tgroenwals shared this post · 2h ago
Carolyn Healey

Your AI governance policy exists.

Your AI governance policy exists.

Your organization's behavior doesn't match it.

McKinsey just put a number on the gap.

Enterprise Responsible AI maturity averages 2.3 out of 4 in 2026, up from 2.0. But fewer than a third of organizations have reached level 3 in the dimensions that matter most: strategy, governance, and agentic AI controls.

Most executives think of "AI governance readiness" as binary: you either have it or you don't. That's the wrong frame.

Readiness is a ladder, and most organizations are standing on a lower rung than the board deck suggests.

Here are the 7 levels I use to diagnose where an organization actually sits:

1/ Undocumented

→ No formal policy. No named owner. AI usage tracked informally, if at all.
→ Shadow AI is the default state, not an exception.

Reality: This is more common at enterprise scale than leaders admit publicly.

2/ Aware, Unowned

→ Leadership acknowledges the risk in principle.
→ No one has the authority, budget, or mandate to act on it.

Reality: Awareness without ownership is a liability disclosure, not a control.

3/ Policy on Paper

→ A governance document exists and has been approved.
→ It is not embedded in procurement, engineering workflows, or vendor contracts.

Reality: PwC found 61% of organizations have reached a strategic or embedded stage of Responsible AI, but only 33% have actually embedded it into core operations and decision-making.

4/ Pilot Pockets

→ One team, one business unit, or one function governs AI well.
→ Nothing about that practice transfers anywhere else.

Reality: A center of excellence is not an operating model. It's a case study waiting to be scaled or ignored.

5/ Enterprise Standard

→ Controls are consistent across business units.
→ They were built for predictive models and haven't been re-tested against agents that take action.

Reality: This is where most organizations believe they are. It is not where most organizations are.

6/ Monitored and Measured

→ Live dashboards. Defined KPIs. A board reporting cadence that actually happens.
→ Still fundamentally reactive; governance responds to incidents rather than anticipating them.

Reality: Only 21% of organizations deploying agentic AI report a mature governance model for it, even as 74% plan to expand agent deployment within two years (Deloitte, 2026).

7/ Adaptive and Accountable

→ Governance evolves at the same pace as deployment, not two budget cycles behind it.
→ Every autonomous action maps to a named accountable owner — not a policy, a person.

Reality: The question boards need to be asking is no longer "is the model accurate?" It is "who is accountable when the system acts?" (McKinsey, 2026).

Organizations that can't answer that in one sentence are not at level 7, regardless of what the governance binder says.

Save for future reference.

Ángel Cárdenas-Bahena I like the distinction between having governance and being able to demonstrate that it actually operates in practice.

The progression toward adaptive and accountable governance is particularly important. But accountability may raise another question: is knowing who is accountable enough to understand whether a decision was sound?

An autonomous action can have a named owner, follow established controls, and remain fully traceable, while still being influenced by weak assumptions, incomplete evidence, or biases embedded in the reasoning behind the decision.

As AI becomes more involved in consequential decisions, governance may need to examine not only who authorized an action and whether the rules were followed, but also the quality of the reasoning that led to it.

Perhaps maturity will increasingly depend on making that reasoning visible enough to challenge, review, and learn from.
Paul Souhuwat This is a useful distinction, Carolyn.

The gap between policy and behavior is, perhaps, the more important governance measure.
An institution can have an excellent governance framework and still behave as though it has none.

The real test is what happens when the policy meets an actual decision: who has the authority to act, who owns the consequence, and whether the control is embedded in the workflow rather than left in a document.

In that sense, governance maturity is less about having more rules and more about making the right behavior increasingly institutional rather than dependent on individual vigilance.

AI simply makes that distinction much harder to hide.