Remobi Articles

AI Governance Isn't Red Tape

Written by Lauren Hargreaves | Aug 25, 2026, 7:29:28 AM

AI governance is the set of policies, controls and accountability that decide how an organisation builds and deploys AI responsibly. Done early, it doesn't slow engineering teams down. Quite the opposite.

Build it into the process from the start and it helps teams move faster, make better decisions and catch risks before they become expensive problems.

At our latest Remobi Fireside, Lauren Hargreaves spoke with Dawn McAra-Hunter, founder of Fìor and member of AI100UK, about what responsible AI looks like once you move past policies and put it into practice.

Here are five lessons for technology leaders building and deploying AI.

Missed the session?

Watch the full Fireside Chat with Dawn here

 

 

 

1. Does AI governance really slow you down?

No. "Move fast and break things" has shaped technology for years, and Dawn argues that mindset has made checking your work feel like a threat to progress, or even "fundamentally detrimental to the venture capitalist model."

But moving quickly and governing responsibly aren't opposites.

Governance becomes slow when teams leave it until the end. If you've built the model, prepared for deployment and only then ask whether it is compliant or could cause harm, fixing the problem means going backwards. Do that thinking upfront and you keep moving.

 

2. When should AI governance start?

At ideation, before anyone writes code.

What are you building? Why? What regulation applies? Where could it cause harm? What controls will you need?

Answer those questions early and your engineers know the boundaries they're working within. You can identify risks, complete impact assessments and design the right guardrails into the system rather than retrofit them later.

It's about preparation, not slowing development down. You don't need to choose between responsible AI and shipping quickly. You need to do the thinking early enough to achieve both.

 

​​3. Who's accountable when AI gets something wrong?

When an AI system gets something wrong, responsibility doesn't disappear into the model.

The Air Canada chatbot case made that clear. Its chatbot gave a customer incorrect information about the airline's bereavement fare policy. Air Canada argued it should not be responsible for what the chatbot said. The tribunal disagreed and held the airline liable.

You remain accountable for the systems you put in front of customers, employees and users. Accountability can sit across developers, providers and organisations, but inside the business someone needs to own it.

Dawn recommends a named person with enough authority to take responsibility. In many technology organisations, that is the CTO.

"A SharePoint folder full of policies that nobody reads" is not governance.

 

4. Is legal compliance enough?

No. The EU AI Act, GDPR and other regulation give organisations requirements to meet. Dawn describes legal compliance as the "absolute bare minimum."

Responsible AI isn't achieved by writing a policy. Governance only works when it changes what people actually do: how teams make decisions, assess risk, use data, build systems and respond when something goes wrong.

The law also can't anticipate every potential harm from a fast-moving technology. Compliant AI and responsible AI aren't automatically the same thing. Technology leaders need to know whether their controls work in practice, not simply whether they exist.

 

5. Start with the problem, or start with the AI?

Start with the problem. One of the easiest mistakes happens before governance even enters the conversation.

Organisations ask, "How do we get AI in?" Dawn's question is better: "What problem are you trying to solve?"

Not every problem needs AI. And even where AI is the right answer, teams need to understand the data underneath it. Poor data governance doesn't disappear because you've put an AI layer on top. Where did the data come from? Do you have permission to use it? Is the quality good enough? Is it right for the system you're building?

Get the data right first, or the AI on top of it inherits every problem underneath.

What should technology leaders do this week?

You don't need a perfect governance framework to make progress. Dawn recommends starting with minimum viable governance.

Ask one question first: are we actively mitigating harm?

Then make sure someone can answer for the AI you're already building or using. Name the person accountable. Establish basic policies. Assess potential impacts. Get your data governance in order. And make those checks part of development rather than something that happens before launch.

Small foundations now are far easier to build on than governance retrofitted after something goes wrong.

 

AI governance FAQs

Does the UK have a specific AI governance law?
Not a single one. The UK takes a regulator-led approach, so AI is governed through existing law such as GDPR and the Data Protection Act, with the Equality Act covering discrimination, plus guidance from bodies like the ICO and sector regulators. If you operate in the EU, the EU AI Act also applies.

Who is accountable when AI is bought rather than built?
The organisation deploying the system is accountable for the harm it causes, even when a third party built it. The detail depends on the procurement terms and the type of harm, and the deployer may be able to pursue the provider separately, but you cannot outsource accountability to the vendor.

What is minimum viable governance?
A practical baseline you can put in place now: a named person accountable for AI, basic policies for AI use, model risk and incident response, and the right impact assessments (data protection, equality and fundamental rights if you operate in the EU). It's the floor to build on, not the finish line.

 

 

Watch the full Fireside Chat

These are five takeaways from a much wider conversation between Lauren and Dawn on AI ethics, governance and accountability.

Watch the full Fireside Chat recording and follow Remobi on LinkedIn to join us for the next one.

 

 

About the guest

Dawn McAra-Hunter is founder of Fìor, an AI ethics and governance consultancy focused on harm reduction, and a member of AI100UK. A former human rights lawyer with ten years in tech, she previously helped deliver Scotland's national AI strategy and led its national AI literacy programme.