AI governance in a company is not a compliance committee. It is the allocation of five responsibilities, sponsoring, framing, leading, building and spreading, to named people. As long as the subject belongs to everyone, it belongs to no one, and the first decision to make is neither a tool nor a budget.
This article draws on the webinar I hosted on 24 September 2026 about the roles and the organisation of artificial intelligence in companies. It covers who decides, who builds, who spreads it, what each body settles, and two operating models depending on your size. The public data quoted comes from the Responsible AI Observatory run by the Impact AI collective, surveying a representative sample of 1,000 French private-sector employees from 17 to 26 February 2026.
Why nobody owns generative AI by default
No department is naturally positioned on generative AI. That is not an oversight, it follows from what the tool touches. Executive management makes AI a priority, business teams make it useful, HR makes it durable, and IT makes it possible. None of the four covers the other three.
The figures describe the gap well. In the Impact AI survey of February 2026, only 10% of employees report that an AI charter or ethics committee exists in their company. At the same time, 61% use external consumer tools, against 19% who go through an internal AI. Usage is there, the framework is not.
Training on responsible use has reached 23% of employees, with 6% getting an in-depth programme. In other words, three employees out of four handle a tool whose rules nobody explained to them, in a company where nine times out of ten no rule has been written. The legal risk already exists, it is simply not visible yet.
Analytical AI and generative AI, two streams under one governance
The most common confusion, and the one that explains much of the fog, is treating AI as a single block. AI was there long before ChatGPT. It forecast, classified and detected, and it lived in the data team. Generative AI produces and transforms content, and it touches every employee. The two share neither the same owner, nor the same timescale, nor the same investment model.
| Analytical AI | Generative AI | |
|---|---|---|
| What it does | Forecast, classify, detect, recognise | Produce and transform content |
| Who uses it | A few experts, inside one precise process | Every employee |
| Who owns it | Data team, IT, research and development | Business teams, HR, transformation |
| Timescale | Projects of 6 to 18 months | Uses within weeks |
| Investment | Heavy, targeted, industrial | Licences, training and internal time |
The resulting recommendation is to separate the two streams clearly in the organisation, under one shared governance that carries the rules and compliance. Without that split, the analytical stream absorbs the generative one, because it is older, better funded and more legitimate technically. Business uses then wait for an arbitration from a team that thinks in twelve-month projects.
One concrete example makes it clear. At a home energy equipment company, a technician installs a unit, photographs the radiator, the electrical panel and the meter, and an inspector checks each photo before grading the anomalies. The generative route has a multimodal model reviewed by the inspector, owned by the business, with first results within weeks. The analytical route trains a custom vision model, owned by the data team, with thousands of photos to label and a six to eighteen-month project.
What organisational fog costs, month after month
Four symptoms show up in almost every company without a designated owner. None comes from a lack of tools, all come from a lack of owner.
- Shadow AI and the security risk. Teams work from personal accounts, sometimes with customer data. Nobody authorised it, nobody forbade it.
- Costs that drift. Prices and pricing models shift every quarter, and nothing is forecast or tracked. The invoice arrives before the return.
- Proofs of concept that go nowhere. The demo works, production never happens. Early enthusiasm becomes the sceptics' argument.
- Licences without usage. Subscriptions paid, usage analytics nobody looks at, duplicate tools. The budget is spent, the gain stays theoretical.
Ten proofs of concept running in parallel and none in production is a symptom of missing prioritisation, not of missing talent. I covered the underlying reasons for that failure in our analysis of companies that see no return on AI, and the prioritisation method in our AI audit guide. This article takes the next question, who owns what.
Five responsibilities to allocate before discussing job titles
An org chart cannot be copied, an allocation of responsibilities can. Five verbs are enough to describe what must be covered. A 150-person company covers them with two people, a mid-market company puts a team on it, but no organisation can skip one.
- Sponsor. Executive management, through one named leader rather than the whole executive committee. They carry the ambition, arbitrate the budget and settle priorities.
- Frame. The AI committee. It is a body, not a job. It sets authorised uses, the data allowed into a tool and the list of approved tools.
- Lead. The AI lead. This is the one role that must exist from day one. They hold the use-case portfolio, the roadmap and the indicators.
- Build. Technical leads on the business side and IT on the industrialisation side. The business prototypes, the technical team ships to production.
- Spread. AI champions, one relay per team. Without this layer, everything else stays a demo.

AI champion and technical lead, two roles that get confused constantly
The champion creates the demand, the technical lead builds the answer. Confusing them produces either enthusiasts asked to ship a tool, or technicians asked to evangelise. Both fail, and the conclusion drawn is that the network does not work.
| AI champion | Technical lead | |
|---|---|---|
| Other names | AI ambassador, AI relay | AI Builder, AI key user |
| Mission | Test, set the example, create appetite, surface friction | Define the need, build and maintain assistants and workflows |
| Profile | Appetite and credibility in their team, not technical | Tech-minded, low-code, understands the real process |
| Time to free up | 5 to 10%, compatible with the day job | 20 to 50%, sometimes full time |
| How many | 1 per 20 to 30 employees | 1 per department or major process |
The real transformation is not in the tools, it is in the roles that emerge. That is what I wrote in my post on the rise of the AI Builder role in March 2026. On the most technical end of that chain, the hybrid profile that installs things for good, between the business and the technology, carries a name borrowed from the software industry, and it has its own article, the Forward Deployed Engineer.
Two axes are enough to place each role, distance to the business and level of decision. The AI committee and the AI lead decide. Champions, technical leads, trainers and engineering profiles deliver. Mixing the two layers is the most frequent source of deadlock, because an arbitration then travels to someone who has no mandate to make it.

The AI committee, who sits on it, what it decides, how often
The AI committee is the body that makes arbitrations binding. Its composition is decided once and does not change. It seats executive management, who settles and unblocks, business departments, who bring the use cases, IT for access and integration, HR for skills, finance for cost per use, legal for the European regulation and data protection, and security for what leaves and what stays.
What it decides fits in six points, and those six points are not delegated.
- The use cases you test, the ones you industrialise and the ones you stop.
- The usage rules that apply to teams, in other words the AI charter.
- The approved tools and the data allowed into them.
- The budget and the quarter's priorities.
- The usage analytics, which give the real return on licences.
- The maturity assessment and the training plan that follows from it.
The rhythm fits in two to four hours a month, with an agenda and a record of decisions. This committee does not build, does not do technology watch and does not approve individual prompts. As soon as it starts doing one of the three, it stops deciding and becomes an information meeting.
One decision keeps coming back to that table, build or buy. I published my reading of it on LinkedIn, the build versus buy choice on AI solutions, and it comes down to one sentence. Buy when your process looks like everyone else's, build when it is strategic.

Two operating models, depending on your size
The same structure works at two scales. In a company of 100 to 500 people, no new headcount is needed. The AI lead is an existing manager whose time is officially freed in part, the committee meets one hour a month, one or two business leads build in low-code, and existing IT industrialises with outside support on the rare skills.
In a company of 500 to 5,000 people, the AI lead becomes a full-time cross-functional role, often titled director of AI transformation. The committee is formalised with legal, security, HR and finance. Each department has its technical lead, a training and change function carries the paths by job family, and champions are run by the AI lead on a regular ritual with a written mandate.

A third route exists when the role is needed but the profile is not available internally. A fractional AI lead runs the use-case portfolio, chairs the committee and activates the champions, on an engagement of a few months. It is the format we see working in organisations that want to start without waiting six months for a hire.
What two organisations actually put in place
Two examples from programmes we ran, presented without naming the companies involved. They describe two different entry points into the subject, through ambassadors on one side, through technical leads on the other.
A mutual insurer saw a widening gap between employees already comfortable with AI and others who had never touched it, with the risk of a two-speed company. It built a path for everyone, a positioning test, online training at two levels and a masterclass, plus a network of ambassadors trained across twelve sites. Around 3,000 employees were introduced to the subject and roughly fifteen ambassadors trained in six months. The main lesson is that ambassadors reveal themselves during the training, and that giving them a coaching posture matters as much as the technical content.
An international logistics company started from an old awareness campaign and an AI barely embedded in HR practice, in an environment restricted to a single approved tool. The programme combined a masterclass for around sixty people, then a two-day bootcamp for a dozen technical leads, each presenting a prototype to a management jury. The lesson lies in the closing device. A prototype presented to management turns a technical lead into a project owner, and the role only holds if it is recognised and valued.
Both programmes rest on a base of collective skill-building that we describe in our guide to AI literacy. Governance decides, literacy executes, and team training is what connects the two over time.
What the law already requires, and what it does not yet
Article 4 of the European AI regulation has applied since 2 February 2025. It requires providers and deployers alike to ensure a sufficient level of AI literacy among the people using these systems on their behalf, taking account of their knowledge and their context of use. The French data protection authority publishes the detailed timeline. Training teams is therefore no longer only a productivity gain, it is an obligation.
One claim circulates everywhere, however, and it is wrong. The CNIL is not yet the designated reference authority for applying the regulation in France. It is competent on prohibited practices, but the general designation awaits adoption of the EU law adaptation bill, passed by the Senate in February 2026 and not yet adopted by the National Assembly at the date of this article. Around fifteen sector authorities will complete the framework depending on the domain.
The real short-term legal risk sits elsewhere, and it is specifically French. Article L.2312-8 of the labour code requires informing and consulting the works council before introducing new technologies that change working conditions. The Créteil court suspended, in July 2025, the use of AI tools at a professional publishing company until the consultation was complete. The tools involved did rewriting, transcription and summarisation, exactly the uses business departments deploy today.
Four mistakes that come back in every organisation
None of these four mistakes is a budget problem. All are definition problems, and all can be fixed in one meeting.
- Management that does not practise. An executive committee far from the subject, not using the tools itself, does not really back it. Train management first, and have them write their own ambition.
- Everything in one basket. A single role for product AI, analytical AI and generative AI, when the timescales have nothing in common. Separate the streams under one shared governance.
- A committee, but no lead. The subject gets discussed, nobody answers for it. Name the AI lead, even part-time, with a one-page mandate.
- Champions with no time. Appointed in a meeting, with not one hour taken off their workload. Three months later the network stops meeting. No mandate without freed time and a line in the annual objectives.
The French state is pushing the subject in parallel, with a record that illustrates exactly this point. The progress report on the Osez l'IA plan published on 3 September 2026 by the Directorate General for Enterprise and Bpifrance reports more than 35,000 companies reached in a year. Over the same period, 70 diagnostics were started. Awareness organises nothing.
Where should you start your AI governance?
With a single decision, and it can be made this week. Name an AI lead, even part-time, even on a quarter of their time, and write their mandate on one page. Without that name, the committee you set up afterwards will produce minutes rather than arbitrations.
The next three moves follow naturally. Convene the committee once to set the approved tools and the data allowed into them. Start the works council consultation before any wide rollout. Then appoint one relay per team, with time genuinely taken off their workload.
Tandem supports more than 50 companies on designing and deploying their AI projects. When the question is which use case to start with, it belongs in an audit engagement. When it is about building team skills and installing the roles, it belongs in an AI literacy programme. In both cases, the first session answers a single question, who owns the subject here.



