Skip to main content
SIM ReThink Everything! · Technology Brief

The Missing Layer

Rethinking AI Governance as Organizational Architecture

By Sonny Claussen (CEO, Bee360) and Beverly Lovett

30 Second Read

Somewhere in your organization, right now, an AI is doing work nobody approved, on a budget nobody set, producing value nobody measures. That is not a hypothetical. McKinsey’s latest global survey puts AI in 88% of enterprises — while fewer than one in ten organizations report a comprehensive governance framework, and only 39% can point to any earnings impact from AI at the enterprise level.

The instinctive fix is policy: an AI policy, an ethics statement, a compliance program aimed at the EU AI Act. But policy is not what separates the organizations scaling AI from those stuck in pilots. In field research with CIOs, not one reported governance slowing them down; half reported governance that exists only to prevent misuse, and a third reported none at all. The constraint is not too many rules. It is the absence of an operating model: nobody can say who owns each AI, what it costs, or whether it works.

This brief names that absence the missing layer, shows why the compliance frameworks everyone is buying cannot supply it, gives you a one-question test for sorting the AI you must govern, and closes with a self-assessment you can score before your next leadership meeting.


Executive Summary

The argument in six findings:

  • The gap is organizational, not technological. Field research at the MIT Sloan CIO Symposium 2026: 50% of CIOs run reactive guardrails, 35% have no AI governance at all, and only 15% deliberately design decision rights. The top barrier to scaling AI is failing to redesign the work itself — and McKinsey’s survey of ~2,000 organizations agrees: workflow redesign is among the strongest of 31 tested drivers of AI impact.
  • The analysts have converged on this reading. Gartner (AI TRiSM), Forrester (AEGIS, agent control plane), and Info-Tech (Adaptive AI Governance) all now frame AI governance as a continuous operating discipline, not a policy artifact.
  • AI governance is two layers doing different jobs, and most stalled programs build only one. Architecture answers the economic questions: worth doing, who owns it, what it costs, does it deliver. Enforcement answers the behavioral questions: what it allowed, is it compliant, is it behaving at runtime. Enforcement tools assume the architecture exists. Usually, it does not.
  • One question routes everything: technology or teammate? AI that executes with a human in the loop is governed like an application. AI that acts autonomously, with humans on the loop, must be governed like a member of the org chart: with an owner, budget, priorities, and a job description.
  • The blind spot is AI resource governance. Research on IT chargeback systems showed a decade ago that traditional cost-control models were designed for stable, predictable resource patterns (Baars et al., 2014). AI inverts that — spend is variable, workload-shaped, and scales with autonomy. “I want ten million dollars of tokens” is a budget request few existing processes are equipped to evaluate.
  • Foundations first is both the prerequisite and the fastest start. Inventory, ownership, cost visibility, decision rights: weeks of work, not years, and it doubles as the basic IT governance. You cannot govern your AI if you do not govern at all.

1 · The Deficit Nobody Planned

AI crossed from experiment to default without asking permission. By 2025, McKinsey’s global survey found 88% of organizations running AI in at least one business function, yet fewer than one in ten maintained anything a rigorous observer would call a comprehensive governance framework (McKinsey & Company, QuantumBlack, 2025). The value picture is starker still: only 39% of organizations report EBIT impact from AI at the enterprise level, and more than 80% see no tangible enterprise-wide earnings effect from gen AI at all (McKinsey & Company, 2025). The project-level data matches — S&P Global (2025) finds 46% of AI projects scrapped between proof of concept and broad adoption, and Gartner projects that 60% of AI projects lacking AI-ready data will be abandoned by 2026 (Gartner, 2025) — while the value that is created concentrates sharply: BCG’s “future-built” minority of companies generates 1.7 times the revenue growth and 1.6 times the EBIT margins of peers, and the gap is widening (BCG, 2025). Agentic systems will widen it further: Deloitte finds 74% of enterprises planning to adopt agentic AI within two years, while only 21% have a mature governance model for it (Deloitte, 2025).

The reflexive response is regulation-shaped: write the policy, stand up the committee, buy the compliance platform. The evidence says the reflex misdiagnoses the problem. In a field survey of technology leaders at the MIT Sloan CIO Symposium 2026, half described their governance posture as preventive guardrails — policies written to prevent misuse — and more than a third admitted to no AI governance structure at all. Only 15% had reached what Schrage and Kiron (2025) call governance as architecture: the deliberate design of decision rights and accountability. The most telling number was zero: not a single respondent said governance was slowing their AI work down. Organizations do not suffer from too much AI governance. They suffer from the wrong kind.

Asked for the single biggest barrier to making AI a core operational capability, the same leaders did not name data quality, talent, or model performance. The plurality answer, at 40%, was adding AI to existing processes without redesigning the work itself. McKinsey’s (2025) far larger sample lands in the same place: high performers are nearly three times as likely to have fundamentally redesigned workflows, and in a relative-weights analysis of 31 variables, redesign made one of the strongest unique contributions to business impact of any factor tested. Data quality is a genuine co-factor — it is the stated basis of Gartner’s (2025) abandonment projection — but in both McKinsey’s (2025) weighting and the field data (workflow at 40% versus data condition at 15%), the organizational variable outranks it. That ordering relocates the whole problem. If the barrier is organizational, the governance response must be organizational too — and no amount of policy or runtime tooling substitutes for it.


2 · Two Markets Wearing One Name

Ask what “AI governance” means and you receive two answers that rarely acknowledge each other.

The first is regulatory. It orbits a handful of frameworks that now anchor every serious program: the EU AI Act, binding law with risk-tiered obligations and enforcement phasing in through 2026 and 2027 (European Union 2024); the NIST AI Risk Management Framework, the de facto American baseline built on four functions — govern, map, measure, manage (NIST, 2023); ISO/IEC 42001, the first certifiable management-system standard for AI, increasingly demanded in procurement (ISO/IEC 42001:2023); and the OECD principles as ethical scaffolding (OECD, 2024). The two regimes run on different clocks. Europe regulates ex ante, through binding horizontal law with extraterritorial reach: any organization serving EU markets is in scope, wherever it is headquartered. The United States has no horizontal federal AI statute; it governs through the voluntary NIST framework, a growing patchwork of state laws, and sectoral regulators. These frameworks specify what an organization must be able to demonstrate: risk assessment, documentation, human oversight, post-market monitoring. What none of them specifies is how to build the organization that produces those demonstrations. The EU AI Act says you must have a management system. It does not tell you who decides, who pays, or who answers when an AI is wrong.

The second answer is operational, and it is where the actual pain lives: shadow AI in personal accounts, agents accumulating faster than anyone can register them, invoices that jump 30% with no attribution, and freed-up hours that vanish without a trace. This layer is about inventory, ownership, intake, budgets, and monitoring — the unglamorous machinery of running AI as a managed capability rather than a phenomenon.

What makes 2026 notable is that the major advisory houses, approaching from three different directions, have all landed on the operational reading. Gartner’s AI TRiSM argues that policy establishes intent but cannot enforce behavior, and pushes toward continuous, embedded controls — extending in early 2026 to “guardian agents” as the runtime enforcement mechanism for agentic systems (Gartner, 2025, 2026). Forrester runs a dual track: AEGIS, a regulation-aware control set whose every control maps to both NIST and ISO 42001 (Forrester, 2025); and an agent control plane thesis holding that governance must sit outside build and orchestration environments — explicitly flagging cost attribution to business value streams as an unsolved gap (Forrester, 2026). Info-Tech went furthest in naming, publishing an Adaptive AI Governance program on the premise that static oversight cannot keep pace with agentic AI and that governance is a shared organizational responsibility, never a compliance-only function (Info-Tech Research Group, 2026).

Three research houses, one conclusion: AI governance is a continuous organizational operating discipline. The conclusion is correct — and it is incomplete, because all three still under-specify the layer this brief now turns to.


3 · Governance as Architecture

If governance is organizational, the question becomes: what, exactly, is being designed? The sharpest available answer comes from research on decision rights. Schrage and Kiron (2025) argue that AI does not merely automate decisions; it rewrites who holds the authority to make them, and that organizations capture AI’s value only when they redesign those rights deliberately — governance as architecture, in their phrase. Westerman describes a companion leadership approach, which he calls “directive emergence”: set an unambiguous direction, then adjust continuously as evidence arrives, rather than executing a plan fixed at the start (Lazzaro, 2025). The field research found this stance already dominant — a majority of CIOs described their role in precisely these terms. The catch is that steering by evidence requires being able to see the evidence. Every framework tells leaders to steer; almost none equips them to see. And the empirical case for this layer is now direct: in McKinsey’s 2025 analysis, CEO oversight of AI governance was the single element most correlated with bottom-line impact from GenAI among 25 attributes tested — and the tested attributes explicitly included how organizations manage the time employees save. Governance ownership and capacity tracking are not compliance hygiene. They are, measurably, where the money is.

Architecture has one practical consequence that generic AI policies systematically miss: the right amount of oversight is not an organizational constant. “How much human in the loop?” has a different correct answer for an AI drafting meeting notes than for one approving invoices or informing a safety decision — and a different answer again in a consulting firm, where the dominant AI risk is reputational, than in mining or geotechnical engineering, where it is physical and legal. Oversight must be calibrated per process and per risk tier. Mature IT governance has always worked this way, applying tight control where stakes are high and freedom where learning matters. The move is not to invent a parallel, static regime for AI beside that logic, but to extend the adaptive logic to a new class of object.


4 · One Question That Routes Everything: Technology or Teammate?

Before you can govern an AI, you must classify first. A single compound question does the sorting: does the system merely execute instructions, or does it act autonomously — and does the work stay the same, or is the work redesigned around it?

Most AI is technology. It automates a step or augments a judgment; a human stays in the loop; the workflow survives intact. An assistant that imports data, summarizes documents, or flags anomalies for human review is technology, however sophisticated the model behind it. Technology belongs in the enterprise architecture and is governed like an application: an owner, a lifecycle, a cost line. Organizations already know how to do this; they need only extend the register.

A small but growing share of AI is a teammate. It exercises genuine agency across multiple steps; the human shifts from in the loop to on the loop; and the work is rebuilt around what AI can do. Consider an agent that monitors overdue timesheets, reminds employees three times per policy, escalates to HR, and drafts the consequence memo. That is not a feature. That is a junior colleague with a job description — and it should be governed as one: a named owner accountable for its behavior; a consumption budget, which is functionally its salary; explicit priorities, because an agent told to “research thoroughly” will happily spend without limit; and a ruleset written with the precision of a job description, because unlike a human hire, an agent cannot be gradually coached — the rigor must be front-loaded into its instructions, and when results disappoint, the fix is sharpening the rules, not redoing the work by hand.

The classification is not cosmetic. It determines where the AI is registered, who answers for it, how its cost is tracked, and which controls apply. And it is dynamic: the moment an automation is granted autonomy, it crosses the line, and the crossing — not the underlying technology — is what must trigger the heavier apparatus.

That distinction is also what makes the resulting inventory steerable, not merely visible. A technology and a teammate don’t surface the same signal, and steering only works if you’re watching the right one: a technology is steered by cost and lifecycle, on the cadence any IT asset already runs; a teammate is steered by behavior and consumption against its ruleset, and because an agent cannot be coached the way a person can, that sight has to convert into a rewritten rule immediately, not at the next scheduled review. Classify an item wrong and the mismatch runs exactly backwards — a technology managed with people-management intensity it doesn’t need, or an agent drifting for a quarter before anyone is watching the right thing. Sight, in other words, isn’t one thing. It’s defined by which track the AI sits in — and that is what turns ‘steer as you learn’ from instruction into something an organization can actually do.


5 · Two Layers, One Seam

The classification exposes the deeper structure of the whole field. AI governance is two layers doing different jobs, and most programs stalled because they built only one.

Governance as architecture answers the economic and organizational questions: Is deploying the AI worth it, given its cost-value ratio? Does it belong in the portfolio at all? Who owns it – meaning who is accountable for its performance and its budget? What does it cost to run, and how does that cost shift as AI takes over more of the process? Is it delivering the value it was deployed for? Where did the freed-up human capacity go? These are ownership and resource questions, and they are answered with muscles every mature IT organization already has — demand management, portfolio management, financial steering — pointed at a new object class.

Governance as enforcement answers the behavioral and compliance questions: What is this AI permitted to do? Is it conformant with the rules that apply to it — the EU AI Act, NIST, ISO 42001, emerging US state law? Is it behaving correctly right now, at runtime? For agents: does it have a controlled identity, monitoring, and a way to be stopped? This is the territory of the AI TRiSM platforms, model-risk tooling, and guardian agents.

Neither layer works alone, and the failure modes are symmetrical. Enforcement without architecture yields immaculate guardrails around initiatives nobody can justify: controls with no owner, no budget, no value case. Architecture without enforcement yields sound decisions that drift the instant the system runs in production: a plan nobody can enforce. The two layers meet at exactly one seam — the technology-or-teammate classification. Once an AI is classified, the architecture layer assigns its owner, budget, and priority, and the enforcement layer supplies its ruleset, identity, and monitoring. For most organizations, the practical implication is a deliberate pairing: an operating-model backbone on one side, a runtime and compliance capability on the other, joined by a single shared inventory. Vendors increasingly claim to span both, but execution on one side is usually much shallower than the other — scrutinize before buying.


6 · The Blind Spot: AI as a Consumable Resource

One governance dimension appears in almost no framework, yet surfaced immediately when CIOs spoke candidly: AI is a metered resource, and its consumption is a demand class that existing financial governance was never built to evaluate. One roundtable participant compressed it into a sentence: budget requests now arrive as “I want ten million dollars of tokens.” No standard annual planning process, business-case template, or chargeback model was built to evaluate that sentence.

The deeper issue is categorical: are tokens an expense, or a form of capital? If a team of three people plus agents now produces what a team of ten produced before, can the difference be capitalized — and who owns that token budget: the CFO, the CIO, the business owner? These are not hypothetical questions. A major European telecommunications company recently put the capitalization question to its asset-accounting function; the function was overwhelmed, and resolving it with the company’s external auditors is expected to take half a year. The processes are not merely unprepared — the accounting categories themselves are unsettled.

Traditional IT cost management assumes consumption that is stable and forecastable — headcount, licenses, infrastructure. AI inverts every assumption. Spend is variable, workload-shaped, and scales with autonomy: the same agent can cost fifty dollars or five thousand on the same task, depending entirely on how tightly its instructions bound the effort. The money can be spent faster than ever before; whether it becomes speed and value or merely sunk cost is decided by governance, not by the model. The FinOps community has already registered the shift — 98% of practitioners now manage AI spend, up from 63% a year earlier, per the State of FinOps 2026 report — precisely because AI costs refuse to behave like the cloud costs they had learned to tame (FinOps, 2026). The pattern itself is familiar: usage-variable pricing broke usage-invariant chargeback models when cloud arrived (Baars et al., 2014); AI repeats the inversion, steeper, because consumption now scales with autonomy rather than workload.

The correct response is not new machinery but familiar discipline aimed at a new object: every AI initiative as a living plan-versus-actual case rather than a one-time approval; consumption budgets and explicit priorities per initiative and per agent; and consumption connected to value. Note what this does not require: meter-level precision. Metering is maturing fast — the FinOps discipline has seen to that — and the missing layer sits above it: consumption budgeted per initiative and agent at the granularity decisions require, and value allocated with the same seriousness that cost is counted. Precision about cost with no value case is precision about the wrong question. On value, honesty is required: the measurement problem is real. Efficiency gains are easy to count but can cannibalize their own business case; genuinely new output — work that could not have been produced before — is harder to quantify but is the durable form of value. And the comfortable assumption that freed-up hours automatically flow to higher-value work deserves skepticism: unmeasured, freed time simply fills. The organizations that steer AI well are those that track where the hours actually went and can translate the answer into language a CFO will act on.


7 · Where to Start: Foundations First, and Fast

The most consequential finding is also the most liberating: the place to start is the bottom, and the bottom is cheap. In the field data, every organization at the lowest AI maturity level reported a complete governance vacuum — and the missing pieces were not AI-specific at all. They were the basics of governance itself: an inventory, named owners, visible costs, clear decision rights. You cannot govern your AI if you do not govern at all. Organizations that cannot list their applications or explain their spend have no substrate for AI governance to attach to — and, less obviously, the reverse is a gift: the urgency and budget that “AI governance” unlocks will fund the basic governance those organizations always needed. The same foundation serves both.

The staging then follows naturally. First, the foundation: a live inventory that includes the shadow AI already in the building — discovery before control, because you cannot govern what you cannot see; an owner for every significant AI use; spend made visible; decision rights made explicit. This is weeks of focused work, not a two-year program. Second, the AI-specific layer on top: risk tiering to calibrate oversight per process; the technology-or-teammate classification to route each system to the right regime; consumption budgets; and the enforcement pairing for runtime and regulatory obligations. Last, the architected state: decision rights engineered rather than inherited, oversight tuned per process, and agents managed as accountable actors with identities, lifecycles, and a kill switch.

The sequencing is the strategy. Leaders who race toward a comprehensive, compliance-first program before the foundation exists produce exactly the governance everyone dreads — slow, expensive, performative. Leaders who build the foundation first, framed around AI because AI is what commands attention, deliver visible value in a quarter and make every harder layer tractable. The foundation is not homework to finish before the interesting part. It is the interesting part, and it is available immediately.


8 · Conclusion

Every framework now tells leaders the same thing: set a direction and steer as you learn. The advice is sound and insufficient, because steering requires sight, and sight is precisely what the missing layer provides — who owns each AI, what it costs, whether it delivers, where the capacity went. Sight is what turns steering into learning: you can only adjust the next move if you can see whether the last one worked. That layer is organizational, not technical; it is the layer most within a CIO’s own control; and it is buildable now, with disciplines the organization already trusts. Decide what each AI is. Give it an owner and a budget. Make its cost and value visible. Calibrate oversight to risk, and pair with enforcement where autonomy demands it. Do this, and the regulations become a mapping exercise, the runtime tools become extensions of a coherent model, and AI stops being a phenomenon that happens to the organization and becomes a capability the organization runs.


Self-Assessment Tool

Two instruments, ten minutes, no data you do not already have. The maturity matrix locates you across the five dimensions of the missing layer; the checklist is the fast gut-check.

A. AI Governance Maturity Matrix

For each dimension, mark the cell that best describes your organization today and note its level (0–3). Sum the five levels for a score out of 15.

Dimension0 · Absent1 · Reactive2 · Managed3 · Architected
Visibility & InventoryNo inventory; shadow AI unknownAd hoc list; big tools known, gaps unmanagedCentral register of AI systems, refreshed on a cadenceLive inventory incl. embedded and shadow AI, tied to the portfolio
Ownership & Decision RightsNobody owns AI; it lands on the CIO by accidentOwnership unclear; decisions made case by caseNamed owner and approval path per AI initiativeDecision rights engineered; a business + IT tandem per system
Cost & Resource GovernanceAI spend invisible and uncappedSpend visible only on the invoice, after the factAI spend on plan-vs-actual; budgets setConsumption budgeted per initiative and agent, tied to value
Risk, Compliance & EnforcementNo risk view; no mapping to regulationOne generic AI policy; nothing enforced at runtimeRisk tiering; high-risk uses mapped to EU AI Act / NIST / ISOOversight calibrated per process; runtime guardrails and monitoring
Agent AccountabilityAgents, if any, unknown and ungovernedAgents used informally; no owner, no limitsEvery agent has an owner, a budget, and defined guardrailsAgents run as accountable actors: identity, lifecycle, a kill switch

The matrix is the authors’ synthesis of the frameworks discussed in this brief, designed as a structured thinking guide, not a validated assessment instrument.

Reading Your Score

  • 0–4 · Foundational gap. Build the substrate: inventory, ownership, cost visibility. Do not buy a compliance platform yet — it would have nothing to attach to.
  • 5–9 · Reactive. You have policy without an operating model. Add risk tiering and the technology-or-teammate classification; put AI spend on plan-vs-actual.
  • 10–13 · Managed. Extend to consumption budgets per agent and pair with an enforcement capability for runtime and regulatory coverage.
  • 14–15 · Architected. Sharpen agent accountability and per-process oversight calibration. You are steering with sight — keep the inventory live.

B. Ten-Minute Checklist

Answer yes or no. Fewer than four yeses signals a foundational gap — and the fastest returns hide in the first three questions.

  • Could you produce, today, a list of every AI system and agent in use — including the shadow AI in personal accounts?
  • Does every significant AI use have exactly one named owner?
  • Can you see AI spend plan-versus-actual, not just on the invoice?
  • Have you classified each AI as technology or teammate?
  • Is the level of human oversight set per process and risk tier, rather than by one blanket policy?
  • Are your high-risk uses mapped to the EU AI Act, NIST AI RMF, ISO/IEC 42001, or US state-law obligations that apply to you?
  • Does every autonomous agent have a budget, a written ruleset, and a way to be stopped?
  • Could you defend the financial value of your top three AI initiatives to your CFO, this week?

Author Recognition & Citation

Authors: Sonny Claussen and Beverly Lovett.

This brief draws on original field research conducted at the MIT Sloan CIO Symposium 2026 and a subsequent CIO roundtable at the Harvard Club Boston (Leuthe & Claussen, 2026), held under Chatham House Rules. It engages publicly available frameworks and research from Gartner (AI TRiSM; Market Guide for Guardian Agents), Forrester (AEGIS Framework; agent control plane research), Info-Tech Research Group (Adaptive AI Governance), NIST (AI Risk Management Framework), ISO/IEC 42001, and the EU AI Act, together with the decision-rights research of Schrage and Kiron (MIT Sloan Management Review) and Westerman’s concept of directive emergence.

All market statistics are anchored to the sources listed under References. Field-survey figures describe a purposive sample of 20 CIO-level technology leaders and are not statistically representative; they are reported as practitioner evidence, not population estimates.

Suggested Citation

Claussen, S., & Lovett, B. (2026). The Missing Layer: Rethinking AI Governance as Organizational Architecture. SIM ReThink Everything! Technology Brief.


References

Baars, T., Khadka, R., Stefanov, H., Jansen, S., Batenburg, R., & van Heusden, E. (2014). Chargeback for cloud services. Future Generation Computer Systems, 41, 91–103.

BCG (2025). The Widening AI Value Gap. Boston Consulting Group.

Deloitte (2025). State of Generative AI in the Enterprise — agentic AI adoption and governance readiness findings.

European Union (2024). Regulation (EU) 2024/1689 (EU AI Act).

FinOps Foundation (2026). State of FinOps 2026.

Forrester (2025). Forrester's AEGIS Framework for Agentic Security; Forrester (2025–2026), agent control plane research.

Gartner (2023–2025). AI Trust, Risk and Security Management (AI TRiSM) research.

Gartner (2025). Prediction: 60% of AI projects will be abandoned through 2026 for lack of AI-ready data.

Gartner (2026). Market Guide for AI Guardian Agents.

Info-Tech Research Group (2026). Establish Your Adaptive AI Governance Program: From Principles to Practice.

ISO/IEC 42001:2023. Information technology — Artificial intelligence — Management system.

Lazzaro, Sage (2025). How classic digital transformation lessons apply to AI—and what's different this time around, Fortune, December 12, 2025. https://fortune.com/2025/12/12/digital-transformation-artificial-intelligence-mit-sloan-aiq/

Leuthe, T., & Claussen, S. (2026). From Pilots to Operations: A Field Study of AI Maturity, Governance, and the Evolving CIO Role. Field research at the MIT Sloan CIO Symposium 2026 and CIO Insight Session, Harvard Club Boston.

McKinsey & Company / QuantumBlack (2025). The State of AI: Global Survey 2025 (adoption, high-performer, and workflow-redesign findings).

McKinsey & Company (2025). The State of AI: How Organizations Are Rewiring to Capture Value (EBIT-impact and AI-governance-oversight correlation findings).

NIST (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0).

OECD (2019; updated 2024). OECD AI Principles.

S&P Global (2025). Generative AI Experiences Rapid Adoption, but with Mixed Outcomes.

Schrage, M., & Kiron, D. (2025). The Great Power Shift: How Intelligent Choice Architectures Rewrite Decision Rights, MIT Sloan Management Review; Winning with Intelligent Choice Architectures, MIT SMR/TCS.

Westerman, G. (2025). Directive emergence (as reported in Fortune, December 2025); Westerman & Webster (2025), research on stages of AI progression.

A note on source discipline: the widely circulated claim that “95% of GenAI pilots fail” (MIT Project NANDA, 2025) is deliberately not relied upon in this brief. Independent reviewers were unable to reconstruct the figure from the report’s published data, and the project’s commercial interests were not disclosed alongside it. The failure-rate picture in Section 1 is instead triangulated from S&P Global, Gartner, and McKinsey, whose methodologies are published.