← All Articles
Strategic

Nobody Is in Charge of the AI in Your Company

Four nightmares, one root cause, and the open operating model that fixes it: if AI touched it, someone signs for it.

KE
Brian Stack
August 23, 2026
7 min read

Ask a CEO what the company’s cash position is and you get an answer in one call. Ask about security posture and someone produces a report. Ask what AI is doing inside the company right now, who is using it, on what data, at what cost, with what oversight, and you get silence. Not evasion. Silence. The artifact that would answer the question does not exist.

Meanwhile the use is already happening. Employees paste customer data into chatbots to write emails faster. A vendor pushes an update and suddenly the CRM has an AI assistant reading every record. Someone in finance builds a forecast with a model nobody vetted, and the number goes in the board deck. None of this is malicious. Most of it is invisible. All of it is unmanaged.

This is not a technology problem. It is a governance vacuum, and it has four distinct parts.

Permission. Nobody decided who may use what AI, for what purpose, on what data. So everyone decided for themselves. Most companies have more AI policies in their employees’ heads than on paper, and no two match.

Protection. Data leaves through AI one paste at a time, by well-meaning people, into tools with training rights and retention terms nobody read. Traditional security controls watch the network perimeter. The new perimeter is a prompt box.

Provenance. AI-generated content is flowing into contracts, filings, and decisions with no marking, no review tier, and no record of where it came from. When a number is wrong, there will be no way to reconstruct how it got there, and no name attached to it.

Price. AI spend is fragmenting across subscriptions, embedded upcharges, and usage-based billing that no one forecasts. Many companies are paying for the same capability four times and could not produce a total AI number within an order of magnitude.

Four nightmares, and they share one root: no one signs for any of it.

The principle that fixes it

Accountability is the oldest control there is. Financial reporting was chaos until officers had to certify the numbers. Federal contractors treated cybersecurity as paperwork until executives had to affirm their scores under penalty of the False Claims Act. The signature is what turns policy into behavior. It always has been.

AI needs the same spine: if AI touched it, someone signs for it. Every sanctioned tool has a named owner. Every consequential output has a human who adopted it. Once a year, an officer attests that the inventory is complete and the controls are real.

That principle, made operational, is a model any company can run. We call it the Stehrling AI Governance Model, and we have published it openly. It has three parts.

The Stehrling AI Governance Model v1.0 — four planes converging at the Gate, the loop, one signature over the top

The Stehrling AI Governance Model v1.0 — four planes, one gate, one loop, one signature. © 2026 Stehrling LLC, CC BY-ND 4.0.

Four planes. Permission, Protection, Provenance, Price. Each plane is one plain question, a short list of artifacts, and a named owner. Permission belongs to legal and compliance: the acceptable use policy, the sanctioned tool register, the rules for what never enters a prompt. Protection belongs to the CISO: the sanctioned environment, the boundary, the logging. Provenance belongs to the business function adopting the output: labeling, review gates scaled to consequence, records for the outputs that matter. Price belongs to the CFO: one register of all AI spend, and a simple value test per use. A marketing draft and a regulatory filing do not need the same controls. A model that pretends otherwise gets ignored, and deserves to.

A loop, not a document. Inventory what is in use, sanctioned and shadow. Sanction each tool and use: approve, contain, or kill. Contain sensitive work inside the boundary. Watch quarterly, because the tool landscape changes monthly and a policy written in January is stale by June. Attest annually, with a name on it. Companies that write an AI policy once and file it away will discover they own a very expensive historical document.

Four maturity levels. Level 0, Shadow: AI is in use and leadership has not looked. This is most companies today. Level 1, Aware: inventory done, policy written, nothing enforced. Level 2, Governed: the four planes operating and the loop running. Level 3, Attested: an officer signs annually, and the company can hand its AI attestation to anyone who asks.

That last phrase is the point of the whole model. Here is a prediction we are willing to be graded on: within a few years, customers, insurers, and regulators will ask for a signed AI attestation the way they ask for a SOC 2 today. Insurance carriers are already probing AI use in underwriting questionnaires. Enterprise procurement teams are already adding AI clauses to vendor security addenda. The demand letter is coming. The companies that can answer it will be the ones that built governance before anyone required it, which is when governance is cheapest to build.

Existing frameworks do not fill this gap, because they were written for a different reader. NIST AI RMF and ISO 42001 address organizations building and deploying AI systems. The EU AI Act regulates providers and high-risk deployers. All useful. None of them tells the other 99 percent of companies, the ones whose reality is employees with browsers and vendors with embedded copilots, what being in control looks like. The Stehrling AI Governance Model is a business operating framework for the companies that use AI. It operationalizes those frameworks on the consumer side rather than replacing them. That is deliberate.

The model is published openly and free to use. Start with the question that costs nothing and reveals everything: if a customer asked tomorrow for evidence that your use of AI is under control, what would you send them?

Right now, for almost everyone, the honest answer is nothing. That is a solvable problem, and the companies that solve it first will spend the next decade answering the question in one call, the way they answer the cash question today.

The Stehrling AI Governance Model is published under CC BY-ND 4.0: share and cite freely with attribution, without modification. The canonical version lives at stehrling.com/ai-governance-model. © 2026 Stehrling LLC.

Want to know where your organization stands?

Take our 3-minute Readiness Check and get an instant gap summary based on your environment.

Start Readiness Check →

An independent firm focused exclusively on CMMC compliance for defense contractors and the DIB.

Fredericksburg, VA