← Back to all Thoughts RSS Feed
Blog post icon October 11, 2026 • 5 min read • Originally published on Other

Climbing Out of the AI Governance Chasm: Why CIOs Need a New Mental Model

Enterprise leaders are discovering something uncomfortable about the AI wave sweeping through their organizations. The technology is moving faster than the structures meant to guide it. This recent InformationWeek article captures this tension well. CIOs are watching AI agents, tools, and workflows appear across their companies at a pace that outstrips their ability to govern them. They reference a DataIku survey that found 84% of CIOs say employees are building AI applications faster than IT can review or control them. Less than half of organizations have clear governance controls in place. That’s not a small gap. It’s a chasm.
AI Governance Gap
The article focuses on the operational and financial challenges this creates. But underneath those challenges is something deeper. AI governance isn’t just a policy problem. It’s a thinking problem. When a technology accelerates faster than the mental models used to manage it, leaders start losing visibility, control, and confidence. They’re forced into reactive mode. They’re stuck cleaning up AI slop, chasing down shadow systems, and trying to explain decisions made by models they didn’t approve.

This is exactly the kind of environment where cognitive discipline matters.

The speed mismatch problem
AI systems operate at machine speed. Humans don’t. CIOs quoted in the article describe a growing fatigue among reviewers who are asked to keep up with automated agents that never slow down. When people get tired, they rubber‑stamp. When they rubber‑stamp, governance collapses.

This is a classic speed mismatch. You see it in aviation, finance, cybersecurity, and now AI. When a system moves faster than the human responsible for oversight, the human becomes the bottleneck. The bottleneck becomes the risk. And the risk becomes the headline.

The solution isn’t to make humans faster. It’s to redesign the oversight loop so humans only intervene where their judgment is actually needed. That requires a shift from “review everything” to “review the right things.”

The inventory illusion
One CIO in the article describes an effort to inventory all approved data sources. It’s a smart move, but it’s also a trap. Inventories create a sense of control, but they’re snapshots of a moving target. AI systems generate new data, new artifacts, and new workflows constantly. The moment you finish the inventory, it’s already outdated.

This is where organizations need to adopt a systems‑thinking approach. Instead of trying to catalog everything, they need to understand the flows. Where does data enter? Where does it move? Where does it get transformed? Where does it get stored? Who touches it? Which agents have access to it?

Flows matter more than lists.

Shadow AI isn’t a technology problem
The article highlights shadow AI as a major governance threat. Employees spin up agents, MCP servers, and tools without approval. But shadow AI isn’t really about technology. It’s about incentives.

People use unapproved tools when:

  • approved tools are slow
  • approved tools are hard to access
  • approved tools don’t solve their problem
  • governance feels like friction instead of support

Shadow AI is a symptom of a mismatch between what employees need and what the organization provides. If governance is seen as a barrier, people will route around it. If governance is seen as a guide, people will follow it.

This is where behavioral design becomes essential. Governance must be easy, obvious, and helpful. Reporting an AI error should be as simple as clicking a button. Requesting approval should take minutes, not weeks. Access to safe tools should be frictionless.

People don’t rebel when the safe path is the easy path.

The accountability paradox
The article states that two‑thirds of CIOs say they couldn’t produce an end‑to‑end audit trail for an AI agent’s decision if regulators asked. And I suspect the real number is actually higher. That’s a serious gap. But it also reveals a deeper paradox.

Organizations say humans are ultimately accountable for AI outcomes. But humans are at a loss to be accountable for decisions they can’t trace, explain, or even observe. Accountability without visibility is theater and a huge liability.

To fix this, enterprises need to adopt a principle from cognitive psychology: explainability isn’t optional for trust. If a system can’t show its reasoning, it can’t be trusted. If it can’t be trusted, it can’t be scaled. If it can’t be scaled, it can’t deliver value.

AI governance must include mechanisms that make decisions inspectable. Not perfect transparency, but enough clarity that a human can understand what happened and why.

The real governance gap: curiosity
One of the leaders quoted in the article says his biggest long‑term concern is over‑reliance on AI. He warns that people may forget the skills they’ve built over the years. That’s a valid fear. When a tool becomes too convenient, people stop questioning it.

The antidote is curiosity.

Curiosity is the cognitive habit that keeps humans from outsourcing their judgment. It’s the habit that pushes people to ask:

  • Why did the model choose this answer?
  • What assumptions is it making?
  • What data did it rely on?
  • What’s missing?
  • What would happen if we changed the input?

Curiosity is the governance layer that can’t be automated. It’s the human safeguard against complacency.

Where CIOs go from here
The article ends with a call for collaboration and simplification. Governance committees, clear pathways for reporting issues, and better tools will help. But the deeper shift is mental.

CIOs need to adopt governance models that assume:

  • AI will move faster than policy
  • employees will experiment
  • data will multiply
  • agents will behave unexpectedly
  • oversight will fatigue
  • accountability will blur

Governance must be designed for a world where uncertainty is the default, not the exception.

The organizations that succeed won’t be the ones with the thickest policy documents. They’ll be the ones with the clearest thinking.

Related Thoughts

Perspectives sharing related architectures, models, and domain context.

All Thoughts →
Oct 03, 2026 5 min read

AI Can Now P‑Hack at Scale. The Real Risk Isn't Cheating. It's Obedience.

For years, p‑hacking was a slow, human problem. A researcher could sift through enough models and enough specifications...

Oct 05, 2026 3 min read

LLMs Aren't Reasoning. They're Predicting - And Why That Matters More Than People Think.

Thore Graepel just published a piece in MIT Technology Review that deserves attention. His argument is simple: Modern...

Sep 28, 2026 3 min read

The Illusion of Autonomy: Why AI Breakthroughs Still Require Human Oversight

A fascinating debate recently broke out on LinkedIn that cuts right to the heart of how we evaluate technological...