Empowering teams with clarity, consistency, and lasting impact across sectors.

AI is moving faster than governance. What if governance capacity is the missing AI capacity?

The world is debating whether AI development needs to slow down. I think we also need to ask a different question: are we building governance capacity fast enough to keep up?

A recent Los Angeles Times article highlights an unusual moment in the AI race. Leaders including Anthropic CEO Dario Amodei, OpenAI CEO Sam Altman and xAI founder Elon Musk are calling for a slower pace of development of increasingly advanced AI models, citing escalating risks. Anthropic has also announced additional safety measures, including the use of third-party evaluators. The conversation is important, but slowing technological development is only one possible response to accelerating risk. The other is to increase our capacity to govern what we are building, which is where I believe the next phase of the AI governance conversation needs to go.

AI capacity is more than technical capacity and the United Nations' Global Digital Compact provides an important foundation for this conversation. Adopted in 2024, the Compact calls for international cooperation to advance safe, secure and trustworthy AI. It explicitly recognizes the need to support countries, particularly developing countries, in building the capacity to access, develop, use and govern AI systems. It also calls for interoperability and compatibility among AI governance approaches, alongside transparency, accountability and robust human oversight. These are ambitious commitments, and in my view, the following question deserves more attention: How do we know whether an organization, or a country, actually has the capacity to govern AI?

We routinely talk about AI capacity in terms of compute, infrastructure, skills, data, investment, research and access to models, yet governance capacity is often treated differently; as policy, regulation, ethics or compliance. I believe that distinction is becoming increasingly problematic. Governance capacity needs to become a measurable component of AI capacity because having the ability to build or deploy AI without having the ability to govern it is not capacity. It is exposure.

The Global Digital Compact recognizes that AI governance needs to be responsible, accountable, transparent, human centric and risk based across the AI lifecycle, from development and evaluation to deployment, use, procurement and decommissioning. It also calls for compatible governance approaches and the sharing of best practices. The challenge is translating these principles into what happens inside an organization.

My research asks: How can organizations translate increasingly sophisticated AI principles into repeatable decisions at the point where AI actually enters an organization? That is where governance becomes real. It is not in a policy document, it is not in a principles statement, not in a strategy deck, but at the point where someone decides: 1. Yes, we will use this AI, or, no, we are not ready, or, yes, but only under certain conditions. That is the space I have been exploring through AI-RESPECT™, however, when I talk to people about the framework, I increasingly find that leading with the framework itself is not necessarily the most useful approach. People do not necessarily want to hear about another framework, they want to know what questions they should be asking.

I have had the opportunity to speak to rooms of leaders, and rather than beginning with a framework, I begin with questions, which I think of as a portable AI reliability test:

  1. Who is accountable for the AI system? If something goes wrong, ownership of decisions and outcomes must be known.
  2. Whose values and rights does the AI system reflect? Understanding the assumptions, priorities and perspectives have been embedded in the system.
  3. Who owns the data and under what authority? Assess whether the (your, our) organization actually has the right, permission and responsibility to use the data this way
  4. Who is protected and who may be at risk of being harmed? Outlining who benefits from the system, and who could experience harm, exclusion or disproportionate impact.
  5. Can clients, collaborators or the public understand how it works? Providing those individuals who rely on, are challenged by or who are affected by the system enough understanding to make informed decisions.
  6. Does the AI system meet current and future compliance requirements? Regularly assess the innovation–governance gap to ensure today’s rules can adapt as innovation and regulation evolve.
  7. Are we being transparent about AI use? Ensuring people know when AI is being used, how it influences decisions and where human responsibility remains.

These questions are deliberately simple as governance must work at the point of action. Having said that, it also connects to another concept I believe deserves ongoing attention, which is the human control point. Human oversight cannot simply mean having a person somewhere in the process. A meaningful human control point requires a person with the authority, information and capacity to question, override or stop an AI supported decision. That distinction becomes increasingly important as AI moves from administrative applications into health care, public services, security, education and other high impact environments. The higher the potential consequence, the stronger the governance capacity needs to be. It should not be innovation that determines the level of oversight, risk should.

This is why the upcoming UN Digital Cooperation Day 2026, taking place September 21 in New York under the theme “Shaping a Global AI Future Through Science, Policy, and Capacity,” is particularly timely. The event is focused on translating digital cooperation into action, with attention to practical country experiences, lessons learned and partnerships that can accelerate impact. The Global Digital Compact has established the direction, however, the next challenge is implementation. Implementation requires capacity, not simply the capacity to build, or use AI, but the capacity to question, assess, govern, monitor and, when necessary, to stop AI. That is what governance capacity looks like in practice.

The emerging debate about whether AI development should slow down risks creating a false binary between the move to innovate or regulate. I see a third option, as I don't believe a choice needs to be made between innovation and governance, and it is to continue to build the capacity to govern innovation. If we can measure whether an organization has the data, infrastructure, skills and technical capability to deploy AI, we should also be able to assess whether it has the governance capability to do so responsibly. That could include measurable indicators for accountability, data authority and stewardship, risk assessment, human oversight, transparency and explainability, compliance readiness, monitoring and evaluation, and lastly, the ability to intervene or stop an AI system when necessary. I strongly believe this is where I believe the next generation of AI governance needs to move.

Moving from principles to practice, from policies to decisions, and from governance as an aspiration to governance as a measurable capability. The UN is asking countries to build the capacity to access, develop, use and govern AI. Perhaps we should take that last word more seriously, because the question is no longer simply whether we have enough AI capacity. It is whether we have enough governance capacity to safely use the capacity we are building.

CT