AI Governance Leaders Network research

Posted 22/9/2026 by Simon Burton

 

We had our first AI Governance Leaders Network meeting this morning. Good mix of people: law firms, investment banks, a couple of the Big Four, global and regional consultancies. Different sectors, different risk appetites, but more common ground than expected.

Enablement vs. governance

Almost every conversation circled back to the same tension: how do you actually support people using AI, while still keeping some kind of grip on it. Nobody wants to be the department that blocks everything. But nobody wants to be the department explaining after the fact why nobody noticed things had gotten out of hand either.

This isn't something you fix once and move on from. It's a balance you have to keep resetting as the tools change under you.

AI governance doesn't always sit with someone who has that title

Worth flagging early, because it came up more than once. Plenty of the people actually doing AI governance work day-to-day don't have “AI governance” anywhere in their job title. That makes it harder to compare notes across organisations, because you're not always talking to the same kind of role even when you're talking about the same kind of problem.

Trust runs both ways

A few people made the point that governance only works if people actually trust it, and that has to be earned in both directions. Staff need to believe the people setting the rules understand how the work actually gets done, not just issuing blanket restrictions from a distance. And leadership needs to trust that people, given decent guidance, will make sensible calls rather than assuming the only safe option is to lock everything down.

Nobody had a neat answer for how you build that trust, but the general feeling was it comes from being visible and honest, not from writing a better policy.

Managing partners and working fee earners don't see the same thing

How close someone sits to the actual work changes what they think AI can or should do. A managing partner's sense of it is often built on demos and headlines. Someone working on live matters day to day usually has a far more grounded, and often more sceptical, view of where it genuinely helps and where it quietly causes problems nobody's noticed yet.

That gap matters when you're writing policy. Get input only from the top and you end up with something either too cautious to be useful, or too permissive because it misses how things actually break in practice. A few people felt strongly that good governance needs perspective from both ends, not just one.

There was a generational angle to this too, though it wasn't as tidy as you'd think. Comfort with AI doesn't split cleanly by age or seniority. Some of the most enthusiastic people in the room were senior, some of the most cautious were junior.

We hear that some lawyers check how much AI the other side used

Apparently some lawyers are already using AI to try to work out how much AI a counterparty firm used on a piece of work, reading the style and structure of their output for clues, essentially benchmarking the other side's adoption.

It's a small thing, but it points to something bigger. AI use is already becoming a signal firms read off each other, not just an internal efficiency question. Which means quality control on your own AI-assisted output isn't just about protecting yourself. It's also about what you're quietly telling counterparties who know what to look for.

Treating AI like a new hire

One of the more useful ideas floated was almost anthropomorphising the whole thing, treating a new AI tool a bit like you'd treat a new person joining the team. Do some due diligence before giving it access to anything. Write an actual specification for what it's meant to be responsible for. Be clear about who's accountable for checking its work.

It's not a perfect analogy, but it forces the right questions: what is this thing actually for, what happens when it gets something wrong, and who's on the hook for that.

Shadow AI isn't really a discipline problem

Several people said they're already seeing, or expect to see, people using tools outside whatever's officially sanctioned. Nobody in the room thought this was really about people cutting corners. It's what happens when the approved route is slower or more limited than what's sitting on someone's phone.

Two other reasons use goes unseen came up separately. Some people don't want to admit they used AI on a piece of work, particularly where there's a perception that it undermines the value of their own expertise or judgment. And conversely, some people are reluctant to ask questions about AI that they think might sound basic, because they don't want to be seen as not already across it. Both point the same way: visible use and visible questions need to be normalised, or a meaningful amount of actual usage and actual confusion stays hidden from whoever's trying to govern it.

Training six months ago is already out of date

This got the most airtime of anything. The pace of change means training can't be an annual event anymore. It has to be treated more like an ongoing service than a course you complete once.

Policies need to actually be living documents, not a PDF nobody's opened since it was uploaded. Training built around one specific tool doesn't age well, better to build real literacy in how these systems actually work, because that survives the next tool switch. Format matters more than people think: snapshots, short handouts, quick updates, not everything has to be a formal training session. And there was a strong belief in the room that people make good decisions when they actually understand what they're working with, which is really the argument for investing in literacy over just writing more rules.

Leaders need to role model this too, including being honest about what they don't know yet. A leader admitting they're still figuring this out does more for adoption than any top-down mandate.

Sovereignty isn't abstract for everyone

For some in the room, particularly those with clients who care a lot about this, data sovereignty isn't a theoretical governance question at all. It's something clients ask about directly, and it genuinely shapes which tools get chosen and how they're deployed.

What's next

There was clear appetite to keep comparing notes properly, so we'll be following up with some research on how organisations are actually approaching training, how they're handling shadow AI, where governance sits organisationally and where accountability lands, and real examples of what's worked across the group.

If you'd like to be involved in this network and help shape the research contact us.

Cookies on this website
We to ensure that we give you the best experience on our website. If you wish you can restrict or block cookies by changing your browser setting. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on this website.