AI Governance & Leadership · Executive Briefing
Ten minutes, well spent.
Three questions that show whether AI governance here is visible, usable and owned.
01 · Listen
Three Questions for AI Governance
Audio arriving shortly — 10:12Awareness · Permission · Ownership
Transcript
You can have an AI policy. You can have approved tools. You can have people discussing AI at leadership meetings. And still be unable to answer three fairly basic questions about what is actually happening in your organisation.
What would that tell you? Not necessarily that nothing has been done. It might tell you something more useful: that governance exists somewhere in the organisation — but is not yet visible enough, usable enough, or clearly enough owned to guide what people actually do.
That is what this short briefing is designed to help you test. By the end, I want you to use three questions to test where your organisation stands, and identify where you most need greater clarity.
And there is one rule. Don’t look anything up. Don’t ask somebody else. Answer from what is currently visible to you as a leader.
Start with what we mean by AI governance. At its core, AI governance is the set of rules, processes, safeguards and ways of working that help an organisation use AI responsibly, safely, fairly and legally.
Underneath that are three things. Rules and Policies. Safeguards. Accountability.
Rules and policies create the boundaries: what people can do, what they can’t, and where they need approval. Safeguards create the checks where the stakes require them. And Accountability keeps responsibility with people.
Who owns the decision? Who can challenge it? Who remains answerable for the outcome?
Not: “The AI produced it.” Not simply: “That sits with IT.” Responsibility still needs a human name attached to it.
Rather than asking, “Do we have AI governance?” I want to give you a more practical diagnostic. Three questions: Awareness. Permission. Ownership.
If you have the accompanying Three Questions graphic, have it in front of you now. Just listen to each question and notice how easy — or difficult — it is to answer.
The first is the Awareness Question. Could you answer right now, with confidence, what AI your people are officially using — and what may be happening outside leadership visibility?
The official picture is usually easier. Which tools have been approved? Which teams are formally using AI? The harder question is whether that picture matches the working day.
Someone wants a faster first draft. Someone needs help analysing information. Someone experiments with a tool because it solves the problem in front of them. That does not automatically mean bad intent. But it can create a gap between the AI leadership knows about and the AI people are actually using.
And that matters in two directions. There may be risk you cannot see: sensitive information entering the wrong tool. But there may also be useful practice you cannot see: something that genuinely helps a team — but that nobody is learning from or considering whether to scale.
So Awareness is not simply about control. It is about understanding reality. If you cannot see the AI use, you cannot govern the risk properly. But you cannot learn from the value properly either.
If your immediate answer is, “I’d need to ask somebody,” notice that.
Now the second question. Permission.
Could you tell your team clearly what good AI use looks like in your organisation — what is encouraged, what is off limits, and why?
This is deliberately different from asking, “Do you have an AI policy?”
Imagine someone comes to you tomorrow and says, “I’d like to use AI for this piece of work. Is that okay?” Can you explain the boundary? Do they know what information should stay out? When a human needs to review the result? Who to ask if the situation is unclear?
Or does the answer become, “I think that’s probably okay.” “You’d better check.” “I’m not entirely sure what the policy says.”
That uncertainty matters. Some people will move ahead anyway. Others will avoid useful AI because they are worried about doing the wrong thing.
Permission means people understand the organisation’s position well enough to use it in a real decision. Could you explain what good AI use looks like here — without reaching for a document?
Then the third question. Ownership.
Is there a named person responsible for AI governance — with real time and real authority to act?
Not a department. Not: “IT handles AI.” Not: “Legal is looking at it.” Not: “We have a working group.” Who is the person?
Because naming somebody is not the same as creating ownership. Do they have time? Do they have enough authority to act? Can they reach leadership when something needs deciding? Without those things, ownership can become symbolic.
If somebody asks you tomorrow, “Who owns AI governance here?” could you name the person? Would they give the same answer? And does that answer mean something in practice?
Now bring the three questions together. Awareness. Permission. Ownership.
And answer them personally. Do not answer on behalf of the organisation. Do not answer what you hope is true. Answer what is visible to you.
First: Awareness. Could you answer right now — with confidence — what AI your people are officially using and what may be happening outside leadership visibility? Give yourself a moment.
Now: Permission. Could you tell your team clearly what good AI use looks like here — what is encouraged, what is off limits, and why? Could you explain it without checking anything?
And finally: Ownership. Is there a named person responsible for AI governance — with real time and authority to act? Who is it?
Now look at your three answers. Which one was hardest? Not which sounds most important in theory. Which one could you not answer with confidence?
Awareness? Permission? Or Ownership?
That is the gap I want you to keep. Because something previously vague has now become more specific.
“We need better AI governance” is difficult to act on. “I don’t know what AI people are actually using” is useful. “Our people cannot easily tell what is permitted” is useful. “We do not have a clearly supported owner” is useful.
Now you know where to look.
And your next move does not need to be enormous. If Awareness was hardest, start with a conversation about what AI is actually being used, where it is helping, and what need people are trying to meet.
If Permission was hardest, test whether somebody doing real work can understand the boundaries without having to interpret a policy for themselves.
And if Ownership was hardest, put a name against the responsibility — then test whether that person has the time and authority to make the ownership real.
The purpose is not to build perfect governance overnight. It is to turn an abstract concern into something visible enough to act on.
So reconstruct the logic. AI governance is broader than a policy. It combines clear boundaries, appropriate safeguards and human accountability.
Awareness asks whether you understand the reality of AI use. Permission asks whether people know what good AI use looks like here. Ownership asks whether somebody is genuinely responsible, with the time and authority to act.
Three questions. Simple enough to remember. But difficult to answer convincingly if governance exists mainly as intention.
Before we finish, three questions to leave with you.
Of Awareness, Permission and Ownership, which could you not answer confidently without checking with somebody else?
What is the first piece of clarity you need in order to improve that answer — something you need to ask, see or have named?
And if your team asked you the same three questions thirty days from now, what would you want to be able to answer differently?
If this briefing has revealed a gap, that is useful. You do not need a perfect governance system overnight.
You need enough visibility to understand what is happening. Enough clarity for people to know how to act. And enough ownership for somebody to move the organisation forward.
That is where practical AI governance begins.
The Executive Foundations programme goes further into the questions underneath this diagnostic: the gap between AI activity and value, what governance actually requires, the risks leaders cannot simply delegate, the regulatory environment, and the leadership mindsets that make governance operate in practice rather than remain on paper.
But for now, keep the three questions in front of you. Awareness. Permission. Ownership.
And keep the one you found hardest. Because that is probably where your next leadership conversation needs to begin.
02 · Keep
The one-pager is yours.
Awareness, Permission and Ownership on a single page — for the next time AI governance reaches your agenda.
Download the quick-referenceOne page · print it, share it, pin it to the boardroom wall
Prefer it as an image? Download PNG
03 · If it was useful
The three questions go further.
Executive Foundations develops them across five short leadership episodes, with practical tools for the working week.
Explore Executive FoundationsThat’s everything. Enjoy the listen.

