboration-driven engineering workflows, integrated enterprise productivity and AI-enabled operational coordination across teams and services.
- An AWS-native organisation may prioritise operational flexibility, infrastructure automation and scalable integration across engineering and operational platforms.
In each case, the technology choices are being shaped by the operating model the organisation is trying to create. That includes decisions around productivity behaviour, governance boundaries, ownership models, auditability, collaboration patterns and operational accountability. That distinction matters.
Because once governance principles are anchored around organisational behaviour rather than individual tooling, the organisation becomes far more adaptable to continuous technology change.
What happens when the next AI stack arrives?
This is where the model becomes important. If governance is built around specific tooling, every major AI shift creates disruption. A new model appears. A new framework gains traction. A new vendor promises higher productivity, lower cost or stronger reasoning capability. Organisations then restart governance discussions, reassess policies, revisit restrictions and reopen approval processes. That cycle never really ends. The problem is not the technology itself. The problem is that governance becomes tightly coupled to rapidly changing tooling decisions.
But once governance is anchored around stable organisational principles, the discussion changes completely. New AI technologies can then be evaluated against existing operating boundaries rather than forcing governance to be redesigned from scratch. The questions become much more practical:
- Does this align with the operating model we are trying to create?
- Does it fit our governance and audit requirements?
- Does it respect our data boundaries and security controls?
- Does it improve customer or operational outcomes without introducing unacceptable risk?
- Does it strengthen existing workflows, or create fragmentation and shadow AI adoption?
At that stage, new technology becomes easier to absorb. For example
- A Microsoft-heavy organisation may evaluate new Copilot capabilities, Fabric AI integrations or Azure AI services in the same way. If collaboration boundaries, data governance, approval models and operational controls already exist, new AI services can be absorbed into the operating model without requiring the organisation to redefine governance every time Microsoft releases new functionality.
- A Databricks-centric organisation that already supports governed natural-language interaction through Genie may later decide to introduce Databricks Apps or additional AI-driven operational interfaces for internal teams and business users. Because governance boundaries, ownership models and enterprise data controls already exist, those newer capabilities can be evaluated and absorbed without requiring governance to be redesigned from scratch.
- An AWS-native engineering organisation may decide to adopt Kiro or AI-assisted engineering agents to accelerate software delivery, infrastructure automation or operational support. The decision then becomes less about “should we allow AI?” and more about whether those capabilities fit existing governance boundaries around code quality, security, auditability and operational accountability.
Another organisation may look at the same technologies and decide the operational risk, regulatory exposure or governance overhead outweighs the value. Both decisions can be valid. The important point is that the organisation is no longer reacting emotionally to technology change. It is evaluating technology against stable organisational principles.
That is a far more sustainable position.
The AI landscape will continue evolving rapidly. New copilots, agent frameworks, orchestration layers and reasoning models will continue appearing at pace. Some will mature. Some will disappear. Others will fundamentally reshape how organisations operate.
The organisations that succeed will not necessarily be the ones adopting every new capability first. They will be the organisations capable of absorbing technological change without having to redesign governance every time the market shifts.
Governance should evolve deliberately
None of this means governance or operating models should remain static. New AI capabilities will inevitably create opportunities to rethink how organisations operate, collaborate and deliver value. Some technologies may genuinely justify changes to customer interaction models, engineering workflows, operational structures or governance processes.
But those changes should happen consciously. The danger is when organisations allow rapidly evolving tooling to drive operating behaviour by default rather than by design. That is how fragmentation emerges. Different teams adopt different AI capabilities independently. Governance becomes reactive. Operating boundaries become inconsistent. Shadow AI grows faster than enterprise controls can adapt.
A mature organisation should absolutely refine its governance and operating model as technology evolves. But it should do so intentionally, with clear understanding of:
- the business outcome being targeted
- the behavioural change being introduced
- the operational impact
- the governance implications
- and the long-term sustainability of the decision
Technology should influence organisational evolution. It should not accidentally dictate it.
Closing thought
AI governance should not be designed to survive one model generation. It should be designed to survive continuous technological change. That requires governance principles that are stable, operating models that are intentional, and technology decisions that remain subordinate to business outcomes.
The organisations that will succeed with AI are unlikely to be the ones chasing every new capability first. They will be the organisations capable of learning quickly, adapting deliberately and absorbing technology change without losing operational control, governance consistency or strategic direction. Because ultimately, AI adoption is not just a tooling problem, it is an organisational design problem..
