Donna Medeiros explains why treating AI governance as pure control is choking off value, especially across the public sector, and what balancing risk with value actually looks like.

The Control Trap: Why Public Sector AI Governance Still Chokes the Value It Was Meant to Protect

Ask most organizations what their AI governance program actually does, and the honest answer is usually some version of “it says no.” A tool gets flagged, a use case gets tabled, a pilot sits in a review queue for months. The policy manages risk well enough. It rarely helps anyone get to yes.

Donna Medeiros, VP of AI and Data Advisory at Data Society, sees this pattern constantly in her advisory work, and she’s blunt about why it persists.
“So many organizations say that governance is seen as a control function, either not allowing AI tools in use, or being very limited in how they’re used. That chokes off innovation and experimentation.”

The Organizations Getting This Right Look Different

Not every organization defaults to control-only governance. Donna points to a clear pattern among the ones that don’t.

“Those that do it right have an innovation mindset. They balance AI governance with risk and value, and they have a use case, project-based framework.”

What separates the two isn’t how careful each one is. It’s what the governance function is actually optimizing for. A control-only model measures success by what it prevented. A risk-and-value model measures success by what it enabled safely, use case by use case, with a defined owner and a defined outcome behind each one. The second model needs more structure up front, not less. It just points that structure at a different goal.

That reframe already has traction outside Data Society’s own advisory work. Writing about UK public sector AI adoption, technology consultant David Rai calls compliance “the ultimate innovation enabler” rather than a barrier to transformation, and argues the real risk sits in the gaps governance leaves open, shadow AI tools handling sensitive data, or poor data quality quietly amplifying bias at scale, not in governance itself, according to THINK Digital Partners. That’s the same sequence Donna is describing: governance comes first, and the innovation gets built on top of it with confidence.

The Public Sector Shows This Trap at Scale

Donna hears this dynamic constantly from one sector in particular.
“I hear a lot from the public sector right now, whether it’s municipalities or the state level, how the governance itself is still very risk-balanced, and it’s choking off potential value, even the services for citizens.”

The data backs her up. State CIOs named AI their top strategic priority for 2026 in NASCIO’s state IT priorities survey, now in its 20th year, with the list weighted toward governance, security, and ethical-use concerns rather than deployment speed, according to StateTech Magazine. That caution is compounding: state CISO confidence in their own security capabilities dropped from 48 percent in 2022 to 22 percent in 2026, according to SecureWorld’s coverage of the 2026 NASCIO-Deloitte study, a decline that pushes procurement and AI decisions into an even more defensive posture.

The federal government shows the same pattern at larger scale. Nearly 60 percent of federal AI use cases are still stuck in the pilot or pre-deployment stage, according to Brookings’ review of federal AI adoption, largely because authorization processes built for static software, like the Paperwork Reduction Act’s six-to-nine-month approval timelines, were never designed for AI systems that need iterative updates. The same review found that more than 85 percent of high-impact federal AI use cases deployed in 2025 were missing required risk mitigation documentation despite explicit OMB requirements. Heavy process doesn’t guarantee good governance. Sometimes it just produces a slower version of the same gaps.

What Gets Lost When Governance Only Knows How to Say No

Donna is specific about what’s actually at stake.

“It’s choking off the fact that some innovative AI product, some data product, isn’t going to get developed, which would be of great value and could enable the business, maybe even drive it forward.”

For a public agency, that lost product might be a faster benefits-eligibility check, a case-routing tool that gets a citizen’s request to the right department the first time, or a fraud-detection model that frees up staff for the cases that actually need a human judgment call. A governance model that only knows how to withhold approval never builds any of it.

Under-governance carries its own version of this problem. A 2025 KPMG survey found that 58 percent of employees already use AI tools at work on a regular basis, policy or no policy, and research from UNC’s School of Government notes that many local governments still have no formal AI policy at all. The absence of governance doesn’t stop AI use. It just moves that use somewhere nobody’s tracking it, which is its own risk.
Truyo’s analysis of 2026 AI governance trends puts the actual trade-off plainly: weak governance stalls progress, while strong governance, the kind built around clear rules and defined ownership rather than blanket restriction, accelerates it. The agencies and companies Donna sees moving fastest aren’t running looser reviews. They’re running a use case, project-based framework built to get a good idea to a confident yes instead of a form built only to catch the ones that deserve a no.

Frequently Asked Questions

It is what happens when a governance program is built only to restrict, so its visible output is flagged tools, tabled use cases, and pilots parked in review queues for months. Donna Medeiros describes this as governance treated purely as a control function, which chokes off innovation and experimentation.

How do organizations govern AI well?

The ones getting it right work from an innovation mindset, balance governance against risk and value together, and run a use case, project-based framework with a defined owner and outcome behind each project. That model asks for more structure up front rather than less, because it exists to reach a confident yes instead of only catching the ideas that deserve a no.

State CIOs named AI their top strategic priority for 2026 in NASCIO’s survey of 51 state and territory CIOs, now in its 20th year, with the list weighted toward governance, security, and ethical use rather than deployment speed, while state CISO confidence in protecting public data fell from 48 percent in 2022 to 22 percent in 2026. At the federal level, nearly 60 percent of AI use cases with deployment data are still in the pilot or pre-deployment stage, slowed by authorization processes like the Paperwork Reduction Act’s six-to-nine-month timelines that were designed for static software.

What goes missing is the product nobody builds: a faster benefits-eligibility check, a case-routing tool that gets a request to the right department the first time, or a fraud-detection model that frees staff for the cases that need human judgment. A slower process is not automatically a safer one, since more than 85 percent of high-impact federal AI use cases deployed in 2025 were missing required risk mitigation information despite explicit OMB requirements.

The AI use does not stop, it simply moves somewhere nobody is tracking it, which carries its own risk. KPMG’s 2025 global study found that 58 percent of employees intentionally use AI at work, with about a third using it weekly or daily, and many local governments still have no formal AI policy at all.

Don’t wanna miss any Data Society Resources?

Stay informed with Data Society Resources—get the latest news, blogs, press releases, thought leadership, and case studies delivered straight to your inbox.

Data: Resources

Get the latest updates on AI, data science, and our industry insights. From expert press releases, Blogs, News & Thought leadership. Find everything in one place.

View All Resources
  • The Control Trap: Why Public Sector AI Governance Still Chokes the Value It Was Meant to Protect

    September 18, 2026

    Read more

  • Who Decides What AI Owes the Public: Governments or the Frontier Labs Building It

    September 18, 2026

    Read more