What is enterprise AI governance?
The controls that decide whether AI output can actually be acted on.
Enterprise AI governance is the set of controls determining what AI may do, on what data, under whose approval, and with what record. It is the difference between an AI system that produces useful output and one whose output an organization is permitted to act on.
Why governance is the adoption gate
In regulated and high-consequence settings, the blocker on AI adoption is rarely model quality. It is that a capable system produces a recommendation nobody can approve, because the organization cannot evidence how it was produced. A clinician cannot act on advice they cannot trace. An auditor cannot accept a figure whose derivation is unavailable. A programme cannot defend a decision it cannot reconstruct.
Governance is therefore not a constraint applied to AI value — in these settings it is the precondition for any value at all.
The four controls
- Trust hierarchy over the knowledge. Every asset AI reasons over carries explicit status — authoritative, working, archived, deprecated. Without this, an approved standard and a superseded draft are weighted identically, which is the single most common cause of confidently wrong output.
- Approval gates at defined thresholds. Which decisions require a human, and which human. Defined in advance by consequence, not negotiated after an incident.
- Provenance on every output. What informed it, who reviewed it, what was AI-generated versus human-approved. This is what converts an output into evidence.
- Deployment control. Tenant isolation, SSO, role-based access, configurable data residency — the controls governing where information can travel.
How should enterprises govern AI agents?
Govern them the way you govern people who can act: define what they may do, on what information, under whose approval, and with what record. The critical design rule is that these controls must be properties of the system rather than policies in a document — a control that depends on someone remembering it will fail under deadline.
Which control actually matters most
Of the four, the trust hierarchy is the one most organizations skip and the one most failures trace back to. Approval workflow gets attention because it is visible and maps onto existing sign-off culture. But an approval gate placed over a system reasoning across an undifferentiated archive only asks a human to ratify a conclusion drawn from superseded material.
The sequencing follows from that. Establishing what is authoritative is prior to deciding who approves, because the approver needs the same distinction the system does. Organizations that invert this — governance committee first, knowledge status later — end up with a control that documents decisions without improving them, and a review burden that makes the AI slower than the process it replaced.
The failure modes
- Governance by policy document. A written standard with no enforcement in the system. Survives audit, not contact with production.
- Retrofitted approval. Gates added after an incident, bolted onto a workflow that was designed without them, so they are routed around.
- Undifferentiated context. Pointing AI at a document archive with no trust hierarchy, then being surprised by outdated answers.
- Provenance as logging. Recording that an output was produced, without recording what informed it — which is enough for debugging and useless for defending a decision.
Where EXOS sits on this
EXOS was architected for buyers where governance is the adoption gate rather than adapted to them afterwards. The four controls above are implemented in Tacit OS as platform properties. See enterprise AI.