The Governance System You Already Trust Is the One You Use for People
Table of contents
- The Governance System You Already Trust Is the One You Use for People
- The Two Ways Organizations Get This Wrong
- Three Pillars of an AI Governance Framework, Borrowed From Hiring
- Why This Speeds You Up Instead of Slowing You Down
- Let People Earn Access: The AI Driver’s License
- Governance People Help Write Is Governance People Follow
- How This Connects to the Work Ahead
- What to Do This Week

The Governance System You Already Trust Is the One You Use for People
Every organization already runs a governance system for powerful, capable, unproven newcomers. It is called hiring. When a talented person joins your company, nobody hands them admin rights to the finance system on day one. Nobody tells them to figure out their own job. Nobody waives the review process because they interviewed well. They get the access the role needs, a clear description of what they own, and a manager who checks the work until trust is earned. Then their scope grows. We have refined this system for a century. It mostly works. And when AI arrived, most organizations forgot all of it. Instead, they reached for one of two responses. Some locked AI out entirely and waited for policy to catch up. Others let it in with no structure at all and hoped for the best. Both feel like decisions. Neither is governance. The better move is hiding in plain sight. Govern AI like you hire. That is the whole AI governance framework: give AI tools and agents the same least-privilege access, the same defined roles, and the same review rigor you give a new hire. Done this way, governance stops being the brake on AI adoption and becomes the thing that lets you go faster.
The Two Ways Organizations Get This Wrong
The first failure is the lockdown. Block the tools, route every request through a security queue, and treat AI use as a violation until proven otherwise. The intent is responsible. The result is not. People who have seen what AI can do for their work do not stop using it because a policy says so. They take it home. Microsoft and LinkedIn’s 2024 Work Trend Index found that 78 percent of AI users were bringing their own AI tools to work, while only 39 percent of people using AI at work had received any AI training from their company. \[SOURCE: Microsoft and LinkedIn, “AI at Work Is Here. Now Comes the Hard Part” (2024 Work Trend Index), May 8, 2024 – https\://www\.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part\] We see this pattern directly. At one regulated services firm we have spoken with, fear-driven rules did not reduce AI use. They pushed it underground, into personal accounts nobody could see. The risk did not disappear. It became invisible, which is worse. The second failure is the open door. Tools get adopted team by team, agents get connected to systems with whatever permissions were easiest to grant, and nobody can say with confidence what has access to what. A leader we spoke with recently described the fear to us in two words: the Wild West. That fear is well founded. In an August 2026 survey of 202 IT and security leaders at large enterprises, 94 percent said they were confident their AI agents did not have more access than they needed. Only 33 percent actually provisioned agents with least-privilege access. And 65 percent had already seen an agent take an action outside its intended scope. \[SOURCE: Cequence Security and Enterprise Management Associates, “Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise,” August 31, 2026 – https\://www\.cequence.ai/news/ai-agent-governance-research/\] Ninety-four percent confident. Thirty-three percent actually doing it. That gap is not a technology problem. It is a governance problem, and it is the same one you would have if you onboarded people without ever defining their access.
Three Pillars of an AI Governance Framework, Borrowed From Hiring
Here’s what makes the hiring frame so useful. It is not a new policy language. Every manager, every IT lead, and every compliance officer already understands how it works. You do not need to train anyone on the concept. You only need to point at it. The system has three parts, and each one translates directly into a pillar of AI governance: least-privilege access, defined roles, and the same review rigor.
Least-Privilege Access
A new hire gets access to what the job requires, and nothing more. A new accounts payable analyst can see invoices. They cannot change vendor bank details. As they prove themselves, access expands. AI deserves the same treatment. The security community already agrees on this. The OWASP guidance on LLM risk names “excessive agency” as a core vulnerability and traces it to three root causes: excessive functionality, excessive permissions, and excessive autonomy. Its first-line mitigation is plain: “Limit the permissions that LLM extensions are granted to other systems to the minimum necessary.” \[SOURCE: OWASP Gen AI Security Project, “LLM06:2025 Excessive Agency,” 2025 – https\://genai.owasp.org/llmrisk/llm062025-excessive-agency/\] If an agent only needs to read a ticket queue, it should not be able to close tickets. If an assistant only needs to summarize contracts, it should not be able to send them. This is not exotic security engineering. It is the same principle your identity team applies to every human account, and it is the foundation of AI agent governance.
Defined Roles
Nobody hires without a job description. The description tells the new person what they own, what they do not own, who they answer to, and what good looks like. Most AI deployments skip this step. A tool gets licensed, or an agent gets built, and its purpose lives in the head of whoever set it up. When something goes wrong, nobody can say whether the agent did what it was supposed to do, because nobody wrote down what it was supposed to do. Give every agent a job description. One page is enough. What outcome is it responsible for? What systems can it touch? Which human owns its work? When does it escalate instead of acting? To be clear about the limits of the metaphor: this is not an argument for treating agents as employees. An agent can be listed on the org chart so people can find it and know who directs it, but it does not get a seat at the table or a performance review. Accountability for its work stays with a named person. The role description lives where your access controls and service records already live, so the agent is governed like a role without being treated like a colleague.
The Same Review Rigor
New hires do not ship unreviewed work in their first month. Code gets reviewed. Client deliverables get a second set of eyes. The rigor matches the stakes, and it relaxes as trust builds. AI output deserves exactly that, no more and no less. Two failure modes show up here. Some teams give AI output a pass because a machine produced it and it looks polished. Others hold AI to a standard of perfection they would never apply to a talented junior employee, so nothing ever ships. OWASP’s guidance points to the middle path: use human approval for high-impact actions before they are taken. \[SOURCE: OWASP Gen AI Security Project, “LLM06:2025 Excessive Agency,” 2025 – https\://genai.owasp.org/llmrisk/llm062025-excessive-agency/\] Review proportionate to stakes is how you already treat people. It is the right way to treat AI.

Why This Speeds You Up Instead of Slowing You Down
Most leaders hear “governance” and brace for delay. That reaction makes sense when governance means a committee that says no. It does not hold when governance means clear rules that people trust. Charles Hoskinson, co-founder of Cardano, put the mechanism better than any framework document I have read. On the Facilitation Lab podcast, he described the historical pattern this way: “high trust things tend to have low bureaucracy and low trust things tend to have high bureaucracy.” His explanation of why: “The bureaucracy’s purpose is to de-risk.” \[SOURCE: Voltage Control, Facilitation Lab podcast, “From Talking Sticks to Blockchain: Revolutionizing Governance Through Collaboration,” with Charles Hoskinson – https\://voltagecontrol.com/blog/from-talking-sticks-to-blockchain-revolutionizing-governance-through-collaboration/\] That is the whole case for governing AI like you hire. When nobody knows what an agent can touch, every new use case needs a meeting, a review, and a sign-off, because every new use case is an unknown risk. When access, role, and review are defined up front, the risk is already bounded. Teams can move without asking permission for every step, because the permission is built into the structure. Clear governance is what lets you say yes quickly. Unclear governance forces you to say maybe, slowly, forever. This is why we describe the current moment as the New Friction. AI has collapsed the cost of execution. The friction did not vanish. It moved to trust, alignment, and governance. Organizations that treat governance as paperwork will feel that friction as drag. Organizations that design it well will turn it into speed.
Let People Earn Access: The AI Driver’s License
Hiring has one more lesson worth borrowing. Access is earned, not assumed and not denied. We do not ban cars because some people drive badly. We also do not hand the keys to anyone who asks. We license drivers. You show you can operate the vehicle under the rules of the road, and you get the right to drive. Higher-stakes vehicles require a higher-stakes license. Apply the same logic to AI inside your organization. Instead of a blanket yes or a blanket no, create a path where people earn tool access by showing they can use AI well under your rules. A learner’s permit might cover sanctioned tools on non-sensitive work. A full license might open access to customer data or internal systems. Building agents that take actions on their own might require something closer to a commercial license. The test should be practical, not a compliance quiz. Can this person get a useful result? Can they spot a weak or fabricated answer? Do they know what data never goes into a prompt? Those are the skills that actually reduce risk. A driver’s license does two things a lockdown cannot. It brings shadow AI above ground, because the legitimate path is now faster than the workaround. And it gives you visibility into who is using what, at what level of skill, which is exactly what a lockdown destroys.
Governance People Help Write Is Governance People Follow
There is a final piece of the hiring system that often gets missed. The best onboarding is not imposed. It is shaped by the people who do the work. We learned this at a scale few organizations ever attempt. Voltage Control facilitators designed and led the workshops through which the Cardano blockchain community wrote its constitution, with community members in 50 countries drafting, debating, and revising the document that now governs their ecosystem. Hoskinson called the investment in that facilitation process “an incredibly powerful move for our organization,” and described what it produced: “It built genuine trust across a diverse global community, laid a stronger foundation for collaboration, and set the stage for the next wave of innovation in our ecosystem.” \[SOURCE: Voltage Control, “Facilitating the World’s First Blockchain Ecosystem Constitution” (Cardano case study) – https\://voltagecontrol.com/cardano/\] Skeptics expected it to fail. Hoskinson recalled what people told him at the first workshop: “You’re just not going to pull this off.” \[SOURCE: Voltage Control, Facilitation Lab podcast, with Charles Hoskinson – https\://voltagecontrol.com/blog/from-talking-sticks-to-blockchain-revolutionizing-governance-through-collaboration/\] It did not. And his explanation of why it held is the most important governance insight in this post: when people build things together, “it connects them, it draws them closer, it becomes their artifact. They’ve had some say in some participation in it, so they own it.” \[SOURCE: Voltage Control, Facilitation Lab podcast, with Charles Hoskinson – https\://voltagecontrol.com/blog/from-talking-sticks-to-blockchain-revolutionizing-governance-through-collaboration/\] Your AI governance policy works the same way. Rules written in a back room by legal and IT get routed around. Rules shaped with the people who will live under them get followed, because they are theirs. This is the same move we argued for in Involve Before You Mandate. It applies doubly to governance. It also explains a shift we are seeing in how organizations structure AI ownership. One new CTO we spoke with did not want a Center of Excellence that controls AI from the center. The CTO wanted an AI Enablement board that helps the whole organization use it well. That is the difference between a gatekeeper and a hiring manager. One decides who gets in. The other makes sure the people who get in can succeed.
How This Connects to the Work Ahead
Governing AI like you hire is not a standalone policy idea. It builds directly on the three competencies we see separating organizations that make AI stick from those that stall. Orient to outcomes. A role description starts with the outcome the role exists to deliver. The same is true for an agent. If you cannot name the outcome, you cannot scope the access. Rebuild rituals. Review rigor only works if your review rituals can keep pace with machine-speed output. Most cannot yet. That is a ritual design problem, not a reason to skip review. Delegate deliberately. Least privilege is delegation discipline. As we wrote in From Maker to Manager, using AI well is a management skill. Deciding what an agent may and may not do is the core of that skill.
What to Do This Week
Start small and concrete. Pick one AI tool or agent already in use on your team. Write its job description on a single page: the outcome it owns, the systems it can touch, the person accountable for its work, and the point where it must hand off to a human. Then compare that page to reality. What can it actually access today? If the answer is broader than the job description, you have found your first governance fix, and it took an afternoon, not a committee. Next, name the review ritual. Who checks its output, how often, and what happens when the work is wrong? If nobody can answer, that is your second fix. Finally, ask your team where they are using AI that you have not sanctioned. Ask it with curiosity, not as an audit. Every answer tells you where your legitimate path is too slow, and where a driver’s license would bring work back into the light. The organizations that govern AI like they hire will move faster than the ones still debating whether to let it in, because their people will know exactly how far they can go and how to go further. The rest will keep choosing between a lockdown nobody follows and an open door nobody can see through. If you are wrestling with how to set up an AI governance framework your people will actually follow, talk with us. Helping organizations design governance together, with the people who will live under it, is exactly the work we do.