Most businesses take a step too late
When companies adopt AI, they almost always ask first: What do we use AI for, and how much control do we need? However, both questions presuppose something that usually remains unspoken: according to which principles this company makes decisions, uses data, distributes responsibility and exercises power. Without a conscious response, any AI strategy remains arbitrary and any control unfounded.
An example makes the difference visible
Take a company that wants to introduce an AI application pre-selection tool. The strategic question is: Is it worth it? The control question is as follows: What tests, what documentation, what approval do we need?
Both questions presuppose that it has already been clarified whether an AI in this company can even participate in deciding who is invited, or whether it can only work while a person makes the actual decision. This clarification concerns how the company understands responsibility. In the best case, the answer has long existed, mostly spread over corporate culture, leadership models and informal agreements, but rarely recorded as an explicit decision-making framework.
Principles must be concrete
Many companies confuse this level of principles with a general set of values, such as fairness, transparency, responsibility, which is well-intentioned but in practice remains too abstract to support a concrete decision.
Effective principles are business-specific and answer very specific questions:
What purpose must AI serve in this company in order to justify its use?
Which decisions remain fundamentally humanly responsible, regardless of how well a system works?
Which data may be used for what and which expressly not?
What effects on customers, employees or third parties are unacceptable, even if they would be economically attractive?
What needs to be made transparent, and to whom?
Who is responsible if something goes wrong, and how does the company remain able to act?
These questions need a conscious entrepreneurial decision, preferably before the pressure is created by a concrete project.
How this affects strategy and control
Once these principles are explicitly formulated, everything that follows changes. The AI strategy is then derived from what the company has already decided on, rather than coming from the technological potential alone. Controls ? Tests, documentation, releases, monitoring ? become the logical consequence of an already clarified principle.
In the application example from above, a company that has established human ultimate responsibility as a principle would not even consider an autonomously decisive system. It opts for a supporting tool from the outset. The subsequent checks then only concern the question of how well this support actually works.
The difference is in the order
In normal practice, governance is subsequently built around a strategy that has already been adopted. This order makes governance an expression of what a company wants to be anyway.
conclusion
AI governance begins with the principles by which an organization delegates decisions, uses data, assigns responsibility, and holds accountability once AI becomes part of its processes. Strategy and control follow ? not the other way around.
This is exactly where we at 2fink start, for example in the governance quick check as a quick start or in the AI & digital governance lab, when it comes to the in-depth work on concrete principles and use cases.