Skip to content
Marketing Profit Marketing ProfitSmarter Marketing. Greater Profit.

Why the First Conversation About AI Governance Is Almost Never With the Right Person in the Room

Most AI governance conversations start too low in the organisation and too late in the process. This article examines how the structure of those early conversations — not just their content — determines whether governance becomes embedded or merely performative.

There is a familiar pattern playing out inside regulated organisations right now. Someone in a mid-level technology or compliance role attends a conference, reads a regulatory update, or receives a vendor pitch. They become concerned — rightly — that their organisation needs to think seriously about AI governance. They schedule a meeting. They bring in colleagues. Decisions get made, frameworks get chosen, and commitments get implied. Weeks or months later, a senior advisor finally enters the room and inherits a situation that has already been partially shaped by people who were not equipped to shape it.

This is not a criticism of those individuals. It is a structural problem. And in regulated industries, structural problems compound.

Why AI Governance Conversations Start in the Wrong Room

AI governance advisory conversations tend to begin at the wrong level for three interconnected reasons: organisational urgency, vendor incentives, and the deceptive accessibility of AI tools themselves.

When a regulator publishes guidance — whether that is the EU AI Act, the FCA's emerging expectations, or sector-specific operational resilience frameworks — the immediate pressure to respond lands on the teams closest to the technology. IT leaders, data scientists, risk analysts, and compliance officers begin researching what governance should look like. This is understandable. These are the people whose day-to-day work is most visibly affected.

Vendors and consultancies, aware of this dynamic, have calibrated their outreach accordingly. Sales and advisory conversations are designed to be accessible to the people most likely to answer the phone — which rarely means the Chief Risk Officer or General Counsel in the first instance. By the time those senior stakeholders are involved, the vendor relationship has already been established, the framing of the problem has already been set, and switching costs — psychological as much as financial — have begun to accumulate.

Meanwhile, AI tools themselves create a false sense of approachability. Because many AI systems have consumer-facing interfaces, there is a widespread assumption that governing them is similarly intuitive. It is not. The regulatory, ethical, legal, and operational dimensions of enterprise AI governance require a level of cross-functional seniority that cannot be replicated by a working group of well-intentioned mid-level professionals, however capable they may be individually.

The Compounding Risk of Late Senior Involvement

The risk of getting the first conversation wrong is not simply that you choose the wrong framework. It is that early conversations create path dependencies that become progressively harder to correct.

Consider what typically happens in those early-stage meetings. Vendors are evaluated using criteria that have not yet been validated by senior legal or risk leadership. Proof-of-concept projects are scoped without adequate consideration of how they might look to a regulator. Internal working groups are formed with terms of reference that implicitly exclude board-level accountability. Documentation practices are established that may later prove inadequate for regulatory scrutiny.

Each of these decisions is, on its own, recoverable. In combination, they create a governance architecture that reflects the assumptions of the people who built it — and those assumptions were formed without the benefit of senior advisory input. When a qualified AI governance advisor eventually enters the picture, they are not starting from a blank page. They are inheriting a structure that may need to be partially dismantled before it can be properly rebuilt.

For regulated firms, this matters acutely. Regulators are increasingly interested not just in whether organisations have AI governance policies, but in whether those policies are embedded in decision-making at the appropriate level. A governance framework that was designed from the bottom up, without senior sponsorship from the outset, is likely to show the seams under scrutiny. The compounding risk is reputational as well as regulatory: firms that present governance as a retrofit rather than a design principle are signalling that it is performative rather than substantive.

How Early Conversation Structure Shapes Governance Outcomes

Content matters in governance conversations. But structure matters more, and it matters earlier.

The structure of a conversation determines who speaks with authority, which questions get asked, which risks get surfaced, and — critically — which assumptions go unexamined. A conversation between a technology vendor and a data engineering team will have a fundamentally different structure than a conversation between a senior AI governance advisor and an executive committee. The outputs of those conversations will differ not because the participants have different views on the same information, but because they are operating with different information sets, different risk tolerances, and different accountability frameworks.

Early conversations that lack senior structural authority tend to produce outputs optimised for feasibility rather than fitness. Working groups ask: what can we implement? Boards ask: what should we implement, and what are the consequences if we get it wrong? The gap between those two questions is precisely where governance risk accumulates.

There is also a subtler structural issue. When governance conversations begin without senior advisory involvement, the vocabulary of governance tends to be set by whoever is in the room. Terms like 'AI risk', 'model governance', 'explainability', and 'human oversight' acquire specific meanings within organisations — meanings that may diverge significantly from how regulators, courts, or senior advisors would use them. Realigning that vocabulary later is painstaking work. Establishing it correctly at the outset is considerably easier.

The Roles Most Likely to Trigger Premature Commitments

Understanding which roles are most likely to make consequential governance decisions before senior advisors are engaged helps organisations design better escalation protocols.

Chief Technology Officers and Heads of Data and AI are often the first to recognise the need for governance structures. Their instinct — commendably — is to build. But building before the regulatory and legal implications have been assessed at senior level creates the risk of constructing a framework that needs to be substantially revised once those assessments are complete.

Compliance officers and risk managers occupy a similarly exposed position. They understand the regulatory landscape in general terms, but AI-specific regulatory risk is a specialist domain that sits at the intersection of technology law, financial regulation, data protection, and operational resilience. Generalist compliance professionals are not always equipped to identify where standard risk management frameworks are inadequate for AI-specific exposures.

Procurement teams represent a third category of risk. When AI tools are evaluated and selected through standard procurement processes — without AI governance advisory input — the due diligence criteria applied may not capture the governance-relevant dimensions of those tools: model transparency, data lineage, audit trail capability, and regulatory alignment. A tool that passes a standard procurement review may nevertheless introduce material governance risk that only becomes visible when a senior advisor examines the contract and technical documentation.

In each case, the issue is not incompetence. It is scope. These roles are operating appropriately within their defined remits. The problem is that AI governance, properly understood, exceeds any individual remit. It requires coordinated senior oversight from the outset.

What Qualified AI Governance Advisory Actually Requires

Qualified AI governance advisory is not a single discipline. It is a synthesis of capabilities that rarely coexist in a single individual or team, which is precisely why the advisory relationship needs to be structured carefully.

At minimum, effective AI governance advisory requires: deep familiarity with the applicable regulatory landscape across relevant jurisdictions; the ability to translate technical AI concepts into legally and operationally meaningful terms; experience working with boards and executive committees on risk and accountability frameworks; and the independence to challenge organisational assumptions rather than simply validate existing plans.

This last quality — independence — is frequently undervalued. Internal governance teams, however capable, are subject to organisational pressures that affect their ability to surface uncomfortable findings. External AI governance advisors who are genuinely independent — not commercially tied to specific technology platforms or implementation contracts — are better positioned to provide the kind of frank assessment that regulated firms need before they commit to a governance approach.

It is also worth being precise about what AI governance advisory is not. It is not a technology audit. It is not a data protection review, though it will intersect with one. It is not a vendor evaluation, though it will inform one. And it is not a policy drafting exercise, though it will generate policies. AI governance advisory is a senior strategic function that integrates technical, legal, regulatory, and organisational dimensions into a coherent and defensible governance posture. Treating it as anything less — or engaging it at anything less than senior level — is a category error with material consequences.

Building a First-Conversation Framework That Holds

Organisations that want to avoid the structural pitfalls described above need to be deliberate about how they design their first AI governance conversation — before it happens, not after.

The first step is establishing a clear principle: no governance commitments, however provisional, are made without senior advisory involvement. This sounds simple. It is culturally demanding. It requires middle-level teams to hold the line when vendors push for accelerated timelines, when internal stakeholders are eager to show progress, and when the pressure to demonstrate regulatory responsiveness is acute.

The second step is defining what 'senior advisory involvement' actually means in this context. It should mean, at minimum, that a qualified AI governance advisor — internal or external — has been engaged, has reviewed the proposed approach, and has confirmed that it is appropriate to proceed. This is a higher bar than many organisations currently apply, but it is the appropriate bar for regulated firms operating in an environment of increasing AI-specific regulatory scrutiny. Guidance such as the OECD Principles on AI provides a useful cross-jurisdictional reference point for what senior-level accountability in AI governance should encompass.

The third step is mapping the escalation pathways that should exist between the teams most likely to initiate governance conversations and the senior advisors who need to be involved. These pathways should be documented, tested, and understood before they are needed — not constructed in the moment when a governance issue surfaces.

Finally, organisations should consider the first conversation itself as a governance artefact. Who attended? What was decided? What was left open? What assumptions were made and on what basis? Documenting the provenance of governance decisions — including the earliest ones — is not bureaucratic overhead. It is evidence of the kind of embedded, senior-led governance culture that regulators are increasingly looking for and that genuinely protects organisations when things go wrong.

The structure of that first conversation is not a procedural detail. It is a signal — to regulators, to auditors, and to the organisation itself — about whether AI governance is being taken seriously from the start, or retrofitted after the fact. For regulated firms, the difference between those two trajectories is consequential. Getting the right people in the room, from the very first conversation, is where that difference begins.

Find out more

AI governance advisoryregulated industriesAI riskcompliancesenior leadershipAI strategygovernance frameworksregulatory risk
← All posts