AI Governance Institute
← News
Research2026-10-09

Thoughtworks Maps Who Owns AI Controls When Business Units and IT Both Claim Governance

What happened

Thoughtworks published guidance titled Who actually controls enterprise AI? on October 7, 2026. The guidance outlines a practical operating model for organizations that have deployed AI across multiple business units but have not resolved who is accountable for security, privacy, and compliance controls. The model recommends keeping shared technology environments and enterprise guardrails at the center while pushing named control ownership out to individual business units. Finance is assigned a distinct role: tracking AI consumption costs and measuring realized value. Business units are given authority to make local AI decisions, but only within boundaries that the enterprise has already reviewed and approved. The model addresses the gap between written AI policies and actual day-to-day accountability. Surveys such as the 36% of Organizations Report Material AI Incidents, EY Survey Finds have highlighted this gap as a leading indicator of governance failure.

Why it matters

  • ·Regulators are looking past written policies to ask whether a named human is accountable for each control. These include bank supervisors under the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) and EU authorities under the EU AI Act (Regulation (EU) 2024/1689). An operating model that cannot answer that question is a regulatory finding waiting to happen.
  • ·The finance monitoring role described in the model is not just a budget function. If AI consumption data surfaces unexpected usage patterns, it becomes an early warning system for shadow AI adoption. Shadow AI refers to tools employees use that have not gone through any approval process. Organizations without this visibility are running AI risk they cannot measure.
  • ·Distributing control ownership to business units without a defined approval boundary creates a coordination risk. If each unit interprets 'approved boundaries' differently, enterprise guardrails break down in practice even when they look intact on paper. Compliance teams need a written definition of what falls inside and outside those boundaries, and a process for resolving disputes.

Governance controls affected

What to do now

  • ☐For each AI system currently in production, confirm in writing which individual or role within the relevant business unit is accountable for security, privacy, and compliance controls, and record that in your AI model registry.
  • ☐Ask your finance team whether they are currently tracking AI tool spend and usage volume by business unit. If not, establish a reporting cadence that would surface unexpected or unapproved AI consumption.
  • ☐Document the criteria that define what AI decisions business units may make locally versus what requires enterprise review and approval. Make this document available to business unit leads and your legal or compliance team.
  • ☐Test your enterprise guardrails by asking three different business unit leads to describe the approval process for deploying a new AI tool. If answers differ materially, your operating model has a consistency gap that needs correction before a regulator asks the same question.
  • ☐Map your current AI governance committee charter against this operating model. Confirm that the charter assigns named owners for technology, compliance, finance, and business-unit governance roles, not just functional categories.

What to watch next

Banking regulators under the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) have already signaled that nominal governance structures will not satisfy examination expectations. Compliance teams should expect similar scrutiny to extend to non-bank regulated entities as EU and state-level AI oversight programs mature. The Credo AI Survey of 371 Leaders Maps Where Mature AI Governance Programs Pull Ahead found that organizations with formal ownership assignment outperform peers on audit outcomes. Watch for enforcement actions or examination findings that cite diffuse accountability rather than missing controls, a pattern that would validate the operating model's core premise.

Related Coverage

Research2026-10-09

Standard Chartered's AI Safety Council Offers a Federated Governance Blueprint

Standard Chartered has described a federated AI governance model in which a central AI Safety Council, shared platforms, and enterprise-wide controls coexist with business-unit-led use-case development. The bank maintains a formal AI inventory overseen by a cross-functional council that brings together engineering, risk, compliance, and business leaders. The model illustrates how large, regulated institutions can balance local innovation with consistent enterprise controls.

Corporate Policy2026-10-06

Utah Healthcare AI Sandbox Sets a Governance Template With Real Teeth

Utah's Office of Artificial Intelligence Policy has signed master agreements with Intermountain Health and University of Utah Health to test AI tools in clinical settings under the state's regulatory sandbox. Three new pilots covering dermatology, postpartum physical therapy, and prescription refills were approved, each with third-party evaluation and human oversight requirements. The initiative was revised after the Utah Medical Licensing Board criticized an earlier version for insufficient stakeholder input.

Enforcement2026-10-05

Norway's AI Glasses Ban Opens a New Category of Physical Surveillance Compliance Risk

Norway's center-left government announced plans to temporarily ban AI-enabled smart glasses in public spaces including parks, beaches, schools, and kindergartens. The measure is intended as a bridge period while an expert group develops permanent national rules. Enterprise compliance teams operating in Norway or deploying wearable AI face an emerging but concrete policy obligation with no current equivalent in most AI governance programs.