Every enterprise I've worked with in the last two years has a slightly different AI governance stack, and almost none of them have an AI governance problem worth solving with more tooling. What they have is a decision-rights problem wearing a tooling costume.

Here's the pattern. Someone in engineering ships an AI feature because it was fast and the model made a good demo. Legal finds out three weeks later. Security finds out when the vendor questionnaire comes back. And the executive who's supposed to own "AI strategy" finds out when a board member asks about it.

None of that is a tools problem. A model registry doesn't fix an org chart where nobody has the authority — or the obligation — to say "not like this."

What actually works

The governance programs that hold up under pressure share one trait: a named executive owns intake, prioritization, and risk sign-off for AI initiatives, the same way that role exists for Security exceptions or vendor contracts. Not a committee. A person. Committees are where accountability goes to average itself into nothing.

From there, the tooling — model inventories, evaluation pipelines, data lineage — becomes the evidence that the decision-maker is doing their job, rather than a substitute for the decision-maker existing in the first place.

If your AI governance conversation keeps circling back to "which platform should we buy," you're solving the wrong layer of the problem.