Everyone agrees AI governance matters, but very few have an effective, centralized program actually running yet. And your project teams aren't waiting around for one.
If you work in a decentralized organization, a small business unit, or a government agency, you already know the problem I'm talking about. I spent the better part of my career automating public services for the State of New Jersey, from tax systems to business registration to notary and UCC filings, and more recently helped implement AI for customer service while also serving as chief technology officer for the Department of Treasury. That combination, building the systems and writing the governance around them, is where this idea came from. I call it the middle path, or project-level governance.
Strip away the frameworks and standards, and governance comes down to two things: decision rights and leadership. Somebody has to set the functional and performance parameters for what an AI system is supposed to do, and somebody has to make sure it operates safely, soundly, and in compliance with whatever rules apply to it.
Frameworks like the EU AI Act and the NIST AI Risk Management Framework are parts of the gold standard list for elaborating on those two core functions. But they're built for organizations with the resources to run a formal, centralized program. A lot of us don't have that. And that's not a reason to skip governance. It's a reason to rethink where it happens.
Formal, centralized AI governance requires permanent structures: cross-disciplinary coordination, sustained executive attention, and real resources. In my experience, organizations that try to stand this up from the top down usually end up in one of two places. Either the central group gets stuck in long-running debate about what governance should even look like, or it produces rote bureaucracy, forms and procedures that the local business units, the people actually generating creative uses of the technology, experience as pure overhead with no value attached.
That leaves an organization facing a real dilemma. Wait for centralized governance to materialize, and you risk institutional paralysis. Push ahead with AI projects and no governance at all, and you risk real harm to your stakeholders and your organization. Neither extreme is good.
The middle path is a third option. Instead of waiting for a centralized program, you delegate governance authority to the people running individual AI projects, and you build governance directly into the project management plans they're already using.
This isn't an anything-goes approach. It requires what I call responsible agility: local business leaders take ownership of a project's vision and commit, visibly, to executing governance as part of that project's lifecycle. Cross-functional matrix relationships, temporary connections to legal, procurement, or ethics staff as needed, replace permanent central structures. And critically, information still has to flow upward. Not for approval, but so the enterprise can learn from what's working and what isn't at the local level.
To make this concrete, I mapped governance actions onto the project lifecycle most teams already follow. Five phases, each correlating to a standard project management stage:
Prepare (feasibility): Establish clear ownership of the AI project and a formal commitment to governance. Set up what I call a collaboration and governance hub, a single repository for every governance decision and the dialogue behind it. Without a place to record and retrieve that institutional memory, governance isn't really possible.
Orient (planning): Turn the broad vision into a detailed use case, covering the project's purpose, its values, and its compliance goals. Designate staff responsible for checking deliverables against that use case, and keep humans involved at every critical juncture: design review, development, testing, implementation. This phase also means identifying stakeholders and thinking through who could be affected and how you'll communicate with them.
Develop (execution): This is where deliverables become real, so governance has to confirm the data sources are fit for purpose, the infrastructure and security posture hold up, risks have been identified and mitigated, and testing goes beyond the standard checks to cover AI-specific concerns like bias, prompt engineering, and scenario testing for agentic applications.
Implement (monitoring and control): Define who owns ongoing operational governance once the system goes live, make sure staff are trained, communicate with stakeholders about what's changing, and confirm funding covers not just launch but ongoing maintenance.
Operate (closure and beyond): Governance doesn't end at go-live. This phase covers continuous monitoring, periodic auditing, evaluation of whether changes are needed, formal change control, reporting upward to existing enterprise functions like budget, IT, and compliance, and eventually, a structured plan for decommissioning the system when its time comes.
Across all five phases, I count 13 distinct roles that typically need to touch an AI project, from sponsorship and information security to records management and ethical screening. In a resource-constrained environment, you probably can't staff all of those separately. Melding roles or pulling in matrix support as needed is often the realistic path, even if it means giving up some separation of duties you'd prefer to have.
None of this is a substitute for judgment. If your organization has an absolute prohibition on AI use in a particular area, don't work around it. And if you're operating in a highly regulated environment, or your application touches health, safety, or individual rights, move carefully. The risk-based factors there can affect your legal posture in ways a project team can't control on its own.
And to be clear: there's no guarantee of success with any governance approach, including this one. What I'm confident of is that in the absence of a formal enterprise program, project-level governance gives you a responsible way to keep moving instead of standing still.
I first presented this model at the AI+IM Global Summit 2026, and the response told me it's hitting a real gap for a lot of organizations. I've since written it up in full detail in a white paper for AIIM, The Middle Path: Project Level Governance for Accountable AI, along with a companion checklist that walks project teams through each phase step by step. Both resources are now available to AIIM members. If you are not a member, you can learn more about membership.
If you're trying to figure out how to govern AI projects right now, without waiting for a program that may be years away, that's where I'd point you next.