Companies adopting artificial intelligence need to identify who has the power to halt a system that causes harm, rather than relying only on dashboards, policies and review processes, according to Adobe’s director of data and AI governance.
Joseph Wallace, who founded Adobe’s enterprise AI and data governance programme, said the central weakness in many corporate AI governance models is not a lack of technical tools but an unclear chain of authority when something goes wrong.
Writing about lessons from Adobe’s approach, Wallace said many large companies now maintain model registries, data classification systems, monitoring dashboards, risk councils and compliance policies. Those mechanisms can help organisations understand what systems they are running and how they may behave, he said, but they do not by themselves answer the operational question of who can stop a model or AI agent from continuing to operate.
The issue is becoming more pressing as companies deploy AI across customer service, hiring, content moderation, pricing, fraud detection and other business functions. Wallace said large enterprises may now be running hundreds of AI systems, including tools introduced quickly by teams trying to improve efficiency, sometimes before governance arrangements have been fully established.
His warning comes as businesses face rising regulatory and public scrutiny over AI. The European Union’s AI Act is now in force and places obligations on companies to demonstrate governance, accountability and documented decision-making for certain AI systems. Wallace said regulators are unlikely to be satisfied by the existence of a risk register alone if a company cannot show who made a consequential decision about an AI system and why.
Wallace argued that the governance industry has focused heavily on visibility tools, such as model inventories and data lineage systems, while paying less attention to whether those tools lead to action. A registry can show which AI systems exist, a framework can categorise risk and a dashboard can flag abnormal behaviour, but none of those necessarily gives a person the authority to intervene.
He compared the distinction to the difference between a fire alarm and a fire department: an alarm may identify that there is a problem, but it does not put out the fire. In the same way, he said, AI governance needs a mechanism that allows a responsible person or body to act decisively when an AI system creates unacceptable risk.
According to Wallace, many roles commonly associated with AI oversight, including ethics officers, responsible AI teams and data governance councils, are important but often advisory. They may be able to identify concerns, recommend action and escalate issues, but the final authority to suspend or block a system can remain with teams whose primary objectives are product delivery, commercial performance or speed to market.
He said this creates a structural conflict rather than a criticism of individual managers. If the person responsible for approving a deployment reports through the same chain as the team that benefits from launching it, governance warnings may be easier to treat as obstacles rather than binding decisions.
Adobe’s response, Wallace said, has been to create a federated governance model with named owners for each AI system and a central steering committee with escalation authority. He said the governance function reports into the company’s trust and security organisation rather than product teams, creating a reporting line independent from those building and shipping AI products.
That separation is intended to ensure that the person or group able to say no to an AI deployment does not report to the person most directly incentivised to approve it. Wallace said governance needs both proximity to development teams and independence from them, so that concerns can be identified early but decisions are not overridden by delivery pressures.
He said every AI governance programme should be able to answer three basic questions: who has the authority to stop a model, whether that person understands it is their responsibility, and whether they have enough organisational standing to exercise that authority when it conflicts with another team’s plans.
If a company cannot answer those questions, Wallace argued, it has paperwork rather than an effective governance programme. He said organisations preparing for the next phase of AI regulation and scrutiny will need to build human accountability structures beneath the technical infrastructure they have already put in place.
The argument reflects a broader shift in the corporate AI debate. Early governance efforts often focused on cataloguing systems and assessing technical risks, but regulators and internal risk teams are increasingly concerned with evidence of accountability: who knew about an issue, who had authority to act, and whether concerns were escalated to the right level.
Wallace said the answer is not to slow AI adoption, but to treat organisational design as seriously as the technology itself. In his view, companies that are best prepared will be those that appoint accountable AI governance leaders, give them real authority, and create clear escalation routes to senior leadership.
He said the dividing line between meaningful governance and what he described as governance “theatre” is whether someone in the organisation can say no to an AI system and have the authority to make that decision stick.