Thoughtworks Maps Who Owns AI Controls When Business Units and IT Both Claim Governance
What happened
Thoughtworks published guidance titled Who actually controls enterprise AI? on October 7, 2026. The guidance outlines a practical operating model for organizations that have deployed AI across multiple business units but have not resolved who is accountable for security, privacy, and compliance controls. The model recommends keeping shared technology environments and enterprise guardrails at the center while pushing named control ownership out to individual business units. Finance is assigned a distinct role: tracking AI consumption costs and measuring realized value. Business units are given authority to make local AI decisions, but only within boundaries that the enterprise has already reviewed and approved. The model addresses the gap between written AI policies and actual day-to-day accountability. Surveys such as the 36% of Organizations Report Material AI Incidents, EY Survey Finds have highlighted this gap as a leading indicator of governance failure.
Why it matters
- ·Regulators are looking past written policies to ask whether a named human is accountable for each control. These include bank supervisors under the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) and EU authorities under the EU AI Act (Regulation (EU) 2024/1689). An operating model that cannot answer that question is a regulatory finding waiting to happen.
- ·The finance monitoring role described in the model is not just a budget function. If AI consumption data surfaces unexpected usage patterns, it becomes an early warning system for shadow AI adoption. Shadow AI refers to tools employees use that have not gone through any approval process. Organizations without this visibility are running AI risk they cannot measure.
- ·Distributing control ownership to business units without a defined approval boundary creates a coordination risk. If each unit interprets 'approved boundaries' differently, enterprise guardrails break down in practice even when they look intact on paper. Compliance teams need a written definition of what falls inside and outside those boundaries, and a process for resolving disputes.
Governance controls affected
What to do now
- ☐For each AI system currently in production, confirm in writing which individual or role within the relevant business unit is accountable for security, privacy, and compliance controls, and record that in your AI model registry.
- ☐Ask your finance team whether they are currently tracking AI tool spend and usage volume by business unit. If not, establish a reporting cadence that would surface unexpected or unapproved AI consumption.
- ☐Document the criteria that define what AI decisions business units may make locally versus what requires enterprise review and approval. Make this document available to business unit leads and your legal or compliance team.
- ☐Test your enterprise guardrails by asking three different business unit leads to describe the approval process for deploying a new AI tool. If answers differ materially, your operating model has a consistency gap that needs correction before a regulator asks the same question.
- ☐Map your current AI governance committee charter against this operating model. Confirm that the charter assigns named owners for technology, compliance, finance, and business-unit governance roles, not just functional categories.
What to watch next
Banking regulators under the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) have already signaled that nominal governance structures will not satisfy examination expectations. Compliance teams should expect similar scrutiny to extend to non-bank regulated entities as EU and state-level AI oversight programs mature. The Credo AI Survey of 371 Leaders Maps Where Mature AI Governance Programs Pull Ahead found that organizations with formal ownership assignment outperform peers on audit outcomes. Watch for enforcement actions or examination findings that cite diffuse accountability rather than missing controls, a pattern that would validate the operating model's core premise.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI systems built to extend your reach are now extending attackers' reach too, and regulators in California and South Korea are making clear that containment failures belong to deployers, not just vendors.8 Oct
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
Free every Thursday. Unsubscribe anytime.
