AI Governance Without Skin in the Game
57% of employees are hiding their AI use from their employers. The problem isn't reckless behaviour — it's that governance is being designed by people who've never been close to th…
On why the people designing AI frameworks need to be much closer to the failure modes
57% of employees are hiding their AI use from their employers. 66% do not verify AI outputs. 48% are uploading company data into public AI tools. Only 47% have received any AI training at all.
These numbers are from a KPMG–University of Melbourne study covering 48,000+ people across 47 countries. They are not describing reckless employees. They are describing organizations that have deployed AI faster than they have built the governance infrastructure to manage it — and workforces that have quietly adapted around the gap.
The question I keep returning to: what happens when the people designing AI governance have never been close to the failure modes they are designing against?
The numbers first
The findings are not catastrophic. They are mundane. This is not dramatic AI failure. It is quiet, everyday governance erosion:

What this describes is large-scale organizational behavior happening largely out of sight of the people who are supposed to be managing it. Adoption without control. Speed without infrastructure.
Meanwhile, BCG research across approximately 13,000 employees finds that 43% of frontline workers already use generative AI regularly, with many saving five or more hours weekly. McKinsey estimates generative AI's potential productivity contribution at $4.4 trillion annually. The adoption is real. The productivity gains are real. The governance is not keeping pace.
This is not primarily a technology problem. It is a proximity problem.
Taleb had a word for this

Nassim Taleb's central argument — sharpest in Skin in the Game — is that systems become fragile when the people making decisions are insulated from the consequences of those decisions. Not because they are incompetent. Because the incentive structure is wrong.
The consequence of insulation, he argues, is not just worse decisions. It is the gradual decoupling of theory from reality. The elegant framework that cannot survive contact with operational complexity. The risk model that misses the tails because the people writing it have never lived in them.
In most large organizations today, AI governance is an insulated function. Policies are written in committees by people who are not the recruiter trying to make sense of an AI-generated shortlist, not the employee who discovered their promotion was shaped by a model they never knew existed, not the HR business partner trying to explain to a colleague why they were flagged as a flight risk. The governance layer and the consequence layer are far apart. And that distance is producing exactly what Taleb would predict: governance that is sophisticated in presentation and fragile in practice.
Think about who we trust to govern complex systems in other domains. We would not accept an aviation safety regulator who had learned to fly entirely from textbooks — who had never experienced instrument failure in real conditions, never had to make a decision when the system behaved unexpectedly. We expect their policy judgment to be grounded in operational reality, because we understand intuitively that the expertise that matters is not theoretical mastery. It is proximity to failure.

Many organizations are now governing AI systems that determine who gets hired, who gets promoted, and whose performance is assessed — with people who have never used those systems deeply, never tested their edge cases, and never sat with the consequences of a result that was wrong.
Where governance models are actually breaking
The most common governance failure I observe is not an absence of frameworks. Most organizations have frameworks. What is missing is accountability architecture.

IT deploys the tools. Legal reviews the risk. HR adopts the systems operationally. Nobody owns what happens when the output is wrong.
PwC's research on Responsible AI maturity finds that while responsible AI is now broadly recognized as a strategic priority, operationalizing governance remains the primary challenge. Principles exist. Clear ownership of consequences rarely does.
This produces three specific failure modes that are now showing up consistently in the data.
The first is shadow AI escalation. When employees find official channels too restrictive or too opaque, they find alternatives. The KPMG data suggests this is happening at scale and mostly invisibly. And here is the thing about shadow AI: the problem is not primarily data leakage, though that is real. The problem is that the governance system loses visibility into what is actually being used to make decisions. The organization is flying partially blind.
This points to something that gets misdiagnosed. The KPMG findings are often read as evidence that employees are reckless or indifferent. I do not think that is what they show. Employees are not afraid of AI. What they fear is opacity — not knowing what data feeds the decision, not knowing how the model reached its conclusion, not knowing whether anyone who matters is genuinely accountable if it is wrong. There is a reason some restaurants put the kitchen in full view of the dining room. Not for efficiency — an open kitchen is operationally harder. Because transparency itself creates trust. People do not need to understand every detail of how the food is made to feel more confident when they can see it being made. AI governance fails the same test when it operates as a black box to the people it governs.
The second failure mode is automation bias. Research consistently finds that humans defer to AI recommendations even when the logic is unclear or the evidence is questionable. In HR decisions — hiring, performance, succession planning — this means AI outputs become de facto decisions while the official position remains that humans are in the loop. The human in the loop is often doing something closer to rubber-stamping.
The third is the literacy gap preceding policy. You cannot write effective policy for behaviors a workforce does not yet understand. If employees do not know how a model works, they cannot meaningfully consent to its use, identify its errors, or comply with rules designed around it. Building policy before building literacy is governance theatre.
What governance-serious HR leaders actually need to do
Three things. They are not complex. They are harder than they sound.
→ Use the tools before governing them. Not a vendor demo. Not a pilot summary written by someone else. Sit with the systems influencing decisions in your organization. Run your real use cases through them. Understand where they are fluent and where they fail. The policy judgment you need requires proximity to operational reality — not theoretical familiarity with the architecture.
→ Own the accountability — do not delegate it. If AI is influencing who gets shortlisted, who gets promoted, whose performance is flagged — that accountability cannot sit with the vendor or the algorithm. It has to sit with leadership, visibly and auditably. Governance frameworks that assign accountability to "the system" or "the provider" are not governance frameworks. They are liability transfer mechanisms.
→ Build AI literacy before building AI policy. The foundation of effective governance is a workforce that understands how these systems work, why they produce the outputs they do, and how to interrogate results rather than accept them. Most organizations have reversed this order: they have policies for employees who lack the conceptual foundation to operate within them.

The observation I keep coming back to
I have been writing about related problems from a few angles this year — on what Adam Smith's Impartial Spectator reveals about what a genuine governance mechanism needs to do; on why Naval Ravikant's leverage framework looks different when AI is doing the lifting, and what that means for who creates asymmetric value inside organizations.
The pattern that keeps emerging is the same. The gap is not the technology. It is the translation layer — the space between what models can do and what organizations are actually prepared to govern, use responsibly, and adapt around. The people who sit closest to that layer — with technical depth, institutional knowledge, and the operational experience to understand both sides — are consistently the most undervalued and underhired in enterprise AI right now.
Taleb's core insight is that proximity to consequences is not just a fairness concern. It is a quality signal. The person closest to the downside is the person most motivated to get the decision right.
The organizations that navigate this transition well will not be the ones with the most advanced models.
They will be the ones willing to stay closest to the consequences.
I write about AI in enterprise HR, the gap between vendor pitches and working deployments, and what it actually takes to govern AI inside large organizations. All views are my own and do not represent any employer or organization.
One question I would genuinely like to hear your answer to: who in your organization owns accountability when an AI-assisted hiring or promotion decision goes wrong? HR, Legal, IT, or the vendor? If you are working through this right now — in any direction — I would like to hear how you are thinking about it. Reply or leave a comment.
Ian Xie | 2026年5月26日 | ian.us.ci
