I have set a decision threshold on a fraud model. I have also sat as secretary to a committee that approves things. AI governance looks like two different problems from those two chairs, and the distance between them explains most of why the conversation online is such a mess.
Everybody has an opinion on how AI should be governed. Fewer people have watched a governance process actually run, and fewer still have been the person whose quiet technical choice the process was meant to catch. I have been in both positions, so let me first set out what AI governance actually contains, and then say what it looks like from inside.
What AI governance actually includes
Governance is not one thing. It is a set of components that have to work together, and most organisations have some of them and assume they have all of them.
Policy and regulation. The external rules an organisation has to answer to. The EU AI Act, which classifies systems by risk and attaches obligations accordingly. Sector rules in health, finance and education. Voluntary standards such as ISO/IEC 42001 for AI management systems and the NIST AI Risk Management Framework. These set the floor. They do not tell you how to run a Tuesday.
Organisational structures. Who decides. Ethics committees, review boards, named accountable owners, escalation routes for the hard cases. This is the component that determines whether anything else happens, and it is the one most often reduced to a diagram in a slide deck.
Risk management. Classifying systems by how much harm they can do, assessing impact before deployment rather than after, red teaming, and having a route for reporting incidents when something goes wrong. A recommendation engine for internal documents and a triage tool in a casualty ward should not go through the same process.
Data governance. Where the training data came from, whether the people in it consented, whether it is accurate, how long it is kept and who can see it. Most of the serious failures I have read about were data failures wearing an algorithm’s clothes.
Transparency and documentation. Model cards, system cards, disclosure that a person is dealing with an automated system, and an explanation of consequential decisions that an ordinary person can follow. If a system declines someone a loan or a place on a course, someone must be able to say why in a sentence.
Fairness and safety testing. Measuring whether the system performs equally across groups, and doing something when it does not. This is harder than it sounds, because fairness has several mathematical definitions and they are not all satisfiable at once. Choosing between them is a value judgement, not a calculation.
Monitoring and oversight. The world changes after deployment. Data drifts, populations shift, behaviour adapts. Governance includes checking that the system still works six months later, keeping a human in the loop where the stakes justify it, and knowing how to switch it off.
Procurement and third party management. Most organisations will buy far more AI than they build. Due diligence on vendors, contractual terms on data use, liability and model updates. This is where governance either becomes real or becomes decorative, because it is the point at which you still have leverage.
These sit at three levels. International, where principles are set by bodies such as the OECD. National and regional, where statutes and regulators operate. Institutional, where an organisation writes its own policies and runs its own reviews. Almost all the practical work happens at the third level, and almost all the online commentary happens at the first two.
The view from the model
Now the part that is mine.
From the builder’s chair, governance usually arrives late. You have finished the work. The model performs. Then a form appears asking about fairness, data provenance and intended use. It feels like paperwork attached to a decision already made, so it gets filled in the way people fill in anything that cannot change the outcome.
But the consequential decision was made earlier, and quietly.
When I built FraudLens, an XGBoost model for detecting fraudulent transactions, the figure I reported was an average precision of 0.860. That figure is engineering. The threshold is not. Setting a threshold is deciding who gets hurt. Move it one way and more fraud passes through, and the institution absorbs the loss. Move it the other way and more ordinary people are locked out of their own money on a Friday afternoon with nobody to call, and they absorb it instead.
I chose that threshold alone, at my desk. No committee was in the room. Nothing in the workflow suggested one should be. Every component I listed above was, in principle, applicable to that moment. None of them reached it.
That is the thing I would want a governance specialist to understand. The ethics of a model are not mainly in the model. They are in a handful of small choices about objectives, cut-offs, error costs and who bears them, made by one person in an ordinary afternoon, framed as technical work because that is what the surrounding process calls it.
The view from the committee
Ten years of committee and secretariat work has taught me something less flattering about the other side.
Governance in practice is rarely about ethics in the abstract. It is about the calendar. The paper that arrives the night before. The item deferred three times because the person who could answer the question was travelling. The approval sought after the contract is signed, when saying no costs more than saying yes. Committees do not usually fail because their members lack principles. They fail because they are handed finished work and asked to bless it.
I have watched capable, conscientious people approve things they had questions about, because the questions arrived at a point in the process where asking them would have cost three months and somebody’s budget. That is not an ethics problem. It is a sequencing problem, and sequencing is administrative work.
Where the two chairs fail to meet
Put them side by side and the picture is uncomfortable. The person making the consequential choice often does not recognise it as one. The body meant to oversee that choice sees it only when reversing it has become expensive.
So the useful question for an organisation is not whether it has an AI policy. Most policies I have read would not have changed my threshold. The question is narrower, and harder. At what point in the build does someone other than the builder see the tradeoff, and can they still change it?
Three changes would do more than another framework.
Review at design, not at deployment. The moment worth governing is when the objective, the error costs and the threshold are chosen. By packaging time the decision is a fact and the review is theatre.
Require the builder to state the tradeoff in one sentence a non-technical person can argue with. “At this setting, roughly one in twenty flagged accounts belongs to someone who did nothing wrong.” A committee can debate that sentence. It cannot debate a confusion matrix, and it will not admit that in the meeting.
Give the reviewing body the power to say not yet, and make sure that power exists before go-live. Authority that only arrives after launch is not authority. It is commentary with minutes attached.
None of this is exotic. It is sequencing, scheduling, and asking for the right sentence at the right time. It is administrative work, which is precisely why it keeps getting skipped, and precisely why it keeps mattering.
Governance that arrives after the threshold is set is not governance. It is minutes.
First published on LinkedIn on 1 September 2026. Read the original.