Skip to content

AI is already in your programme but is your governance keeping up?

Added to your CPD log

View or edit this activity in your CPD log.

Go to My CPD
Only APM members have access to CPD features Become a member Already added to CPD log

View or edit this activity in your CPD log.

Go to My CPD
Added to your Saved Content Go to my Saved Content
AI governance

Most project leaders did not expect to govern artificial intelligence. Their focus has been on delivering outcomes, managing risk and leading teams through complexity. Today, AI is embedded in the tools, decisions and data flows of nearly every significant programme. The question is no longer whether AI requires governance, but if those responsible for delivery are prepared to govern it.

In many organisations, the answer is still evolving.

The governance gap is real

Grant Thornton's 2026 AI Impact Survey found that 78% of senior leaders lack strong confidence that their organisation could pass an independent AI governance audit within 90 days. Deloitte's 2026 State of AI in the Enterprise report adds further weight. Only 21% of responding enterprises reported having mature governance in place to manage the risks of agentic AI.

These figures should concern every programme manager, not because AI is inherently risky, but because ungoverned AI introduces the kind of uncontrolled risk exposure that leaders are responsible for preventing.

The challenge is not the absence of governance, since most organisations have frameworks for risk, compliance, data and IT. However, these were built for static systems. In contrast, AI systems learn, drift and evolve after deployment. Their decisions are often difficult to explain or trace, and data quality issues may only surface months later. Traditional change management depends on stable, versioned systems, which AI does not offer.

The result is a gap between what your governance framework was designed to manage and what your programme is actually doing.

You do not need to start from scratch

Many organisations mistakenly treat AI governance as a separate discipline, creating new committees, frameworks and budgets. In reality, integration is far more effective than duplication.

The governance structures you already operate are the right foundation. They simply need to be extended:

  • Add AI-specific categories to your enterprise risk register, such as model risk, data representativeness risk, bias risk and autonomous decision risk.
  • Introduce a model review gate in your change advisory board before deploying AI into live programmes.
  • Have your compliance team map relevant obligations and guidance from the EU AI Act, NIST AI RMF and ISO 42001 to your existing controls.
  • Expand your internal audit scope to include model validation and fairness testing, in addition to current financial and operational reviews.

These changes do not require rebuilding your current systems. Instead, they involve asking new questions within your existing structures.

Where project leaders come in

Programme managers are, in many ways, the natural owners of AI governance at the delivery level. They already understand risk appetite, escalation thresholds, accountability structures and stakeholder expectations. They are accustomed to making decisions with incomplete information and managing consequences when things go wrong.

What changes with AI is the nature of some of those consequences. When an AI system makes a decision affecting a customer, colleague, or contractual obligation, accountability remains with the programme that deployed it, not the model. Project leaders should therefore address governance questions that may not yet be included in their programme charters:

  • What level of autonomous decision-making is acceptable in this programme?
  • Who owns the outcome when an AI recommendation turns out to be wrong?
  • How will model performance be monitored after go-live, and by whom?

These questions are not solely for the data science team. They are programme governance matters and should be considered alongside your risk register and change authority.

A practical starting point

If your programme uses AI in any capacity, follow these three steps:

  1. Audit your processes: identify all points where an AI system influences decisions or actions, regardless of scale.
  2. Map accountability: for each point, determine who is responsible if the output is incorrect, biased, or harmful.
  3. Enhance existing controls: incorporate AI-specific review steps into your governance calendar instead of creating separate processes.

Perfection is not required at the outset. Governance is iterative, including for AI. What matters is that it starts.

The opportunity for our profession

Project and programme managers excel at bringing order to complexity. At its core, AI governance is a delivery challenge. How can we embed oversight in a fast-moving environment without causing delays? Our profession is well positioned to address this.

Organisations that succeed will not necessarily have the most advanced AI. Instead, they will have clear accountability, consistent oversight and project leaders who ask the right questions early.

AI governance is not a technology problem seeking a technical solution. It is a leadership responsibility that already rests with you. 

 

You may also be interested in:

0 comments

Join the conversation!

Log in to post a comment, or create an account if you don't have one already.