Dr. Ali Alkhafaji is the CEO of APPLY, a global Agentic Customer Experience partner helping enterprise brands transform through agentic AI.
Nearly every conversation I’ve had about AI failure inside an enterprise boardroom eventually arrives at the same root cause. It’s rarely the model that’s to blame. It’s almost never the technology, either. It’s a matter of governance, and it’s consistently the one thing organizations leave until last.
There’s a pattern, and it’s problematic, to say the least. An organization deploys an AI agent into a customer-facing workflow. The pilot goes well. Confidence builds. Scope expands. And somewhere within that expansion, the question of who is actually accountable for what the system produces gets dropped. Not maliciously, I should add. It’s just because nobody owned it from the start, and momentum carried the deployment past the point where anyone stopped to ask.
I think about this through a concept engineers call normalization of deviance: the process by which small, reasonable-seeming compromises get accepted one at a time until an organization is operating with a level of risk that would have been unthinkable at the outset. It is the same dynamic that contributed to the Challenger disaster. No single decision looked unreasonable in isolation. The danger built cumulatively until a catastrophic failure made the accumulated risk visible all at once.
AI governance is following the exact same shape, and it rarely announces itself. Take a retailer running a personalization engine, for example. In its first quarter, the system recommends products based on browsing history. Reasonable. By the second quarter, it’s factoring in purchase timing and frequency. Still reasonable, on its own. By the third, it has started inferring things no one explicitly authorized it to infer, like a change in a customer’s life stage, and adjusting messaging accordingly. No one made that decision. No one signed off on it. It just accumulated, one defensible step at a time, until the system was doing something that would make the company’s own leadership uncomfortable if a customer asked them to explain it out loud.
That is the shape of the risk. Not a single bad call, but a hundred small ones that nobody was assigned to catch.
The organizations that get this right share one structural habit I think matters more than any policy document: They assign a named human to own every AI output before it reaches a customer or client. Not a committee. Not a department. A person, a caretaker, if you will.
That single design choice forces a level of accountability no written policy can replicate, because policies do not get blamed when something goes wrong. People do, and people who know they will be accountable behave differently.
This matters more now than it did even a year ago. We are no longer talking about a chatbot answering basic questions. We are talking about agentic systems that reason, plan and act across entire customer journeys, often without a human reviewing each decision in real time. The surface area for ungoverned risk has expanded dramatically, and most governance structures have not kept pace.
Three questions I would put to any leadership team, regardless of how far along their AI deployment is:
1. Can you name the person accountable for every AI-generated output your customers or clients see? If the honest answer is a process rather than a person, that gap is worth closing immediately.
2. When did you last trace a small compromise back to its origin and ask whether it would still look reasonable if explained to a customer directly? Most organizations have never done this, and it is one of the fastest ways to surface normalization of deviance before it compounds.
3. Does your organization treat governance as a constraint on innovation, or as the foundation that makes innovation trustworthy? Teams that see governance as friction route around it. Teams that see it as what earns them the right to move fast build it in from the start.
The Challenger disaster wasn’t caused by one bad decision. It was caused by a long series of small, defensible ones that nobody stepped back to add up. AI governance will fail the same way unless someone is standing in the way of that accumulation, with their name on it.
That’s the whole model. Not a bigger framework. Not another layer of review. A name next to every output, and a person willing to be accountable for it.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?











