<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1331609480336863&amp;ev=PageView&amp;noscript=1">
Fast Enough to Matter, Careful Enough to Trust: How Leaders Govern AI

August 21 2026 | Thought Leadership

Fast Enough to Matter, Careful Enough to Trust: How Leaders Govern AI

The conversation about AI governance in large organisations tends to default to a familiar shape. Set the policy. Appoint the committee. Add the controls once something has gone wrong. It is a reasonable instinct. It is also, increasingly, the wrong place to start.

Spend enough time listening to the people actually responsible for AI strategy inside major organisations, and a different picture emerges. Governance, they will tell you, is not something bolted onto a finished decision. It is the decision.

That is the thread running through the latest episode of Data and AI Mastery. Featuring a compilation of conversations with senior data and AI leaders at Santander UK, Aviva, VodafoneThree, Oxford Saïd Business School, and Intact Insurance, one theme surfaced consistently, regardless of sector, scale, or where each organisation sits on its AI journey. Moving fast and staying trusted are not competing goals. Treated properly, they are the same goal.

Guardrails Are Not a Trade-off

Ask leaders where governance actually sits in the delivery process, and the strongest answers put it right at the architecture stage, not at the review stage.

Sarah Self at Aviva is direct about this. If an organisation delivers something to a customer quickly and cheaply but fails to protect their data or behaves unethically along the way, that is not a partial win. It is a total failure, dressed up as a success. The good outcome and the safe outcome, in her framing, are not two separate things to be balanced against each other. They are one and the same requirement, and treating them that way from the very start removes the trade-off altogether.

 

Curated, Not Controlled

Mark Bramwell at Oxford Saïd Business School describes a different route to the same discipline. Rather than mandating a single AI tool across the institution, the school built a portfolio approach: broad, secure access to a range of tools, on the basis that people will find their own way to AI regardless of whether an organisation provides it safely. The philosophy is deliberately permissive. Access is given. Experimentation is encouraged. Control is exercised through the architecture of the access itself, not through restricting what people are allowed to try.

The Governance Conversation Boards Actually Need

Where organisations often go wrong is having the wrong governance conversation entirely. Luke Pearce at Santander UK is sceptical of boardroom discussions that fixate on the fear of hallucination, treating every unexpected output as evidence the technology cannot be trusted.

The more useful conversation, he argues, is about oversight. How models are being called. Whether the data feeding them is good. Whether outcomes are being checked as they scale. Once a board understands those three layers, the question shifts from a vague anxiety about AI going wrong to a concrete, answerable one: do we have confidence these controls are working, and are they working everywhere they need to?

The Question Worth Asking

Miryem Salah at VodafoneThree offers a useful synthesis of how this plays out operationally. Rather than choosing between rigid, waterfall-style control and fast-moving agility, she describes building a hybrid: waterfall discipline for the foundations that matter most, security, privacy, and ethical use, paired with genuine agility everywhere else. A governed, agile approach, rather than a choice between the two.

Underneath all of it sits a discipline that is easy to skip and expensive to skip badly: measuring impact against a baseline before scaling anything further, so that when a board asks whether an initiative is working, there is an actual answer.

The organisations making genuine progress on AI governance are not the ones with the most restrictive policies or the ones moving fastest without any. They are the ones who asked the harder question first: have we designed trust into this from the start? And then built accordingly.

______________________________________________

Chapter Markers: 

  • (00:00) Episode Introduction

  • (02:01) Miryem Salah, VodafoneThree: building an AI strategy from first principles

  • (05:40) Sarah Self, Aviva: why guardrails and customer outcomes are not a trade-off

  • (09:47) Miryem Salah, VodafoneThree: a governed, agile approach to change

  • (12:28) Luke Pearce, Santander UK: moving the board past fear of hallucination

  • (16:22) Mark Bramwell, Oxford Saïd Business School: a portfolio approach to AI tools

  • (20:13) Luke Pearce, Santander UK: a domain-led approach to use cases

  • (23:44) Indhira Mani, Intact Insurance: what success looks like a year from now

  • (27:24) Conny Ploth: why you can't manage what you don't measure

  • (29:53) Nick Edwards, The AA: curated, not controlled

  • (30:53) Closing reflections

Useful Links:

At Cambridge Spark, we work with organisations tackling exactly this challenge: building the AI strategy and governance capability that lets leadership teams move fast without losing the trust of the people they serve. If this is something your organisation is navigating, explore how we can help - explore our AI solutions

 

Upskill your workforce

Upskill your workforce and accelerate your data transformation with expert technical programmes designed to create impact.

Contact us