Three months ago, in a meeting that had nothing to do with technology, someone finally asked the question every executive team eventually has to face: “If one of our AI tools makes a bad call next quarter, whose name is on it?” The room went quiet. Not because no one had an answer, but because everyone realized, at the same moment, that no one had thought to ask.

That silence is the real story of AI in business right now. Not the productivity gains, not the vendor demos, not the breathless keynotes. The real story is a governance gap that most organizations have not yet admitted they have.

I lead the Americas business for Mauviel 1830, a French copper cookware maker that has been in continuous operation since 1830. We are about as far from a Silicon Valley company as a business can be, which is exactly why I have paid close attention to how AI moves through an organization that was not built for it. Over the past two years I have watched AI tools show up in our forecasting, our finance close, our onboarding, and our marketing content review, often before anyone in leadership formally approved them. Somebody found a tool that solved a real problem, started using it, and word spread. That is not a criticism of my team. It is how AI adoption happens almost everywhere, and it is precisely why governance cannot be an afterthought.

The data backs this up. McKinsey's 2025 State of AI survey found that only 28 percent of organizations say their CEO takes direct responsibility for AI governance, and just 17 percent say their board does. Deloitte's most recent State of AI in the Enterprise report found a similar pattern: as companies race toward more autonomous, agentic AI, roughly one in five has a governance model mature enough to actually manage it. Put plainly: adoption has a two-year head start on oversight, and the gap is widening, not closing.

This should worry leaders more than it currently does, because governance is not a compliance exercise you bolt on later. It is what determines whether AI compounds your advantage or quietly erodes the thing your business is actually built on. In a heritage brand like ours, that thing is trust; trust in the craftsmanship and trust in the judgment behind every decision that touches a customer. AI can strengthen that trust or undermine it in a single misstep, and the difference usually comes down to whether someone was actually accountable for the decision to deploy it.

So what does real governance look like in practice, as opposed to a slide in a strategy deck? For us, it started with three plain questions we now ask before any AI tool touches customer data, brand content, or a decision that affects people: Who owns this decision if the tool gets it wrong? What data is this tool actually seeing, and did the people whose data it is agree to that? And where does this tool stop, and a person starts? Those three questions sound almost too simple to matter. In practice, they are the entire difference between AI governance as a genuine discipline and AI governance as a document nobody reads.

The ownership question matters most, because it is the one organizations dodge most often. It is easy to say “the team decides” or “IT will handle it.” Neither is an answer. When we set up a small cross-functional review across finance, marketing and operations, meeting briefly whenever a new AI use case comes up, the change was not procedural, it was cultural. People started thinking about AI decisions the way they think about financial ones: with a name attached, a rationale on record, and a person who could explain the choice if asked. That single shift, more than any policy document, is what closed our governance gap.

The data question comes next, and it is where most shortcuts get taken. Every AI tool is trained on something or draws on something, and the fastest way to damage a heritage brand or any brand is to let a tool touch customer information, proprietary designs or sensitive records without asking basic questions about where that data goes and who else might see it. This is not a legal department problem to be solved after the fact. It has to be asked before the tool is adopted, not after something goes wrong.

The third question, where the tool stops and a person starts, is a judgment call every organization has to make for itself; it will look different depending on the industry and the stakes involved. What matters is that the line is drawn deliberately, in advance, rather than discovered accidentally after a mistake reaches a customer.

None of this is a case against AI adoption. If anything, the organizations that govern well move faster, because they are not constantly firefighting problems that better upfront judgment would have prevented. Governance, done properly, is not a brake. It is closer to a suspension system, the thing that lets you go over rough ground at speed without the wheels coming off.

The uncomfortable truth is that most companies will not build this discipline proactively. They will build it after an incident: a data exposure, a biased hiring recommendation or a customer-facing mistake that becomes public. My hope in writing this is that a few more leaders build it before that happens, because the cost of governing early is a few uncomfortable meetings, and the cost of governing late is a rebuilding of trust that can take years.

If your organization has not yet had the meeting where someone asks who is accountable for what your AI tools decide, I would treat that as the most important meeting on your calendar this quarter. The technology will keep moving regardless. The only real choice leaders have is whether judgment moves with it.

About the Author

Carlos Antillano is Vice President Americas at Mauviel 1830 and the author of The Ultimate Perseverance Training. He writes about leadership, AI governance, resilience, and building trust in legacy brands.

Sources:

McKinsey & Company, “The State of AI: How Organizations Are Rewiring to Capture Value”, 2025 Deloitte, “The State of AI in the Enterprise," 2025