Governance That Creates Speed: A 30-60-90 Day Design for AI

Coloured paths pass through transparent checkpoints toward an open horizon, representing governance that creates speed.

Governance often gets blamed for slow AI. In reality, vague governance slows teams down: it makes every project renegotiate data, approvals and risk from scratch. The price is not only time. It creates shadow solutions, late surprises and a climate where nobody knows which experiments are safely allowed.

Good governance does the opposite. It builds a safe default path. Teams know what they need to document, test and decide — and what they do not need to request again every time.

The problem is not control. It is ambiguity.

Many organisations have either a thin PDF of principles or an approval process that appears just before launch. Both create friction. Principles without an operating connection are ignored. Controls at the end cause expensive rework.

NIST’s Generative AI Profile treats risk management as recurring work: govern, map, measure and manage. The sequence matters. Governance does not sit outside the product. It gives the product team a shared language to assess data, behaviour, benefit and harm early.

Regulation makes this design mindset more relevant, too. The European Commission explains the EU AI Act through a risk-based approach and lists risk management, logging, documentation, human oversight, robustness and cybersecurity for certain high-risk systems. That is not a reason to treat every small helper as high risk. It is a reason to make the risk level of an initiative visible early.

Days 1–30: one intake and five non-negotiable questions

Do not start with a committee. Start with a short, continuous intake page. Every initiative answers the same five questions:

  1. Which result and process are in scope?
  2. Who owns the business decision and who owns the risk?
  3. Which data, systems and permissions are involved?
  4. What action may the system take — and what may it not take?
  5. How will we stop, correct or escalate when something goes wrong?

It sounds basic. That is why it works. A common intake replaces corridor decisions with inspectable assumptions. It also creates a useful inventory: not only “we have something with AI,” but “we know its purpose, owner, data space and action boundary.”

The time limit matters. A green, low-risk use case must not take weeks to enter. If it does, you have not built governance; you have built a bottleneck.

Days 31–60: three lanes and reusable evidence

The second month is about proportionality. Divide initiatives broadly into green, amber and red. Not as a substitute for legal advice, but as an operating language:

  • Green: approved data, no irreversible impact, tight user group. Standard tests and a fast release.
  • Amber: sensitive data, integrated systems or cross-functional use. A named owner, test cases, privacy and security checks, and a controlled rollout.
  • Red: material impact on people, money, access rights, security or regulated decisions. Formal approvals, stricter evaluation, logging, an incident plan and clear reversibility.

The accelerator is reuse. A safe connector, proven test set, data classification, rollback runbook or useful risk question should not have to be invented by ten different teams. Microsoft’s guidance for managing Copilot Studio projects likewise recommends controlled environments, lifecycle management, testing and monitoring. The tools may change. The pattern remains: guardrails belong on the path forward, not as a barrier at the end.

Days 61–90: make operations visible

An inventoried, approved agent can still change in production: new data sources, new use, new failure patterns, new cost. That is why observability does not belong in a later “phase two.”

Within 90 days, you should have at least four views:

  • Inventory: Which AI systems and agents exist, who owns them, and what may they do?
  • Operations: Usage, failures, latency, cost and unusual actions.
  • Impact: Which business and user signals are actually improving?
  • Risk: Which escalations, policy breaches, new data access patterns or recurring bad inputs have appeared?

Evaluation should not be reduced to “the model sounds good.” Current Microsoft Agent Framework documentation distinguishes quality, tool-use and safety evaluators. Across any platform, that translates into a simple discipline: test not only the answer, but selection, inputs, execution and behaviour under bad or conflicting information.

Treat governance as a product

The best governance feels like a good internal product: clear language, short paths, examples, templates and useful feedback. It does not make every team start from zero. It also creates data about the organisation itself: Where are standards missing? Which risks repeat? Which teams need better self-service?

In my public work on transformation, I return to the same point: governance, data architecture and leadership must meet if AI is to become a strategic capability. The question is not, “How do we control everything?” It is, “How do we make safe, responsible progress repeatable?”

The 90-day test

Ask a team with a green use case: Can it create a safe pilot in a few days without requesting an exception to the process? If the answer is yes, governance is creating speed. If not, do not begin by automating more. Find the unclear decision that still makes every piece of work wait.

Deutsche Ausgabe: Governance, die Tempo schafft: Ein 30-60-90-Tage-Plan für KI

Sources and framing

Continue: Browse all Weekly Field Notes.

Editorial note: This plan is a deliberate starting point for operating design. It does not replace legal, privacy or information-security advice.