Somewhere in your org right now, there is a slide deck called "AI Strategy." It's probably at
version 4.3, past a compliance review, with a section titled "Responsible AI Principles." It exists
because your board asked for it, and your job depends on producing it.
Nobody who wrote it thinks it's real.
I don't mean the people are cynical. I mean the artifact is a compliance object, not a decision.
Once you notice that shape, you start seeing it everywhere.
Bruce Schneier gave us a phrase for this pattern back in 2003, in a different context: security
theater. The airport shoe removal, the plastic knives on planes. Visible activity that looks like
security without producing any. The point of security theater was never to catch a bad actor. It
was to reassure the people watching.
Twenty-three years later, we've built the software industry version of that. Call it governance
theater.
The mechanics of a rational trap
Nobody sat down and chose to build theater. The organizational incentives just make it the path
of least resistance.
If you're a CTO, your board wants "an AI strategy" by Q3. Tell them you don't need one yet and
you look asleep at the wheel. Ask for eighteen months to figure out the right shape for your
specific business, and you look slow. Produce a 40-slide deck with a governance framework, an
ethics statement, six pilot programs, and a moon-shot POC in a new business unit, and you look
ready. Only one of those keeps your job safe past the next board cycle.
If you're on the legal team, saying no to a project makes you the villain. Saying yes with 43
conditions makes you a professional. The conditions rarely get audited. The yes is what ships.
If you're the risk committee, you have no authority to stop anything. Your budget is a rounding
error, and your outputs are memos. Memos are how organizations decide not to decide.
None of these people are villains. They're rational actors in a system that rewards the
appearance of governance over the practice of it. The gap between the artifact and the decision is
the entire game.
The committee versus the permission to say no
Every enterprise now has an AI Ethics Committee, or an AI Steering Group, or a Responsible AI
Council. Pick your favorite noun stack. They meet monthly, produce a charter, review submissions.
Ask the person running one how many projects they've stopped.
Watch the pause.
The pause is the answer.
Governance without the authority to refuse isn't governance. It's a permission-slip factory.
Every project comes in, gets stamped, goes out. Its function isn't to gate. It's to produce a paper
trail proving that gates were considered.
That's not a small distinction. It's the entire difference between a governance function and its
imitation.
The numbers under the polish
You don't have to take my word for the pattern. The industry has been measuring itself for a few
years now, and the shape is visible in the data.
MIT's NANDA project published The State of AI in Business in August 2025. Their finding:
95% of enterprise generative AI pilots produced no measurable return. Ninety-five percent. Not a
fringe number. That's the typical outcome of enterprise AI investment right now, not an outlier.
Boston Consulting Group ran a global survey the year before and reported that 74% of companies
could not show tangible value from AI investments. Only 22% qualified as "leaders." Only 4% had
cutting-edge AI capabilities operating across functions. The other 74% were shipping activity, not
outcomes.
The Stanford AI Index Report 2025, in its Responsible AI chapter, published something quieter
that's worth sitting with. Organizations were asked which AI risks they recognize, and separately,
which they actively mitigate. Every category shows the same gap. Cybersecurity: 66% recognize, 55%
mitigate. Regulatory compliance: 63% recognize, 50% mitigate. Intellectual property infringement:
57% recognize, 38% mitigate. Fewer organizations act than admit they should.
IBM's 2026 CIO study put a name on the compounding version of this. Seventy-seven percent of
CIOs and CTOs surveyed report that AI adoption in their org is outpacing their governance
capabilities. Sixty-six percent are accountable for AI systems they don't fully control. Eleven
percent believe they're ready for the deployment scale coming by 2027.
Those numbers aren't a training problem, and they aren't a maturity curve that patience will
fix. They're the same pattern showing up everywhere anyone bothered to measure it. The artifacts
get produced. The decisions do not.
The bill you don't get to skip
When governance can't actually stop bad projects, the cost isn't zero. It compounds in ways that
are invisible on any single project. Obvious across a portfolio.
Rework is the first bill. The projects nobody was allowed to say no to become the projects
nobody wants to own. Six months later a small team is quietly unwinding what a large team
enthusiastically shipped.
Customer trust is the second. When your AI product ships broken because the governance was
decorative, your customers perform the actual governance for you. Publicly. On social media. Your
engineers know before your customers do. The executive team knows after.
Then your senior engineers. They've been in the room. They watched the committee wave through
the thing they flagged as a problem. They filed the objection in writing. They saw the objection
get "resolved" without being addressed. Something quietly breaks in a good engineer the third or
fourth time that happens. They stop objecting. Later they leave.
And when the regulator eventually shows up (they do, in every industry that touches personal
data or safety-critical decisions), the paper trail becomes evidence against you rather than for
you. "The AI Ethics Committee reviewed it" is a defense until the discovery process finds the
internal thread where three people warned about the exact failure mode that occurred.
None of this is theoretical. It's already happening, at organizations that have all the
artifacts.
The direction the industry is moving
The problem gets worse from here.
What I've been calling the openclaw moment is the current industry trajectory: autonomous agents
calling autonomous agents, subtasks fanning out to more subtasks, data moving to services that were
never explicitly authorized because no human was in the room when the decision was made. The
vendors selling this direction call it agentic AI. Your board is probably reading a McKinsey slide
about it right now.
If your governance is decorative today, that direction turns it into professional malpractice
tomorrow. A committee that can't stop a human-authored project has no chance against a fan-out of
agent-authored subtasks that finished before the ticket got assigned. Theater scales badly.
I'm not arguing against agents. I'm arguing that the governance layer has to be real before the
agent layer runs at scale, or the agent layer eats the org before anyone knows what happened.
What real governance actually looks like
Real governance has a few properties that theater doesn't, and each one is something you can
test.
It records decisions with their trade-offs, not only their outcomes. "We shipped it" isn't a
decision. "We shipped it despite these three concerns, resolved this way, accepting this remaining
risk, owned by this person" is a decision. The second one survives an audit. The first one is a
headline waiting to happen.
It has a mechanism for refusal that carries actual weight. A committee can say no, and the no
sticks by default. There's a defined override path, but every override gets recorded and owned by a
name. If every no gets overridden and nothing is recorded, you have theater with better fonts.
It maintains a trail that survives the people who wrote it. When the engineer who wrote the spec
leaves and the PM who owned the feature moves on, the reasoning is still legible to the person who
inherits it. Not the outcome. The reasoning. That's a governance artifact. Anything less is a
status update with a compliance stamp.
It catches drift as it happens, not in the post-mortem. Something changed between what got
approved and what got built. Somebody flags it before the change ships, not three months later when
the customer flags it.
None of that requires a new committee. It requires that the practices your existing committee
already claims to do actually produce artifacts an outside auditor could interpret. That's the
test.
Here's the uncomfortable part. Doing this actually slows a team down at first. Deliberation is
slow, and governance is what forces the deliberation. A team practicing real governance ships fewer
projects and defends the ones it ships better. Real governance is cheaper across a year. It feels
expensive in the moment. Most organizations never get past the moment.
The diagnostic
Go find whoever is running your AI governance function. It could be a Chief AI Officer, a VP of
Trust, a committee chair, or the poor senior counsel who inherited the responsibility because
nobody else raised their hand.
Ask them to name a specific project where the governance framework produced a different outcome
than would have happened without it. Not a project that was reviewed. Not a project that received
conditions. A project where the framework caused a decision to change.
If they can name one, you have governance.
If they hesitate, you have theater.
If they name one and the "different outcome" turns out to be a schedule delay rather than a
redirect, that's theater with a delay function bolted on.
That's the entire test. Everything downstream is a consequence.
The part that should make your stomach drop a little
Nobody in this system is a bad person. Your CTO isn't lazy. Your risk committee isn't asleep.
They're all operating inside a system that rewards theater and taxes substance. Change the
incentives or the pattern continues.
Real governance asks hard questions before shipping. Most organizations never get the chance to
practice it.
Go look at the last approval memo your team produced. Ask whether it changed a decision.
That's the diagnostic. The rest is fonts.
Andrew Schwabe is the founder of QCoda, working in AI engineering governance. Twenty-five-plus
years in engineering leadership will do that to you.
References
- Bruce Schneier. Beyond Fear: Thinking Sensibly About Security in an Uncertain World.
Copernicus Books, 2003. Origin of the term "security theater."
- MIT NANDA. The State of AI in Business 2025: The GenAI Divide. August 2025. Finding:
95% of enterprise generative AI pilots produced no measurable ROI.
Report PDF.
- Boston Consulting Group. AI Adoption in 2024: 74% of Companies Struggle to Achieve and
Scale Value. Press release, October 24, 2024.
BCG press release.
- Stanford HAI. Artificial Intelligence Index Report 2025, Chapter 3: Responsible AI.
April 2025. Recognition-vs-mitigation gap data drawn from the McKinsey global AI survey
referenced in the chapter.
Chapter 3 PDF.
- IBM. New IBM Study Finds CIOs and CTOs Face Growing AI Control Gap as Enterprise
Deployment Scales. Newsroom release, June 8, 2026.
IBM newsroom.