VICI Insights • AI Track • Week 08
AI Governance Should Not Be a Department of No
The flagship bank AI rulebook of 2026 says generative and agentic AI are "not within the scope."
That is not a loophole. It is the assignment.
For regulated industries, this is the uncomfortable reality of AI governance right now: the safe lane for GenAI does not fully exist on paper yet. SR 26-2 revised the model risk guidance, but explicitly carved out generative and agentic AI while still saying firms need appropriate governance and controls.
In plain English: the regulator told leaders, "You still own the risk," but did not hand them a complete answer key.
That is why AI governance cannot become the Department of No.
The companies that win here will not be the ones that say yes to everything. They also will not be the ones that send every use case into a committee maze until business teams give up and build shadow AI on the side.
They will be the ones that make the safe lane visible.
Three moves matter:
- Publish the pre-approved lane.
Name the sanctioned tools, data types, workflows, and use patterns employees can use today without asking for a one-off ruling. A default "yes, within these rails" beats a vague "come to governance first."
- Tier by risk and route accordingly.
A low-risk internal summarization workflow should not face the same approval burden as a model influencing credit, pricing, fraud, or customer treatment. Light use cases need a light logged lane. High-materiality decisions need ownership, effective challenge, controls, and an approval path.
Governance is a router, not one gate at one height.
- Measure both adoption and control.
Track sanctioned-lane usage, shadow usage, incident rate, cost, quality, and business impact. If adoption is low, the lane is probably too narrow or too slow. If incidents are high, the tier is too loose. Tune the system. Do not freeze it.
This is not just compliance theater. Grant Thornton's 2026 AI Impact Survey found that 78% of executives were not strongly confident they could pass an independent AI governance audit in 90 days, while only 7% of pilot-stage firms were very confident compared with 74% of fully integrated firms.
The governed firms are not necessarily the slow ones. They are often the ones with enough confidence to scale.
MIT Sloan has called out the real failure mode: governance can become a bottleneck. The answer is not no governance. It is minimum viable governance: proportional, embedded in the workflow, and designed to enable the right work faster.
Where is this showing up for you?
Is your AI governance opening safe lanes, or has it become the Department of No?
And where are you feeling it most: experimentation, governance, data readiness, or scaling?
Prefer LinkedIn? Join the discussion on the original post.
