Cape Town, South Africa
Part 2: The not so Sexy AI & Data Governance
Home  ∣  AI   ∣   Part 2: The not so Sexy AI & Data Governance

Part 1: The AI Executive

Part 2: The not so Sexy AI & Data Governance

Part 3: Measure What Matters

Part 4: A new software Play Book

Part 5: The Engine Room

In my previous post, I argued that every enterprise is running its own bespoke race with artificial intelligence, navigating uncharted terrain without a standard playbook. Yet the moment you transition from theoretical strategy into actual execution, you slam directly into the elephant in the room: AI governance. Depending on where you sit, that reality looks completely different.

If you are running a startup, you have no choice. You must lean into AI immediately. Survival is the only metric that matters, and burning precious runway on compliance committees before finding product market fit is corporate suicide. If you are an SME, you have no excuse. Your footprint is manageable, your technical debt is smaller, and organizational inertia cannot justify sitting on your hands.

The real struggle belongs entirely to the large listed enterprise. They are in for a brutal journey.

The standard narrative claims that enterprise leadership lacks the appetite for risk, but that completely misses what is happening on the ground. The board wants progress. Executive leadership demands speed. The true bottleneck is the corporate immune system, where middle management, legal reviews, procurement queues, and security panels stall momentum. These teams are not villains. They are well intentioned professionals trapped in theoretical panic. I have spent months sitting in soul crushing governance reviews. When you press security teams on the actual origins of their restrictive policies, the truth slips out. They are doing research, but they are relying on benchmark papers and synthetic lab tests conducted in sterile environments. Those experiments have zero relevance to real world enterprise systems. Real enterprises do not live in clean research labs. They run on a messy, sprawling landscape of Python, C#, and TypeScript services, tangled up with decades worth of bolt on ERP platforms, fragmented CRMs, legacy BI tools, and ancient SOAP or XMLRPC endpoints, if you are lucky enough not to be running a sixty year old COBOL backbone. Suddenly, a simple proof of concept requires months of jurisdictional acrobatics. An enterprise cannot hold direct contracts with American providers, so software licenses must be routed through European entities. If engineers want frontier models, they are forced through cloud proxy layers just to satisfy compliance optics. When you peel back the layers, it quietly traces back to an unverified anxiety that corporate data will magically vanish into the model. Meanwhile, actual technical practice exposes how hollow that fear really is. With sound architecture, sensitive data never leaves corporate boundaries. Finance teams can generate income statements and balance sheets using models while the underlying raw numbers remain locked securely inside internal repositories, completely untouched by external training loops. Guarding against downside risk makes sense when an hour of operational downtime costs millions of euros. Yet by anchoring policy to academic papers rather than operational reality, the organization guarantees slow, inevitable irrelevance.

Engineering leaders cannot defeat theoretical fear with abstract logic. You have to change the battlefield entirely. Stop asking committees to imagine how AI might behave. Build focused, functional proofs of concept under your operational radar. Place them into secure, controlled environments. Then walk into the room and hand compliance teams working software with explicit architectural boundaries rather than conceptual slide decks. Force the governance apparatus to evaluate tangible code instead of ghost stories. If enterprise AI is going to deliver real value, policy must stop coming from sanitized research labs and start getting forged in running systems.

Yet breaking through governance gridlock only solves the first half of the equation. Once you finally get permission to build, you immediately collide with the next corporate obsession: measuring return on investment. In Part 3, we will tackle the madness of premature AI KPIs, why demanding linear ROI in Year 5 of an emerging technology is pure fantasy, and how to measure real adoption before the bean counters kill your momentum.

Comments are closed!