One Global AI Policy or Regional Autonomy?
An AI Governance Dilemma.
A global retail company allows each regional office to develop and deploy AI solutions independently.
Innovation accelerates.
Regional teams can respond quickly to local customer needs and market conditions.
However, over time, the central risk team discovers that similar AI applications are being classified differently across regions.
Some offices consider an AI system to be low risk.
Others classify a similar system as high risk.
The result is inconsistent governance, potential safety gaps, and unclear accountability.
What would you do?
From an AI Governance perspective, there are generally three possible approaches.
Centralized Governance, the headquarters makes all major AI decisions.
Advantages:
• Consistent standards
• Clear accountability
Challenges:
• Slower innovation
• Reduced local flexibility
Decentralized Governance, each region manages its own AI governance.
Advantages:
• Faster execution
• Better adaptation to local markets
Challenges:
• Inconsistent risk management
• Fragmented governance practices
Hybrid Governance
• A central governance function establishes common principles, risk standards, and escalation thresholds.
• Regional teams retain the flexibility to execute day-to-day operations within those shared boundaries.
• In many large organizations, hybrid governance helps separate enterprise-level accountability from local operational execution.
Enterprise risks should be governed consistently, while operational decisions can remain locally adaptable.
From the NIST AI Risk Management Framework perspective, this scenario is not only about organizational structure. It is also about the relationship between the functions of GOVERN, MAP, and MANAGE.
The organization should establish shared governance policies and accountability structures (GOVERN), while ensuring that each region consistently identifies stakeholders, contexts, and AI risks (MAP).
Those risks should then be monitored and managed throughout the AI lifecycle using appropriate controls and continuous improvement mechanisms (MANAGE).
AI innovation should be accompanied by governance mechanisms that foster trust.
My perspective:
• AI Governance should not become a bureaucratic process that slows innovation.
• At the same time, governance should not be so decentralized that every business unit creates its own definition of acceptable AI risk.
• The role of AI Governance is to build common guardrails that enable organizations to innovate responsibly.
• Governance should provide direction, not unnecessary obstacles.
Question for discussion:
If you were responsible for AI Governance in this organization,
Would you choose a centralized, decentralized, or hybrid model—and why?