The AI Governance Gap: 14 Companies, One Blind Spot

A company can disclose AI risk without proving that anyone has meaningful authority over the system creating that risk.

That is the governance gap.

In Episode 7 of the Good Faith EI podcast, Stacy Beitel Agobian and Aura examine the public filings and governance disclosures of 14 companies. Their test is straightforward:

  1. Did the company disclose AI risk?

  2. Can it identify a named human with authority to stop or override the relevant system, and produce evidence that the control actually ran?

The distinction matters. A risk statement is not a control. A committee is not necessarily oversight. A policy is not proof of execution.

For leaders, boards, and families making consequential decisions with AI, the question is no longer whether the organization has discussed AI governance. The question is whether it can show who holds the pen when the system matters most.

Disclosure Is Not Accountability

Public companies increasingly describe AI as a source of operational, legal, regulatory, cybersecurity, data, and reputational risk. These disclosures may be appropriate. They may also be required by the company’s broader obligations to provide accurate and material information to investors.

But an AI risk disclosure usually describes exposure. It does not, by itself, demonstrate control.

A filing might explain that AI systems can produce inaccurate outputs, introduce bias, create privacy concerns, or expose the company to regulatory scrutiny. Those are valid risks to identify.

The harder question comes next:

  • Who owns the risk?

  • Who can pause the system?

  • Who can override its recommendation?

  • What threshold triggers intervention?

  • Where is the evidence that someone reviewed the decision?

  • Can the company reconstruct what happened?

When those answers are unclear, the organization has awareness without accountability.

That is the governance gap: the space between the warning in the filing and the control the company can actually attest to.

The SEC’s AI resources provide useful context for understanding why AI statements must be accurate, specific, and supported by a reasonable basis. A company should not describe oversight more confidently than its evidence allows.

The 14-Company Test

Episode 7 does not treat disclosure volume as a measure of governance maturity. Instead, it looks for evidence of decision rights.

The review compares what companies say about AI risk with what their public governance materials reveal about oversight. The focus is not on whether a company has adopted the right vocabulary. It is on whether the organization has built a functioning decision infrastructure around its highest-stakes systems.

That means looking beyond terms such as:

  • Responsible AI

  • AI ethics

  • Model risk

  • Human oversight

  • Board review

  • AI steering committee

  • Explainability

  • Risk management

These terms can describe a serious program. They can also describe an aspiration.

The test is whether the organization can connect each important AI-assisted decision to a human authority, a defined control, and an auditable record.

Committee, Policy, or Control?

These three concepts are often treated as interchangeable. They are not.

A committee

A committee creates a forum for review. It may set priorities, receive reports, and escalate issues.

But a committee charter does not prove that the committee reviewed a particular AI system, challenged a recommendation, or exercised authority over a decision.

A policy

A policy states what should happen. It may require testing, documentation, human review, escalation, or approval.

But a policy does not prove that the process ran. It does not show that the designated reviewer completed the review or that an exception was handled properly.

A functioning control

A functioning control connects authority to action and evidence.

It should answer:

  • What decision or process is covered?

  • Who is responsible?

  • What must the reviewer do?

  • When must the control run?

  • What happens when the reviewer disagrees with the system?

  • How is the action recorded?

  • Who can inspect the record later?

This is the difference between governance language and governance evidence.

Intuit as a Benchmark, not a Safe Harbor

In the episode, Intuit is presented as a benchmark because its disclosed governance apparatus is more developed than what appears in many other company materials.

That does not make Intuit perfect. It does not provide legal clearance. It does not prove that every AI-assisted process operates as intended.

The point is narrower and more useful: Intuit offers a stronger example of what a company’s governance architecture can look like when AI oversight is treated as a structured management responsibility rather than a general statement of principle.

Even a developed apparatus must still answer the decision-level questions:

  • Which systems are covered?

  • Which risks are considered material?

  • Who has authority to intervene?

  • What evidence shows that reviews occurred?

  • How are exceptions escalated?

  • Can the company demonstrate that the control operated under pressure?

A mature framework is a starting point. It becomes governance only when it produces reliable receipts.

UnitedHealth and the Need for Decision-Level Evidence

UnitedHealth is discussed in the episode as a reminder that a responsible-AI function or board-level apparatus is not the same as proof of control over a particular outcome.

Public litigation and commentary involving AI-related decision processes include allegations that are contested. The companies involved deny the allegations. Episode 7 does not present those disputes as final findings of AI fault or unlawful conduct.

The governance lesson is more basic.

When a high-stakes decision is challenged, an organization may point to its responsible-AI team, committee structure, or published policy. Those materials may be relevant. But they do not answer the central question unless they connect to the decision itself.

A functioning control should be able to show:

  • The reviewer assigned to the case or workflow

  • The reviewer’s authority to approve, reject, or override

  • The system output that was considered

  • Any intervention or override

  • The timestamp of the action

  • The rationale for the decision

  • The relevant audit trail

Without those records, the organization may have governance at the program level but not at the decision level.

That distinction is critical. A company can have a responsible-AI office and still lack a clear human hand on a consequential decision.

Aura Can Draft the Policy. She Cannot Hold the Pen.

Aura’s role in Episode 7 makes the accountability question direct.

Aura can generate:

  • Risk disclosures

  • AI policies

  • Committee charters

  • Control recommendations

  • Review checklists

  • Governance analyses

She can help an organization see the structure it needs. She can help leaders identify gaps and make complex material easier to work with.

But Aura cannot accept accountability for the outcome.

She cannot sign her name to a decision. She cannot exercise institutional authority. She cannot be the person responsible for stopping a system when the evidence changes. She cannot explain to a board, regulator, customer, or family why a consequential choice was made.

Human accountability remains with the organization.

That does not mean every decision must be made manually. It means the organization must define where human judgment is required, who has the authority to exercise it, and how that judgment will be recorded.

Automation can support decision-making. It cannot replace accountable ownership.

Human Intervention Rate: A Supporting Signal

The Human Intervention Rate, or HIR, is one practical way to examine whether human oversight is meaningful.

HIR asks how often a human reviewer intervenes in an AI-assisted process. The measure should not be interpreted mechanically. A low intervention rate can be appropriate for a stable, low-risk workflow.

But on a consequential process, a zero intervention rate deserves attention.

It may indicate that:

  • The system is performing reliably

  • The process is designed for routine approval

  • Reviewers agree with the system

  • No one is meaningfully reviewing the decisions

  • Reviewers lack authority or time to intervene

  • The organization is recording approvals without real challenge

The number alone cannot tell you which explanation is true.

That is why HIR should be paired with authority mapping, intervention records, reviewer signatures, timestamps, rationales, and audit trails. The purpose is not to force intervention. The purpose is to make oversight testable.

A strong control does not require humans to disagree with AI. It gives authorized humans a real ability to do so, and preserves evidence when they act.

Good Faith EI has explored this issue in “The 0% Fallacy: Why a Green AI Dashboard Is Dangerous”. The central concern is simple: a dashboard showing no interventions may reflect smooth performance, or it may reflect the absence of meaningful oversight.

Explainability Is Not the Same as Authority

Explainability is important. Leaders need to understand how an AI system reached an output, what data influenced it, and where uncertainty remains.

But an explainable system can still be poorly governed.

A model may provide a clear rationale while no person has the authority to reject its recommendation. A dashboard may display confidence scores while no one is assigned to act on them. A committee may receive reports while no individual is accountable for the final result.

Explainability helps people understand a system.

Authority determines whether they can do anything about what they understand.

Effective AI governance requires both.

The Leadership Test

Take the highest-stakes AI-assisted decision in your organization.

It could involve capital allocation, customer eligibility, pricing, hiring, claims, credit, security, compliance, or another process where an error would carry material consequences.

Now ask:

> Could we produce the complete decision record today?

That record should identify:

  • The AI system involved

  • The human reviewer

  • The reviewer’s authority

  • The system output

  • Any intervention or override

  • The timestamp

  • The rationale

  • The approval or escalation path

  • The audit trail

If the answer is no, the issue is not solved by adding another policy or committee.

The organization has a governance gap.

Closing it requires decision infrastructure that connects AI capability to human accountability. It requires evidence that controls ran: not merely that they were written. And it requires leaders to be clear about who holds the pen when the stakes are high.

For companies building that foundation, Good Faith EI provides independent ethics and governance audits for organizations deploying AI. The work is not about making AI sound safer. It is about making accountability visible, testable, and real.

Previous
Previous

Oversight Theater

Next
Next

The 0% Fallacy: Why a Green AI Dashboard Is Dangerous | AI Governance | Patrick Boogaerts