Governing AI Systems,
Not Just Models
When people talk about Responsible AI, I've noticed the conversation almost always ends up in the same place. Someone asks about the model. Is it accurate? Has it been validated? Can we explain its decisions? Has it been tested for bias? They're all good questions, but after helping organisations operationalise AI governance, I've come to believe they're not the questions we should be starting with. They're questions about a model. Responsible AI is about something much bigger.
Several years ago, I led GDPR programmes for a large analytics organisation. Like many organisations at the time, the initial reaction was to treat GDPR as another compliance initiative. The organisations that were most successful realised it wasn't really about implementing another policy. It was about improving the way the organisation governed information. Once good governance became part of everyday operations, compliance became a natural outcome rather than the primary objective. As I look at Responsible AI today, I see similar patterns emerging. Many organisations are understandably focused on the latest regulation, the newest framework or the next compliance deadline. Those things matter, but I don't believe they're where the conversation should begin. For me, Responsible AI has never really been about governing models. It's about governing AI-enabled business capabilities.
One concept that reinforced this perspective for me was the PMI Certified Professional in AI (CPMAI™) programme. It encouraged practitioners to think beyond the model and consider the entire AI system, which closely aligned with what I was already beginning to experience in practice.
One lesson surprised me early in my AI governance journey. The first governance decision isn't whether a model is ready for production. It happens much earlier. Someone has to decide whether AI is actually the right solution to the business problem. Not every challenge requires a cognitive solution. Sometimes a well-designed business rule or traditional analytics will achieve the desired outcome. Responsible AI begins by asking whether AI should be used at all.
One experience that really shaped my thinking came while supporting product teams developing AI-enabled capabilities. We initially approached the work much as you might expect from a governance function, focusing on controls and accountability. It quickly became clear that if governance was going to add value, we first had to understand how products were actually built. That meant learning the entire product lifecycle—from the earliest conversations about an idea through design, development, testing, deployment and continuous improvement.
Rather than trying to introduce Responsible AI across every initiative at once, we deliberately chose a highly visible business process that represented a significant strategic investment for the organisation. It mattered to senior leadership, carried meaningful business risk and gave us an opportunity to demonstrate that governance could enable delivery rather than slow it down. We knew that if we got it right, we'd build confidence in the programme, secure further investment, mature our governance capabilities and extend Responsible AI across other products and business areas.
Working alongside product managers, engineers, architects, legal, privacy and risk teams, we embedded governance throughout the product lifecycle rather than concentrating it at the end. We learned just as much as the delivery teams did. What surprised me most wasn't the technology. It was the people. Responsible AI couldn't be handed to a governance team during a final review. It had to become part of the way products were conceived, designed, built, deployed and continually improved.

Canadian organisations now navigate PIPEDA, OSFI guidance including B-10, B-13 and E-23, and the proposed Artificial Intelligence and Data Act (AIDA), while many also prepare for the EU AI Act. Although each regulation uses different language, they consistently reinforce the same themes: accountability, transparency, privacy, human oversight, operational resilience and governance. None of these expectations begin with the model. They begin with governance.
That also changed the way I think about AI risk. The better question became: do we understand the risks across the entire AI system well enough to make informed business decisions? That shifts the conversation from technical performance alone towards business outcomes, customer impact and organisational resilience.
Looking back across my career, I don't think the organisations that have been most successful were the ones with the largest governance teams or the longest policy manuals. They were the organisations that recognised that Responsible AI begins with a business decision, not a model, and that good governance measures the health of the entire AI-enabled business capability rather than simply the performance of a single algorithm. Technology will continue to evolve. Regulations will continue to evolve. Customer expectations will continue to evolve. If we build governance capabilities that evolve alongside them, we won't need to reinvent governance every time the technology changes. We'll simply continue doing what good governance has always done—helping organisations make better decisions, manage risk and earn trust.
Reflection Questions
- Are you governing individual AI models, or the end-to-end AI systems that create value for your organisation?
- Are you building governance capabilities that can adapt to evolving regulations, or are you responding to each new requirement as it emerges?
- If AI continues to evolve over the next five years, will your governance evolve with it—or will you need to reinvent it?