CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running
Boards want AI returns. Employees want access. Compliance teams want guardrails. The CIO is stuck in the middle of all three.

The pressure is not subtle. Nearly two-thirds of senior leaders say they face more scrutiny to prove ROI on AI investments than they did a year ago, according to Kyndryl's 2025 Readiness Report. CEOs are naming AI capitalisation as the top mandate for their IT chiefs. And employees — not just engineers, but sales, finance, and marketing teams — want in.
Jonathan Tushman, chief AI officer and CTO at Hi Marley, a conversational platform for the property and casualty insurance sector, added the CAIO title to his remit eighteen months ago. The urgency, he says, has sharpened considerably in the last six.
The risk profile is genuinely new. Tushman identifies two features of AI risk that break traditional IT governance models. First: AI is indeterminate. Most enterprise technology is deterministic — you can set controls and verify behaviour. AI doesn't work that way. "You can't prove an AI system will or won't do X," he says, "so the traditional 'put controls around it and verify' model breaks down." Second: users won't wait. If IT takes its usual evaluation timeline, employees route around it. Shadow use, Tushman argues, creates more exposure than controlled rollout ever would.
Tony Vizza, founder and managing partner of advisory firm Novera, names the failure mode plainly: staff pasting sensitive data into public tools, or copying AI output directly into customer deliverables without checking it. Both scenarios flow from the same root cause — adoption without governance architecture.
Vizza recommends anchoring AI decisions to a formal risk register. Define expected outcomes, size of investment, and organisational importance before any deployment decision. Third-party accountability is a specific gap he flags. Contracts with AI providers need scrutiny — who bears liability in a data breach, and what recourse does the organisation actually have. "Some organisations build that into their risk management process," he says. "Others are quite flippant or don't even know they should be asking those questions."
At Hi Marley, Tushman's answer is structural. The team deliberately separates AI adopters — product and technical staff — from AI oversight functions sitting in compliance and legal. Compliance owns audits and security. Legal owns boundary documentation. The two sides are kept independent by design. Disagreements between innovation and oversight go to a senior leadership forum; unresolved ones escalate to the CEO.
"Conflict by design" is how Tushman describes it. It is not a committee built for consensus.
Karthik Chakkarapani, SVP and CIO at subscription-software company Zuora, three years into its AI programme, frames the mandate similarly: security and governance are required, but they cannot become the story. "You have to build the highway with enough guardrails and fewer speed breakers," he says.
The organisational design choices made now, Tushman believes, will compound. Companies that get the structure right early carry a durable advantage — not just in compliance posture, but in how fast they can move when the models improve again.



