Insight · August 6, 2026
Governance moved
into the product.
Most companies now run AI in production. When it is wrong, the failure shows up in the product, not the legal file. That is where a product team meets it.
01 · The shift
Governance used to be a memo. Now it is a product decision.
For a decade, governance meant a document. Legal wrote a policy, the policy sat in a shared drive, and the product shipped on its own schedule. That order worked because software was deterministic. It did what it was told, and what it was told was reviewed once.
AI broke the order. In McKinsey's 2025 global survey, 88 percent of organizations reported regularly using AI in at least one business function, up from 78 percent the year before. The systems are live. They answer customers, price orders, and draft the words a company stands behind. When one of them is wrong, the memo does not contain the damage. The product does, or it does not.
02 · What you own
The policy is not yours. The enforcement is.
A product team does not write the AI policy, and should not. What a product team owns is everything that makes the policy true at runtime. What the model is allowed to touch. What happens to its answer before a person sees it. What gets written down when it acts. Those are not legal questions. They are build questions, and they get decided in the same sprints as every other feature.
This is the quiet shift. Governance stopped being a gate the product passes through once and became a property the product either has or lacks, every hour it runs. You cannot delegate that to a file on a drive. You design it, or it is absent.
The one line to keep
“A policy nobody can enforce at runtime is a wish. Governance is the code that makes the wish true.”
03 · The four moves
The public scaffold, translated into product work.
The National Institute of Standards and Technology published its AI Risk Management Framework in January 2023. It is voluntary, and it is the reference most teams start from. Its four functions read like abstractions until you rewrite them as things a product team ships.
01
Set the boundary
Decide what the system is allowed to do before it can do anything. Which actions need a person, which data it may read, who is accountable when it acts. Written as configuration, not aspiration.
02
Know the surface
Name every place the model meets the world. The inputs it trusts, the tools it can call, the users it answers. You cannot govern a surface you have not drawn.
03
Grade the output
Score what the system produces against a bar you set, on real traffic, continuously. Not a demo that passed once. A number that moves, and that someone watches.
04
Contain the failure
Assume it will be wrong and design for that moment. A way to catch the bad answer, a way to roll it back, a record of what happened. Failure handled is failure survived.
04 · The clock
The regulation is now a date on the calendar.
The European Union's AI Act turned governance from good practice into law with teeth. On 2 August 2026 the Act reaches a decisive enforcement milestone. The oversight of general purpose AI models is in effect, and so is the penalty regime. The fines are not symbolic. For prohibited practices they run to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. For breaches of the general purpose AI obligations, up to 15 million euros or 3 percent.
The product lesson sits underneath the numbers. You cannot bolt compliance onto an opaque system after the fact. If the stack cannot show what the model did and why, there is nothing to hand a regulator, and no way to prove the boundary held. Accountability has to be built while the product is built, not reconstructed under audit.
05 · One case that made it real
A chatbot spoke for the company, and the company paid.
In late 2022 Jake Moffatt asked Air Canada's website chatbot about bereavement fares after his grandmother died. The chatbot told him he could book at full price and claim the lower rate afterward. The airline's real policy did not allow that. He paid full price and was refused the refund.
He took it to British Columbia's Civil Resolution Tribunal. Air Canada argued the chatbot was, in effect, a separate entity responsible for its own words. The tribunal rejected that outright. A company is responsible for everything on its site, it held, whether the words come from a static page or a bot. Air Canada was ordered to pay 650.88 Canadian dollars in damages in Moffatt v. Air Canada, decided in 2024.
the sum is small. the precedent is not. the model speaks for you. a governance gap is not an engineering footnote. it is a statement your company is legally bound to. every answer the system gives in your name is an answer you own.
Moffatt v. Air Canada · 2024 BCCRT 149
06 · Where accountability lives
Governance shows up in the interface, or it does not show up.
Most of the governance a user ever sees is interface. A citation next to a generated claim, so the answer can be checked. A visible marker when the system is unsure, instead of confident prose over a guess. A confirmation step before the model does something that spends money or sends a message. A decision trail a support agent can open when a customer disputes what the product said.
These are not compliance decorations. They are the components a classic design system never had to specify, because classic software did not improvise. A probabilistic product does. The interface is the last place a wrong answer can be caught before it becomes a customer's problem, or a tribunal's.
07 · Not a launch gate
You do not sign off once. You govern every day it runs.
The old model had a finish line. Review the build, approve it, ship it, move on. A probabilistic product has no such line. The model updates. The traffic shifts. An input the system has never seen arrives on a Tuesday and the output drifts.
So the work is continuous. Evals run on live traffic and grade quality the way tests once gated a merge. Guardrails sit at runtime and refuse the actions the boundary forbids, including the inputs written to hijack the system. A log records what the model did, so the answer to what happened is a query, not a guess.
Governance done this way is not a brake on shipping. It is the thing that lets you ship a product you cannot fully predict and still stand behind it.
Closing
Governance is not a document. It is a property of the thing you ship.
Pick the one place your AI already speaks for you. Ask what checks its answer before a customer sees it. If the answer is nothing, that is not a policy problem. It is the next thing to build.
McKinsey · The State of AI, 2025 · NIST AI Risk Management Framework 1.0, January 2023 · Moffatt v. Air Canada, 2024 BCCRT 149 · European Union AI Act, Article 99 and the August 2026 enforcement milestone
Share this perspective
More insights
Adjacent perspectives.
Bttr. Field Brief
The brief Bttr. writes for senior buyers.
Monthly. One signal worth your time on Brand Operating Systems, AI search visibility, and the infrastructure buildout. No filler.