Most AI governance I see in large companies is doing the opposite of what it was meant to do. It is slowing the business down, and the best people are quietly routing around it anyway.
I have sat on both sides of this and that is why it bothers me so much. As a CIO I was the person accountable when AI showed up everywhere at once and nobody could tell me what was running, who was running it, or on what data. And as a builder I have been the person who quietly used a tool because the approved path was too slow to be worth the bother. Both of those things are true at the same time, and honestly that tension is the whole problem.
So when a leadership team tells me they have AI governance handled, I have learned to ask one question. Is it actually operating, or is it a policy sitting in a folder that everyone nodded at once and nobody follows.
What governance usually becomes
Governance, the way most firms end up doing it, is a list of things you are not allowed to do. A policy, an approval queue, and a committee that meets once a month. It manages risk by adding friction, and on paper that feels responsible. The reality is different. Your smartest people, the ones actually creating value with these tools, hit the friction, decide it is not worth the wait, and find their own way around it. Now you have the risk you were trying to control, except it is invisible, and you have annoyed the exact people you most want to keep.
The other failure mode is the strategy deck. A big AI governance document that satisfies the board for a quarter and changes nothing about how the work actually happens. I have seen plenty of those. They make everyone feel safer for a while and then the gap between the document and the day to day quietly widens.
What operating control actually is
Operating control starts from a different place. It is not about telling people what they cannot do. It is about being able to see what is happening, fund the work that is worth funding, and contain the risk that needs containing, all built into how the work already runs.
You can see which tools are in use, by whom, on what data, and at what cost. You can tell which initiatives are real and which are productivity theatre. You can move the good work from experiment to production with the controls matched to what could actually go wrong, instead of one heavy process applied to everything regardless of risk.
Governance asks permission. Operating control gives you a clear view and a fast safe path. People prefer the second one, so they actually use it.
Minimum viable control
The phrase I keep coming back to is minimum viable control. Enough structure to scale safely, and not one bit more than that. Enough to answer the board honestly, to own the spend, and to stop the genuinely risky stuff early. Not so much that you smother the people doing the interesting work.
This is the bit a lot of compliance vendors get wrong. They sell you more control as if more is always better. In my experience more control past a certain point just pushes the activity underground, which is the opposite of what you wanted. The skill is knowing where that line sits, and that comes from having actually built and run this stuff, not from reading about it.
The difference that matters
Here is the simplest way I can put it. Governance is defensive. It is mostly about not getting in trouble. Operating control is about moving faster with your eyes open. Same concern underneath, completely different posture, and the business can feel the difference straight away.
When the control layer is good, the safe path is also the fast path. Your people choose it because it removes work, not because a policy told them to. That is when you know it is working. Nobody is being policed and the risky behaviour is just quietly disappearing because there is a better default sitting right there.
Where to start
You cannot control or scale anything you cannot see, so seeing it is always the first move. That is what a FitCheck does. It maps where AI is actually being used across the business, what value is emerging, where the risk is piling up, and which initiatives are worth backing, all scored against your own evidence rather than my opinion.
If you are not sure whether what you have is real operating control or just a policy in a folder, that is exactly the gap a FitCheck shows you, and it does it in a few weeks rather than a few quarters. If you want to find out where you stand, book a working session and we will map it together.