Jay Hawkinson is a board-certified (NACD.DC) data and digital leader turning data into margin through AI, analytics and strategy.

Most of my work currently involves AI governance reviews, often ahead of a transaction, and I’ve seen one pattern recur over and over again.

Consider a mid-market manufacturer that runs a pricing engine producing daily recommendations, which the sales team acts on. The vice president of sales approved the model, and the data team built it. However, legal had never reviewed it, and the board had never heard of it.

Eighteen months later, a buyer asks in diligence who owned the pricing decisions the model produced. The vice president says the model made the recommendations, the data team says the vice president approved them, and the CFO says pricing is a sales function.

Three people, three answers, nothing in writing.

This is a composite example, and the details can vary, but the three-answer problem doesn’t. I’ve encountered the same structure inside a $5 billion industrial manufacturer and a $6 billion global food company before I saw it raised in a diligence room.

What failed in these cases was the authority structure around the models. In all of the cases, nobody could answer a question from outside the company on a deadline.

Internally, ambiguity about who owns a decision is survivable, because people route around it. Under outside scrutiny, it becomes a finding, and by then it cannot be fixed.

What Most Governance Documentation Actually Contains

AI governance frameworks are usually careful documents, and they satisfy an auditor’s first request for evidence. What they rarely contain is a named person accountable for each AI-influenced decision, a record of who holds override rights and has used them, or an inventory the board has seen.

At a private-equity-backed global manufacturer where I led data governance work, roughly a quarter of the data domains had no business owner, simply because nobody had assigned the responsibility. The problem surfaced in on-time delivery. Operations reported 94% on a plant calculation, commercial reported 68% on a customer calculation, but nobody owned which number was right.

Naming an owner for that calculation ended the argument, and ending the argument allowed decisions to move forward.

Three Conditions For AI Ownership

After building data and AI functions at companies from $1.5 billion to $6 billion, and sitting across from boards as a chief digital and AI officer and National Association of Corporate Directors-certified director, I’ve found that three conditions are necessary to create ownership for sufficient AI governance:

A Named Owner For Every Material AI-Influenced Decision ​

Not the system owner or the team that built the model, but the executive accountable for what the output causes.

At a $2.5 billion global manufacturer, CRM adoption sat at 6% for years and the standard explanation was that people needed more training. But it turned out that employees knew how to use the system; they just didn’t want to. The sales managers didn’t enforce it because no one could explain why it mattered.

Adoption finally increased when accountability was designed: named owners by region, documented decision rights over the forecast and a platform those owners could run themselves. Once the forecast that leadership relied on had to originate in that system, and a specific person owned it, the data went in.

Adoption reached 89%, largely because people understood the purpose and had someone to ask what was needed.

An Escalation Path That Has Been Tested ​

Who can override the model, under what conditions, and what happens after? These read as administrative questions until a regulator, a litigant or a buyer asks them on a deadline.

At a $5 billion industrial manufacturer, we moved AI and machine learning models into production in 16 weeks because named owners, override protocols and board reporting cadence were settled before the build.

After the first features shipped, our environmental health and safety model, which was built to flag conditions that could lead to life-altering injuries, produced results none of us expected.

In this case, I worked with the named owner on a short project comparing our assumptions against the data. Because accountability was already assigned, that only took a phone call. Without it, it would have been a month of meetings about who was allowed to stop the model.

Reconstructability

For any material AI-influenced decision in the past year, the organization should be able to say which model version was running, who reviewed it, who approved it and what override rights existed.

At a $6 billion CPG company, a new COO inherited an AI-driven decision about which plant supplied a given product to a given region, and he questioned it. What he was really asking was whether he could trust the output. Walking him through the model version, the review and the person who signed off turned it into a conversation about adjusting to current conditions rather than an argument about blame.

Why This Became A Compliance Question

The EU AI Act’s Article 50 transparency obligations have been in effect since August 2, 2026. Fannie Mae’s Lender Letter LL-2026-04 took effect August 6, 2026, requiring seller/servicers using AI or machine learning to maintain written policies with a named owner who reviews them annually. Colorado SB 26-189 takes effect January 1, 2027, for automated decision-making technology used in consequential decisions.

Each of these regulations attaches responsibility to the organization using the system rather than the one that built it. Article 50 covers deployers, and the Fannie Mae letter extends explicitly to vendor and subcontractor use of AI.

Firms that inventory only the models they built themselves miss most of their exposure, because in a mid-market company most AI arrived inside a purchased platform nobody classified as AI.

What The Board Should Ask

Boards do not need to evaluate model accuracy. The useful questions are: Who is named as accountable for a system’s output? What is the documented process for overriding it? Could management reconstruct tomorrow who approved what, and on which model version?

If those answers come from memory rather than a document, the structure isn’t finished. In my experience, a first review surfaces three to five AI systems nobody had inventoried. Heading into diligence or a regulatory deadline, those gaps carry more weight than any model performance metric.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Exit mobile version