The seat
nobody is filling
One governance model asks whether AI is safe. Another asks what it costs. Neither asks whether the workflow was worth automating.
01The first model governs risk
The compliance-led committee is now a well-documented reference design. OneTrust's 2026 roadmap for launching an AI governance committee in ninety days is a clear example, and the pattern shows up across the category.
Membership: executive council, AI programme lead, IT governance, risk governance, privacy and compliance, information security, procurement, data stewards. Workflow: intake, risk tiering, review, approval, monitoring. Metrics: time to approval, escalation count, documentation quality.
That structure answers a specific set of questions. Is this legal. Is this safe. Is this documented. Is this defensible if a regulator asks.
Those are the right questions, and under the EU AI Act and the emerging state regimes they are mandatory ones. A compliance-led committee is a coherent thing for a governance software vendor to describe, and nothing here argues for governing risk less.
But there is no CX leader in that room, and the structure has a specific blind spot. It has a well-defined response when a use case is dangerous, non-compliant, or poorly documented. It has none when a use case is compliant, well documented, safely deployed, and commercially pointless. That case trips no gate, raises no escalation, and moves from intake to approval quickly, which registers on the dashboard as a success.
MIT's Project NANDA research puts enterprise generative AI pilots delivering no measurable P&L impact at 95%. The attribution matters more than the number: the failures were driven by approach, not model capability. Most would have passed every gate in that workflow, because the workflow contains no gate they could fail.
02The second model governs cost
The more interesting development is that a second governance model has arrived, and this one does ask about value.
McKinsey's July 2026 Quarterly article on agentic economics is the clearest statement of it. The argument is that enterprises are experiencing sticker shock on AI agents despite collapsing token prices, and that the answer is not token cost reduction. They quote Pay-i's CEO on the point: tokens are the bill, not the value. Their CEO agenda is explicit that the job is to design the operating model to maximise value rather than optimise token usage.
Several of their imperatives land close to what this commentary would otherwise be arguing for. The unit of governance is the completed business outcome, not the token or the model call. No autonomous system should operate without a defined mandate, budget, and stopping rule. The "who owns the capability" question has to be answered explicitly, because it does not sit cleanly inside any existing mandate. They argue AI governance is becoming a basis of competition in its own right.
That is a real advance on the compliance model, and it is worth saying so rather than pretending the ground is empty.
But look at what is actually being governed.
Context management. Model routing. Workload placement. Insourcing versus outsourcing. Tool architecture. Cost per outcome, return on intelligence, the productivity of machine work against human work. The named executive owners are the CIO, the CTO, and the CFO.
Every imperative on that list governs the efficiency of the machine. Is the right model running this task. Is the context bloated. Is the workload in the right place. Is the reasoning spend proportionate to the difficulty.
Those are good questions, and most enterprises cannot answer them. But every one of them presupposes that the work being done is work worth doing.
03The question between them
Compliance governance asks whether this is safe to run.
Cost governance asks whether this is efficient to run.
Neither asks whether it should be running at all.
An agentic workflow can be correctly risk-tiered, fully documented, routed to the cheapest adequate model, running at an excellent cost per outcome, and sitting on top of a process that was broken before anyone automated it. The compliance committee approves it. The economics discipline prices it accurately and optimises it. Both report success.
Hammer and Champy made the relevant point in 1993 and it has not aged: automating a mess yields an automated mess. What has changed is that we can now automate the mess cheaply, measure the cost per unit of mess precisely, and route the mess to a smaller model.
The efficiency of a machine doing worthless work is not a governance metric. It is a cheaper way to be wrong.
04Why this is getting harder, not easier
McKinsey's own analysis contains the reason the process question is becoming more important rather than less.
Their first competitive implication is that process advantage is harder to defend, because agentic systems compress the advantages that used to come from superior execution. The same capability can now be scaled across thousands of workflows through software platforms.
Read that alongside the sequencing finding from their earlier work, that high performers are roughly twice as likely to have redesigned workflows before selecting a model, and the conclusion is uncomfortable for the cost frame.
If every competitor can buy the same agent, run it on the same models, and route it with the same discipline, the routing is not the advantage. The underlying process is. The enterprise that redesigned the workflow before automating it and the enterprise that automated the existing mess are now running identical technology at identical cost per token, and only one of them is getting anything back.
Cost governance is a race to parity. Everyone arrives eventually, because the techniques get published and the vendors sell them. The process work is where the difference sits, and it is the one thing neither governance model has an owner for.
05What the third seat asks
Six questions, drawn from what we assess in Value at Stake engagements. None of them appear in either model.
Does the underlying process work?
Not whether the agent executing it is efficient. Whether the process is worth executing at all. In our own delivery, roughly 80% of standard operating procedures need rewriting before agentic AI can sit on top of them. That is a practitioner observation from our engagements rather than a published figure, but it is consistent enough that we plan for it.
Is the workflow documented as it actually runs?
Every enterprise workflow has a documented version and a real version. The documented one has five steps. The real one has nine, including four that exist only because an experienced agent learned to work around a system limitation years ago. Nobody wrote those down. The AI does not inherit them. Model routing does not surface them. A privacy impact assessment does not surface them.
Is the data good enough for this specific decision?
Not whether a data governance function exists, which the compliance committee will confirm. Not whether the context layer is well architected, which the CIO now owns. Whether the data supporting this workflow, at this quality and this refresh rate, will support the decision this model is being asked to make.
Will the organisation actually adopt it?
The quietest failure. The system works, the agents route around it, adoption stalls at 30%, and the business case assumed 85%. Cost per outcome still looks healthy, because the only outcomes being counted are the ones that happened. Adoption is a variable in the return calculation and it should be estimated before build, not discovered after.
Is this the right use case, or the first one somebody suggested?
A ranked portfolio built on realistic twelve-month deployable return looks nothing like the list that arrives organically through intake, and nothing like the list that emerges from asking which workloads consume the most tokens.
Who owns the number?
Not the risk. Not the run cost. The number. If this use case is projected to return a specific amount, whose P&L does it land in, and what happens at the review when it does not.
06Three changes
Add the seat. Somebody who owns commercial outcome rather than risk or run cost. A CCO, COO, or SVP of CX where the use cases are customer-facing. Their authority to say no has to match the CISO's and the CFO's, and it has to be exercisable on commercial grounds alone.
Add the verdict. Risk tiering classifies by impact and data sensitivity. Cost governance classifies by workload placement. Put a commercial classification alongside both, binary rather than graded. GREEN means we believe this returns, and here is the number. RED means it does not, or not yet, and here is the specific condition that would change that. A graded scale invites hedging. Binary forces a position.
Add the metric that can fail. Time to approval measures the committee. Cost per outcome measures the machine. Realised value against the original business case measures the programme, and it is the only one of the three that can tell you the programme is not working.
07The uncomfortable version
A governance model constituted purely around risk cannot fail. If the programme returns nothing, nothing unsafe was deployed and the audit trail is complete.
A governance model constituted around cost has a subtler version of the same property. If the programme returns nothing, the machine work was still efficiently allocated, well routed, and accurately priced. Cost per outcome can improve every quarter while the outcomes themselves are worth nothing.
Both can report green through a programme that delivers no return, because the thing that failed was never in scope for either.
Governance that cannot fail is not governance. It is documentation, and now it is documentation with a cost model attached.
08Audit your own committee
Take your terms of reference and the last four approval records.
Who in that room can say no on commercial grounds alone, and has actually done it.
If a use case approved eight months ago is returning nothing today, which metric shows it. Not which metric shows it is running expensively. Which one shows it is not working.
Of the last four approved, how many had the underlying process examined before anybody chose a vendor or a model.
If the answers are nobody, none, and none, both governance models are doing exactly what they were built to do. Between them, they still leave the question that decides the outcome unasked.
Governance that cannot fail is not governance. It is documentation, and now it is documentation with a cost model attached.
CXaiS is an independent AI in CX consultancy. We build the commercial foundation, ROI framework, and implementation plan that makes AI investment in customer experience perform. We have no platform to sell and no preferred vendor.
cxais.ai/contact