Skip to main content



AI governance 2.0: Control at the speed of scale

If AI governance is slowing you down, you’re doing it wrong.

Portrait of a smiling woman wearing a white button-up shirt. She is standing indoors against a softly lit, textured wall. The image is in black and white, emphasizing contrast and facial expression. The overall composition conveys professionalism, approachability, and confidence.
Jillian Powers, PhD
Senior Director
Published:
4 minute read

TL;DR

  • Traditional AI governance is too slow to support AI at scale.
  • AI governance 2.0 embeds oversight and controls into AI development and operations.
  • Built-in governance helps teams innovate faster while reducing risk and improving accountability.
  • Governance isn’t a bottleneck to AI scale—it’s what makes scale possible.

Why traditional AI governance can’t keep pace

Many organizations are learning the hard way that their current AI governance models aren’t just slow—they’re unsustainable. Risk reviews happen too late, councils lack decision authority, and endless document handoffs between business, legal, compliance, and engineering teams leave AI initiatives paralyzed.

While many leaders are moving in the right direction, the reality on the ground tells a different story. Slalom’s 2026 AI Research Report shows that executives have experienced a 30% year-over-year increase in confidence around leadership and strategic alignment. Yet delivery teams often remain trapped in cycles of approval purgatory, unable to ship, iterate, or scale. As a result, only 38% of respondents believe the pace of innovation aligns well with AI advancement.

This gap isn’t just a matter of maturity; it’s an architecture and people problem. Initial AI governance programs and operations weren’t created for the velocity, complexity, or risk profile of AI today.

AI systems can now make decisions, invoke tools, trigger downstream workflows, and, in some cases, talk to other AI systems and agents. The future is not a single chatbot in a sandbox. It’s ecosystems of distributed agents operating across customer relationship management systems (CRMs), cloud environments, customer channels, and mission-critical infrastructure. And if your governance model can’t see, score, or stop those agents in real time, you’re already behind. The agentic era is here, and without real-time policy enforcement, adaptive controls, and embedded observability, you’re trusting ungoverned software, confused end users, and untested third parties to integrate and act on your behalf.

AI governance can no longer be treated as a checkbox exercise owned by legal, risk, or compliance teams operating outside the build process. As systems become more complex, adaptive, and autonomous, governance must be conceived, engineered, and executed as part of the system itself. It should be ingrained from the start, not bolted on after deployment.

It’s time for AI governance 2.0.

AI governance 2.0 moves oversight out of inboxes and committees and into the system where AI is built and operated. Instead of relying on fixed policies and one-time reviews, governance is woven directly into the DNA of workflows and pipelines, using code to manage risk and enforce policy. This allows governance to function in a systematized, role-aware, and risk-tiered way, designed to work continuously as AI systems evolve.

It’s a people-first approach to AI modernization. Decision-making shifts closer to those responsible for delivery while remaining connected to shared standards, traceable processes, embedded controls, and scalable reporting mechanisms. As a result, teams are no longer forced to stop, restart, or reinterpret requirements every time the system changes.

For example, instead of waiting for a risk council to review a 40-page document post hoc, teams run through pre-wired approval tollgates, auto-generate required documentation, and escalate only when risk thresholds are crossed. Think: dynamic workflows, not static checkpoints.

The problem

AI governance today is largely made up of:
  • Policy documents
  • Review committees
  • Manual approvals
  • Reactive and slow oversight
  • Piecemeal and ad hoc processes
But AI has changed:
  • It’s adaptive, autonomous, and embedded in critical workflows
  • Agents can use tools, access data, and cross SaaS boundaries
  • Agentic systems act, not just predict
  • Traditional governance can’t keep up; static policies can’t govern dynamic behavior

AI governance 2.0

AI governance needs to be:
  • Integrated into development and deployment pipelines
  • Parameterized by risk tier, use case, and environment
  • Testable, monitorable, and observable
  • Designed for human oversight and adaptive operations
How we get there:
  • Capture impact assessments as structured inputs (APIs, intake data, etc.)
  • Implement approvals as gates in CI/CD pipelines
  • Auto-generate documentation from telemetry and system activity
  • Automate and integrate red-teaming across the development lifecycle
  • Trigger escalations by risk thresholds in real time
  • Use dashboards for shared visibility into risk and oversight

AI governance, engineered for your future

At Slalom, AI governance 2.0 isn’t a single tool or framework. Instead, we align operations with technical enablement to embed governance into how AI systems are engineered and evolved—not just how they’re reviewed—so teams can move faster without sacrificing control.

Our AI governance 2.0 is:

  • Embedded by design, not layered on after deployment
  • Context-aware and runtime-adaptive, with policy and control guardrails and tollgates
  • Driven by dynamic and modular escalation thresholds, human oversight, and audit logs
  • Tested and monitored continuously, in preproduction and production
  • Versioned and reviewed, just like any other codebase

Unlocking speed and accountability with AI governance 2.0

FINANCIAL SERVICES

A financial services customer reduced approval bottlenecks by automating impact assessments and risk tiering during the intake process. With controls integrated directly into a ServiceNow-native workflow, teams can move through approvals faster and significantly increase throughput without elevating risk.


LIFE SCIENCES

A life sciences customer improved auditability and reduced review delays by connecting its policy library to a Git-based versioning system. As models changed, required documentation and compliance artifacts were generated automatically, allowing teams to release updates without restarting lengthy review cycles.


TELECOMMUNICATIONS

A telecommunications customer strengthened trust in its AI systems by automating red-teaming and evaluation across the development lifecycle. Using Pyrit, Lasso, and other custom-built evaluation libraries, teams could continously test AI behaviors. The results? Faster releases and fewer stakeholder surprises.


Final takeaways: What we must get right about AI governance

Ultimately, as organizations move from experimentation to scale, AI governance 2.0 comes down to six core principles:

  • Treat governance as infrastructure, not overhead
  • Build governance into the AI lifecycle, not after deployment
  • Share accountability across risk, cybersecurity, engineering, and product teams
  • Operationalize controls as code
  • Invest in quality, testing, and evaluation (QC/QA) at scale
  • Design governance around people, supporting how teams actually work

Most importantly, AI governance 2.0 isn’t solved through technology and process changes alone. For many executives, AI governance 2.0 also demands a mindset shift: It isn’t a drag on innovation; it’s the foundation for innovation. When AI oversight brings people and technology together, governance is no longer a blocker to scale; it’s how you scale safely.

If your organization is navigating the complexity of modern AI, Slalom can help you adopt governance as a practical, people-first capability. Together, we’ll operationalize oversight in a way that supports innovation instead of slowing it down, turning your biggest blocker into your strongest enabler.

SET AI IN MOTION

Move AI from experimentation into everyday operations.

 

  • Adaptable foundations
  • Human–AI workflows
  • Measurable outcomes

 

Trusted by organizations delivering:

 

  • $8B+ in customer value
  • 3x average ROI