Dr. Angela D. PearsonAuthor · Strategist · Advisor

AI Governance

You Think You're Governing AI. The Data Says You're Not.

By Dr. Angela D. Pearson

You still believe you are in control.

You approve the budgets. You sign off on the strategic plans. You review the dashboards. Meetings happen. Decisions get documented. Governance looks, on paper, like it is functioning exactly the way it is supposed to.

Control has already shifted anyway.

Not through a single dramatic failure. Through a thousand small delegations that each felt reasonable in the moment. A hiring tool adopted to speed up screening. A credit platform adopted to process applications faster than human underwriters could. A scheduling algorithm adopted to reduce no-shows. Each decision was defensible on its own. None of them felt like surrendering authority. All of them were.

McKinsey's most recent research on board governance makes the gap between what executives assume and what is actually true impossible to ignore. Eighty-eight percent of organizations report using AI in at least one business function. Yet as of 2024, only 39 percent of Fortune 100 companies disclosed any form of board oversight of AI, whether through a committee, a director with relevant expertise, or an ethics board. Sixty six percent of directors globally report having limited to no knowledge or experience with AI, and nearly one in three say it does not even appear on their board's agenda. Fewer than 25 percent of companies have a board-approved, structured AI policy, and only about 15 percent of boards receive any regular AI-related performance metrics at all (McKinsey & Company, 2025).

Deloitte's newest survey of business and IT leaders finds the same gap from a different angle, and it is only widening as automation becomes more autonomous. Only 21 percent of organizations report having a mature governance model in place for agentic AI, the systems now capable of acting with limited human intervention, even as 74 percent expect to be using these systems by 2027 (Deloitte, 2026). Roughly four out of five organizations are actively expanding what automated systems can decide, faster than they are building any real authority to govern it.

Put those two findings side by side, and the pattern is unmistakable. Adoption is sprinting years ahead of governance, and most executives have no idea how wide that gap has actually become until something breaks in public.

THE THREE WAYS CONTROL QUIETLY DISAPPEARS

Control does not get handed over in one meeting. It erodes through patterns that feel like progress at the time.

The first is optimization replacing judgment. A system gets built to improve one specific metric, faster hiring, shorter wait times, higher conversion, and it does that job well. But optimizing a metric is not the same as exercising judgment about what actually matters. A hiring tool that speeds up screening can quietly filter out nontraditional candidates whose experience does not match the keyword patterns it was trained on. The system is working exactly as designed. The outcome is something no thoughtful leader would have chosen if they were making the call themselves.

The second is efficiency removing the checkpoints that used to catch problems. Manual review, human approval, a judgment call that slows the workflow down, these all get labeled as friction and removed in the name of speed. Some of that friction was never inefficiency. It was the exact moment a human being could notice something an algorithm could not.

The third is complexity that makes accountability nearly impossible to locate. As systems get more sophisticated, the logic behind their decisions gets harder for anyone outside a technical team to explain. When an outcome looks wrong, there is no longer a clear point where a person should have intervened, because the system itself has become too complicated to interrogate. Complexity becomes a shield, and authority quietly transfers to whoever can explain the model, whether or not they understand the actual consequences it produces.

WHERE THIS SHOWS UP, AND WHY NO ONE NOTICES UNTIL IT IS PUBLIC

A healthcare system adopts an algorithm to prioritize appointment scheduling. It works exactly as intended. No-shows decline. Utilization improves. Then, months later, patient advocates notice a pattern. Certain zip codes, insurance types, and medical histories consistently get later appointments or are routed to less convenient locations. No one designed the system to discriminate. It optimized for the metric it was given, and it learned that certain patient profiles correlate with higher no-show risk, and adjusted accordingly. The executive team approved a scheduling tool. They did not realize they had delegated decisions about who gets timely access to care.

A financial services company adopts a credit decisioning platform that processes loan applications faster and more consistently than human underwriters ever could. Default rates improve. Then a pattern emerges. Applicants from certain neighborhoods, with certain employment histories, are approved at meaningfully lower rates than similarly qualified applicants with different profiles. The algorithm never used a protected characteristic directly. It used proxies that correlated with those characteristics, learned from decades of lending data that reflected exactly the kind of structural inequity the company had publicly committed to correcting. Leadership approved the system because it promised neutrality. What they actually got was bias, automated at scale.

In both cases, no single person made a discriminatory decision. That is precisely why no one felt accountable, and precisely why accountability was owed anyway. The executives who approved these systems created the conditions for what happened next. They removed the human judgment that would have caught the pattern earlier. Owning that outcome, not explaining it away by pointing at the vendor, the data, or the algorithm, is what governance actually requires.

WHAT ACTUAL GOVERNANCE DEMANDS, AND WHY MOST LEADERS AVOID IT

Real governance is not a policy binder or an ethics committee formed to demonstrate good faith. It is three specific, uncomfortable commitments.

First, slow down the decisions that carry real consequences. Not every decision, but the ones with genuine moral or organizational weight need friction deliberately built back in, even when that friction runs against everything optimization culture rewards.

Second, actually understand what your systems do. Not at the level of a vendor's executive summary. At the level of being able to ask a question that cannot be answered with reassurance alone, and demand an explanation that can genuinely be interrogated rather than simply trusted.

Third, own outcomes you did not personally produce. Your organization will generate harm through systems you approved but do not operate yourself. That harm belongs to you regardless of intent, because you created the conditions for its existence and benefited from its efficiency while it ran.

None of this is complicated to state. It is genuinely uncomfortable to practice, which is exactly why McKinsey and Deloitte's numbers look the way they do. Adding another committee or another dashboard creates the appearance of oversight without restoring any of the actual authority that quietly slipped away. Delegating the problem to a chief AI officer transfers the appearance of accountability while the real work of reclaiming judgment goes undone.

THE ACTUAL TAKEAWAY

The gap between formal authority and actual influence does not close on its own, and it does not announce itself before it becomes a problem. It just keeps widening, one reasonable delegation at a time, until an executive who genuinely believed they were governing discovers they had actually just been informed.

The data says this gap is already wide open at most organizations. The only real question left is whether leadership closes it deliberately or waits to find out how wide it has become, as the healthcare system and the credit platform both did, in public, after the harm was already done.

Learn more about Governance in Automated Decisioning, forthcoming from Dr. Angela D. Pearson

References

All insights