The AI Governance Gap: What HR Is Not Yet Being Asked to Own

The room is set up. The accountability isn’t.

Organisations are moving fast on AI. Most have someone responsible for the technology. Fewer have someone responsible for the people consequences: the decisions it shapes, the roles it rearranges, and the trust it either builds or quietly erodes. That gap is where the next wave of people risk is accumulating.

Every organisation I am working with is somewhere in the process of adopting AI. The conversations are no longer about whether to adopt. They are about pace, about risk tolerance, and about who is responsible when something goes wrong in a way nobody anticipated.

What I often do not hear in those conversations is HR’s role in the governance architecture. Technology leadership owns the tools. Legal and compliance own the regulatory surface. In many of the organisations I work with, HR is being consulted. The question of what HR owns within AI governance, specifically the decisions that govern how AI outputs interact with people’s working lives, has frequently not been asked clearly enough for anyone to answer it.

Driving clarity on that question is HR’s work. The organisations that navigated AI adoption well recognised early on that the question was never purely technical. It was about decision rights, accountability, and what the organisation is prepared to be responsible for. HR is the function positioned to define those boundaries, and to ensure the accountability architecture keeps pace with the technology.

Where the gap actually sits

AI in HR is often discussed in terms of its direct applications: screening, scheduling, sentiment analysis, and performance calibration. These are real and worth examining carefully. The governance gap I am pointing to is different.

It sits at the intersection of AI-driven decisions and human accountability. When a recommendation is produced by a system, who is accountable for the outcome? When a manager acts on an AI-surfaced insight about their team, what obligation exists to tell the team member how that insight was generated? When a workforce model shifts hiring or deployment decisions, where does the employee’s right to understand those decisions live?

These are not primarily legal questions, though they have legal dimensions. They are governance questions. They require someone within the organisation to be explicitly accountable for the human layer of AI adoption: the decisions, accountabilities, and processes that govern how AI outputs interact with people’s working lives, who can be affected by a system-generated recommendation, what they are entitled to know about it, and who is responsible when something goes wrong.

The scale of the gap is not in dispute. Grant Thornton’s 2026 AI Impact Survey of 950 C-suite and senior leaders found that 78% of executives are not confident they could pass an independent AI governance audit within 90 days, and that 46% identified governance failures as a leading cause of AI underperformance. A joint HFS Research and Altimetrik study of 500 global enterprises found that only 14% have an AI strategy aligned to accountability structures, with close to 80% reporting unclear ownership of AI initiatives. Recent WEF research found that less than 1% of organisations globally have fully operationalised responsible AI, while Accenture’s APAC research puts the regional figure at 1%.

None of those figures reflect a technology deficit. They reflect a governance one, and specifically a story about who has been asked to own the human layer of AI adoption, and who has not yet been asked at all.

The APAC dimension

Across the markets I work in, the regulatory environments vary considerably. What does not vary is the speed of AI deployment relative to the readiness of governance structures to absorb it.

Regulatory frameworks across the region are moving deliberately, and the direction is clear. Singapore issued its Model AI Governance Framework for Generative AI in May 2024, built on earlier AI governance work and covering accountability, incident reporting, and content provenance as operational dimensions. Japan passed its AI Promotion Act in May 2025, adopting a principle-based approach that emphasises national oversight over prescriptive compliance. South Korea’s AI Basic Act took effect in January 2026, the first comprehensive national AI legislation in the region. The direction is consistent: accountability structures are being formalised, and the bar for what constitutes responsible governance is rising.

But regulatory compliance is a floor, not a ceiling. The organisations managing this well are building internal governance that exceeds the regulatory minimum, because the reputational and operational consequences of getting it wrong are not bounded by what a regulator can see.

In more hierarchical organisations across the region, the same failure tends to stay invisible longer. When the cultural architecture around decision-making means that consequences travel slowly upward, AI systems can be running at scale before anyone with the authority to act has seen what they are producing.

In founder-led and scaling organisations, the context where much of my current work sits, the risk is different again. The pace is faster. The governance infrastructure is thinner. The founders most at risk are those who believe their values provide sufficient protection. Values are necessary, but governance architecture is what makes values operational at scale.

What HR needs to own

AI governance as a whole is cross-functional. Technology owns the tooling. Legal owns the compliance surface. The human layer, the decisions that govern how AI outputs interact with people’s working lives, is, by definition, within HR’s domain. The question is whether HR is ready to claim it.

That accountability has at least four dimensions:

  • Which decisions affecting employees require human judgment as a non-negotiable, and which can be AI-influenced.
  • What employees are entitled to know about how AI shaped a decision that affected them.
  • How AI-related people risks get escalated, through a path that exists by design rather than by chance.
  • Who is accountable if the human layer of AI governance fails, and through what mechanism.

That last question is the one most HR functions are not yet equipped to answer. If a CHRO cannot answer it, they are operating without a governance mandate, regardless of what the org chart implies.

Claiming that domain does not require HR to become a technology function. It requires HR to define what it owns in AI governance, and to drive the clarity that makes that ownership legible to the rest of the organisation. For most HR leaders, that starts with an honest read of where the function currently stands: not against a generic maturity benchmark, but against the organisation’s specific operating model and the AI adoption pressures it is actually navigating.

The leadership question

AI adoption changes what managers are being asked to do. In organisations moving quickly, they are increasingly expected to act on recommendations they did not generate and may not fully understand.

When accountability is clear, and people understand what they are responsible for, they exercise judgment. When accountability is diffuse, and the system appears to be carrying the decision, the quality of that judgment under pressure decreases. AI systems that are opaque to the managers using them do not produce better decisions, they produce decisions that travel further up the hierarchy, because nobody is comfortable owning them at the right level.

The governance architecture has to define what a manager is accountable for when they act on an AI-surfaced recommendation, as a structural expectation, not a liability disclaimer. Where that clarity exists, someone in HR has deliberately built it. Where it does not, the question of who owns the human layer of AI governance tends to remain open, and unresolved questions at that level have a way of becoming someone else’s problem to define.

A CHRO who gets ahead of that is doing something valuable. One who waits may find the boundaries have already been drawn without them.

Mirror & Map

Mirror: Where in your organisation are AI-influenced decisions affecting employees without a clear human accountability structure? Which of those situations would be hardest to explain to an employee who asked how a decision affecting them was made?

Map: Who currently owns the human layer of your AI governance? Is that ownership explicit and resourced, or is it assumed because someone in HR is generally aware of what is happening? And if the ownership fails, if a consequential AI-influenced decision goes wrong, who answers for it, and to whom?

The pattern above is what the AI Readiness Diagnostic is designed to surface, a structured review of whether the people, governance, and operating-model foundations are actually in place before AI adoption scales further.

Also in this series

See all editions →

Read the original on LinkedIn →

Mirror & Map is published by Alf Carlesäter, founder of GROW HR Consulting, fractional HR leadership, organisational diagnostics, and executive coaching for scaling organisations across APAC and EMEA.