A practical implication is that AI governance cannot remain a policy artifact. If urgent deployments bypass review, leaders create a credibility gap that will matter more than the model choice itself. CIOs should treat AI oversight as a living operating process with shorter review cycles than conventional enterprise risk, explicit decision rights, and documented exceptions. The strongest proof of maturity is often visible restraint: projects delayed, redesigned, or rejected because the risk-reward case was weak.
This also has an organizational change dimension. Employees and business leaders are reading the same alarming headlines as boards, so silence invites rumor and overreaction. Showing where AI was not used, where human oversight remained in place, and how concerns were escalated can reduce fear while reinforcing that augmentation is not automatic replacement.
Useful next questions for leadership:
- Which AI decisions require business, risk, legal, and architecture sign-off, and who can halt deployment?
- What evidence can we show the board that governance changed an outcome rather than merely documented it?
- How often are AI risk assumptions revalidated, and what events trigger reassessment?
- Where have we explicitly said “no” to AI, and are we communicating why?
After years of exciting new launches and rollouts, AI’s biggest names are now publicly arguing over whether the technology is moving too fast.
Anthropic CEO Dario Amodei has called for slowing frontier AI development , while OpenAI has backed stronger safety measures. Nvidia CEO Jensen Huang and Meta CEO Mark Zuckerberg have separately pushed back on calls for a coordinated slowdown. The disagreement has revived some of the most alarming warnings about AI, including concerns that increasingly capable systems could eventually become difficult for humans to control — and even bring about the end of humanity.
Those warnings have spread far beyond the companies developing frontier models; employees, boards and customers are consuming the same headlines. Even though the AI being deployed inside most organizations is far simpler in nature, used for tasks such as summarizing documents, writing code or automating workflows, the fear is still real.
That duality creates a difficult question for CIOs: How do you give people confidence in the organization’s AI strategy when even the technology’s leading developers disagree about the risks involved?
Make uncertainty manageable
The answer doesn’t require pretending those uncertainties don’t exist. For CIOs, building confidence in AI means giving employees, members of the C-suite and boards evidence that the organization can make responsible decisions even when the technology itself remains uncertain.
“A CIO can promise process: governed deployment, human oversight, continuous monitoring and transparency about what we know and don’t know,” said David Linthicum, founder of Linthicum Research and former chief cloud strategy officer at Deloitte. “What they shouldn’t promise is outcomes, that AI will never err, never be misused or that its future behavior is predictable.”
There is an important distinction between confidence in AI and confidence in the organization using it. A CIO cannot credibly promise that an AI system will never behave unexpectedly — and they shouldn’t. Trying to offer that kind of certainty can make the organization more vulnerable when something does go wrong.
“Boards don’t need perfection; they need to know risks are identified, owned and managed,” Linthicum said. “Promise diligence, guardrails and accountability — never certainty.”
That approach requires showing how the organization will respond when its assumptions change. Niel Nickolaisen , technology leader advisor at IT solutions provider VLCM and a former CIO, said companies should expect to reassess their AI risks more frequently than they might traditional enterprise risks. An enterprise risk management assessment could be conducted annually, while an enterprise AI assessment might require an every-other-month or quarterly basis.
That more frequent assessment process gives CIOs something concrete to demonstrate. Rather than telling a board that the organization has a responsible AI strategy, they can show how that strategy has evolved as models, use cases and risks have changed.
“AI is changing quickly, and so are the related technologies and practices,” Nickolaisen said. “The organization gains confidence when it stays on top of these changes and has a solid process for assessing the changes and their impact on the organization.”
The same principle applies when something goes wrong. Linthicum said organizations should conduct honest postmortems and be transparent about what they learned.
“Say, ‘Here’s how we’ll detect and respond to surprises,’ rather than, ‘There won’t be surprises,'” he said.
Show responsible AI in action
Policies and frameworks matter, but they are difficult to use as evidence of responsible behavior if nobody can show how they affect actual decisions.
This has been a real concern in AI deployments. A recent EY survey of 202 U.S. senior AI decision-makers at companies with at least $1 billion in annual revenue found that “about half (47%) of respondents say their organization has previously not applied its AI governance process for urgent deployments, despite 98% having formal AI governance policies in place.”
The figures point to a credibility gap: Having a policy does not necessarily demonstrate that an organization will follow it when circumstances become difficult.
Kanti Prabha, president and co-founder of AI contract management platform Sirion, said CIOs should instead be prepared to show the decisions their responsible AI strategy has produced.
“Responsible AI has to show up in each decision you make, and those decisions should be explainable,” she said.
That could mean documenting which AI use cases were approved, which were modified after review and which were rejected. It could also mean demonstrating where human oversight was added, where sensitive data was kept out of a system or where a deployment was slowed to address a risk.
Tracking how decisions evolved over time is another way to demonstrate effective oversight. Linthicum recommended keeping concrete evidence of AI governance, including risk assessments, testing results, incident records and vendor due diligence, to support broader claims of AI responsibility.
Make ‘no’ visible
Several experts also advocated tracking AI projects that didn’t make it to deployment, arguing that this can be one of the clearest signals that an AI strategy is being managed deliberately.
“Trust is built on visible restraint,” Linthicum said.
He argued that CIOs should be willing to highlight AI deployments that were pulled back when they failed to meet the organization’s standards: “The ‘no’ stories are your most valuable communications assets.”
His examples included an internal facial recognition proposal that was rejected over privacy concerns, or a customer-facing bot that was pulled after its quality deteriorated. Those decisions give a board member — or an employee — a way to see that the organization isn’t committed to deploying AI simply because the technology is available.
Prabha made a similar point from the perspective of deciding where AI belongs in the first place. If an existing technology already solves a problem effectively, she said, adding AI can introduce unnecessary complexity and risk. Responsible AI therefore includes being able to explain where the company deliberately chose not to use it.
That can be particularly important for employees watching AI move into their work. A strategy that consists entirely of approved deployments can look like an inevitable expansion of AI, one that may eventually subsume human roles altogether. A strategy that includes documented decisions not to deploy AI can reassure valued staff of their place in the company.
Through restraint, the message becomes that AI has to earn its place in a workflow.
Make disagreement useful
Organizational confidence also depends on what happens when people inside the organization disagree about an AI decision.
Some disagreement is inevitable: Engineers may identify a technical risk that business leaders consider manageable; employees may question how a system affects their work; executives may see an opportunity that others believe carries too much risk.
Linthicum said the organization should make it possible for anyone involved with an AI system to raise those concerns, not just executives responsible for the technology.
He recommended a cross-functional AI review group with authority to pause deployments. Concerns should be acknowledged quickly, evaluated against documented criteria and answered in writing, including when the eventual response is that the organization disagrees.
“Disagreement handled visibly and respectfully is a feature; suppressed, it leaks out as headlines,” Linthicum said.
That does not mean every objection should have veto power. Nickolaisen advised that AI decisions need clear ownership, with an established process for resolving disagreements. He said he views AI safety as an extension of enterprise risk management, meaning the organization needs to assess competing concerns against its broader risk tolerance before making a decision.
The most effective approaches will likely blend both ideas. Employees need to know that raising a concern will result in genuine consideration, while the organization needs to have clarity on who ultimately decides what happens next.
Prabha’s emphasis on explainable decisions applies here, too: A decision does not necessarily become more credible because everyone agrees with it; it becomes more credible when the organization can explain how it reached the decision and what evidence informed it.
Confidence comes from demonstrated judgment
Despite much of the current conversation revolving around theoretical future AI applications, there will be times when an alarming AI headline proves relevant to the enterprise.
Nickolaisen said CIOs should be able to explain whether a particular development applies to their environment, outline what the organization has done to prevent the same issue and detail what it learned from the situation. If the headline doesn’t apply, the CIO should be able to explain why.
The AI industry will continue to argue about how quickly the technology should advance, and how much risk is acceptable. CIOs cannot settle those debates for their organizations, much less for the companies building frontier models. But they can demonstrate how their own organizations make decisions in the face of that uncertainty.
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

