Learn how to build an AI governance framework enterprises will actually use, with insights from Data Society’s Donna Medeiros.

The Enablement Mindset: How to Build an AI Governance Framework Enterprises Will Actually Use

Ask most executives what “AI governance” means to their organization, and you’ll hear some version of the same answer: a list of restrictions, a compliance checklist, a legal sign-off that slows down every pilot project. That perception is understandable. It’s also the reason so many governance programs quietly fail. Employees route around them, business units build shadow AI workflows outside official channels, and the organization ends up with less oversight than before the policy existed.

Donna Medeiros, VP of AI and Data Advisory at Data Society, has spent the last several years helping enterprises rethink that framing entirely. Her core argument is simple but easy to miss when you’re under pressure to “do something” about AI risk: governance that only shows up as a gate at the end of a process will always be resented and eventually bypassed. Governance that shows up as a partner throughout the process becomes something teams actually use.

WHY EVERY AI GOVERNANCE FRAMEWORK NEEDS A HUMAN IN THE LOOP, FOR NOW

Before getting into structure and ownership, Donna is clear about a boundary that shapes everything else in the framework: AI is not ready to run unsupervised on business-critical decisions.

“I believe there needs to be a human in the loop for most of AI’s decision making. We’re not there at this point in time to have AI be completely business autonomous.”

That single point should anchor how executives think about scope. An AI governance framework isn’t primarily about picking the right vendor or writing an acceptable use policy, although both matter. It’s about deciding, deliberately, where a human must review, approve, or override an AI-generated output before it becomes an action. Agentic AI tools are increasingly capable of taking multi-step actions on their own, which makes this checkpoint more urgent, not less. The organizations getting this right aren’t the ones with the most restrictive policies. They’re the ones that have mapped exactly which decisions require human sign-off and built that requirement into the workflow itself, not just into a document nobody rereads after the rollout.

REFRAMING GOVERNANCE AS ENABLEMENT, NOT A BRAKE PEDAL

This is where Donna’s framing diverges most sharply from the conventional compliance-first approach.

“Governance should be enablement for the outcomes and not just an outcome being reached and then spun off unchecked.”

Read that twice, because it reverses the usual sequence. Most organizations treat governance as something that happens after a capability exists: a team builds a tool or adopts a vendor platform, and governance arrives afterward to contain the risk. Donna’s model treats governance as the thing that makes the outcome possible and trustworthy in the first place. It’s not a brake, it’s the steering system.

That distinction matters practically. When governance is positioned as enablement, it changes the conversation executives have with business units. Instead of “here’s what you can’t do,” the conversation becomes “here’s how we get you to a faster, safer yes.” Some organizations even go as far as rebranding the function internally, calling it “AI enablement” rather than “AI governance,” specifically to shed the cost-center connotation. The name change alone won’t fix a broken program, but it signals to the organization what the function is actually there to do: help teams move, not just police them after they’ve already moved. This kind of top-down reframing needs visible executive sponsorship. If leadership treats governance as something to tolerate rather than champion, the rest of the organization will follow that cue.

WHAT GOVERNANCE ACTUALLY COORDINATES

It helps to be concrete about what “governance” covers, because the word gets used loosely. Donna describes it as an orchestration function, not a single control.

“It’s usually the orchestration of AI to ensure that risk is mitigated, that value is received, and that throughout the organization there’s the roles and responsibilities needed for AI value realization.”

Three things are packed into that sentence, and enterprises tend to focus on only one of them. Risk mitigation gets the most attention because it’s the easiest to justify to a board. Value realization gets less attention, even though it’s the entire point of adopting AI in the first place, whether that’s a chatbot, a forecasting model, or an agentic workflow. And roles and responsibilities, the actual organizational plumbing of who is accountable for what, often gets skipped entirely until something goes wrong and nobody can say who owned the decision.

A governance framework that only addresses risk will feel like pure friction to the business. A framework that also tracks whether AI investments are producing value, and clarifies who is accountable at each stage, earns credibility with the people it’s meant to guide. Organizations that have gone through this exercise deliberately, building a genuine data governance culture, tend to see much higher adoption of the framework itself: https://datasociety.com/data-leadership-collaborative-creating-a-data-governance-culture/ Lockheed Martin’s approach to scaling AI with governance is a useful real-world example of what that orchestration looks like at enterprise scale, and it’s worth studying alongside your own framework design: https://datasociety.com/scaling-ai-with-governance-practical-advice-from-lockheed-martins-mike-baylor/

WHO SHOULD OWN AI GOVERNANCE

Ownership is one of the most common sticking points executives raise, and Donna’s answer reflects how the role has evolved across the market.

“AI governance has heavily been managed at the central function these days by an AI officer, chief AI officer if one exists, or it could be the CIO if one doesn’t exist, CTO, or could be the CDO.”

Notice that this is a central function, not a solo function. A chief AI officer, CIO, CTO, or CDO can hold the pen, but none of them can execute governance alone. Legal needs a seat at the table for regulatory exposure and contract risk. HR needs to be involved because AI tools reshape how people are trained, evaluated, and in some cases replaced. And business-line leaders need real ownership, not just a notification, because they understand where AI is actually being used day to day, often in ways central IT doesn’t fully see. A federated model, where the central function sets the framework and standards while business units apply and adapt it to their own workflows, tends to outperform a purely top-down or purely decentralized approach. Data Society’s launch of dedicated AI advisory services was built around exactly this kind of cross-functional support, recognizing that governance design is rarely a job any single department can do in isolation: https://datasociety.com/data-society-launches-ai-advisory-services-to-support-responsible-outcomes-driven-ai-adoption/

GOVERNANCE AND TRAINING HAVE TO MOVE TOGETHER

Perhaps the most practical insight from Donna’s perspective is one that executives frequently underweight: governance and workforce training are not sequential projects. They’re the same project.

“Fluency in AI can’t happen without the governance. It can’t happen without the skills enablement. It’s a dual thing.”

And again, reinforcing the point:

“Governance also has to be paired with the trainings to get that AI fluency needed.”

Here’s why that matters for anyone building a framework right now. A governance policy that nobody understands isn’t a safeguard, it’s a liability with a false sense of security attached. If your teams don’t know which decisions require human review, what the acceptable use boundaries are, or how to escalate a questionable AI output, the policy exists only on paper. Skills enablement is what turns a governance document into an operating norm. That’s also why Data Society’s approach to AI advisory pairs governance design work directly with instructor-led training rather than treating them as separate line items on a budget. The 2025 AI Readiness Report found that many organizations are still treating these as disconnected workstreams, which is a large part of why so many AI governance frameworks stall after the initial policy rollout: https://datasociety.com/the-2025-ai-readiness-report-insights-to-build-your-2026-strategy/

If you’re an executive sponsoring an AI governance initiative this year, the practical takeaway is to stop asking “what should we restrict” as the first question. Start with “what outcomes are we trying to enable, and what does responsible look like for each one.” The restrictions will follow naturally. The trust from your business units will follow too, and that trust is what actually determines whether your framework gets used or quietly ignored.

Frequently Asked Questions

An AI governance framework is the set of policies, roles, and oversight mechanisms that guide how an organization develops, deploys, and monitors AI systems. Rather than functioning only as a risk checklist, an effective framework also enables safe, faster adoption by clarifying accountability and tracking whether AI investments deliver real value.

Who Should Own AI Governance in an Enterprise?

Ownership is typically centralized under a chief AI officer, CIO, CTO, or CDO, depending on the organization’s structure, but effective governance requires close collaboration with legal, HR, and individual business-line leaders. A purely centralized or purely decentralized model tends to underperform a federated approach where central standards are adapted locally.

Current AI systems, including agentic AI, are not reliable enough to make consequential business decisions fully autonomously. Human review at key decision points reduces the risk of costly errors, compliance violations, or reputational damage while AI capabilities continue to mature.

Traditional governance is often perceived as restrictive, arriving after a capability is built to contain risk. AI enablement reframes governance as a function that makes safe, value-generating outcomes possible from the start, positioning the team as a partner in adoption rather than a gatekeeper.

A governance policy is only effective if employees understand and apply it. Without paired skills training, staff may not know when human review is required or how to use AI tools within approved boundaries, making the policy symbolic rather than operational.

READY TO BUILD A GOVERNANCE FRAMEWORK YOUR TEAMS WILL ACTUALLY FOLLOW?

If your AI governance policy is sitting in a shared drive while your teams quietly work around it, the framework needs a redesign, not another memo. Book time with Donna to pressure-test your AI governance framework and turn it into something your business units treat as a genuine enabler rather than an obstacle: https://meetings.hubspot.com/donna-medeiros/meet-with-data-societys-ai-and-data-advisor

Don’t wanna miss any Data Society Resources?

Stay informed with Data Society Resources—get the latest news, blogs, press releases, thought leadership, and case studies delivered straight to your inbox.

Data: Resources

Get the latest updates on AI, data science, and our industry insights. From expert press releases, Blogs, News & Thought leadership. Find everything in one place.

View All Resources
  • The Enablement Mindset: How to Build an AI Governance Framework Enterprises Will Actually Use

    July 21, 2026

    Read more

  • Data Before Models: How to Build an AI Governance Framework Your Enterprise Will Actually Use

    July 20, 2026

    Read more