HR Transformation

AI Governance Is Following the Same Path as Operational Resilience, Just Faster

Elie Azzi | Client Relationship Partner

Anyone who lived through the operational resilience years will recognise what is now happening with AI governance. The pattern is the same. And the organisations that spot it early will be far better placed than the ones that don’t, just as they were last time.

It starts with a misread. Across regulated sectors like financial services, pharma, and infrastructure, many organisations are treating the lack of clear AI rules as breathing room. No rulebook yet, so no urgency yet. Wait, see what gets required, then comply. It sounds sensible. I think it’s a mistake. Not because I can predict the regulation, but because we have seen this exact situation play out before.

“No rulebook” does not mean “no obligation”

Look at what the regulators are actually doing. In financial services, the sector furthest down this road, the FCA, the PRA and the Bank of England have said clearly that they will oversee AI through the rules that already exist, rather than write new AI-specific ones. The Government has taken the same line nationally, holding back on AI legislation in favour of a lighter, sector-by-sector approach. So there is no rulebook coming. Nobody is going to hand you one.

But look at what is happening at the same time. The expectations are climbing fast. In financial services, responsibility for AI-driven decisions is being placed directly on named senior people; someone has to be able to explain what an automated system did, and step in if needed. In January, the Treasury Committee publicly criticised the “wait-and-see” approach and warned it risks real harm. By most counts, around three-quarters of UK financial firms already use AI in some form.

Put those two things together, and the message is simple. The rules are not changing. But the expectation that you can account for your AI clearly, at a senior level, with a person able to step in, is rising quickly. So “no rule yet” is not permission to wait. It is the gap that the slower organisations will fall into.

Why this echoes resilience

This is where the comparison earns its place. Operational resilience went through exactly this shape, and not long ago.

For years, there was no single hard rule. Just a principle that you should be able to keep running and recover when something broke, expectations that kept rising, and less and less patience for firms that treated it as a box-ticking exercise. The organisations that came through it best were not the ones with the best-written policies. They were the ones that treated resilience as something the board owned, built into how decisions were made and who was accountable, instead of pushing it down to the risk team to handle once a quarter. When the expectations finally hardened, they were ready. The ones that waited spent years catching up under pressure from supervisors. That is the most expensive way to do anything.

AI governance is following the same script. And the same divide is opening up. Some organisations are treating it as paperwork to delegate downward. Others are treating it as a leadership issue to own at the top. A lighter, principles-based regime does not reward the thickest binder. It rewards the organisation that can show it has genuinely thought early, and at a senior level, about the risk it is taking. That was the lesson with resilience. It is becoming the lesson with AI.

The big difference is speed. Resilience built up over the best part of ten years. AI is arriving across organisations in months, often faster than anyone can put proper controls around it. So the gap between “we are using this” and “we can explain how we use it” opens much faster than it did before. And supervisors know it.

There is already a standard you can use

The fair question is: if there is no rulebook, what do you actually build against? The most useful answer is to borrow the one concrete standard already in force, the EU’s.

The EU AI Act’s rules for higher-risk AI systems are due to take effect in August 2026. They are specific in the places a principles-based approach stays vague: a named owner for each high-risk system, checks on data and bias, records that can stand up to an audit, AI obligations passed on to outside vendors, and human oversight set up so a person can actually step in. UK direction through senior-manager responsibility, the work on automated decisions, and the Treasury Committee’s pressure seems to be heading toward the same substance, even if it never copies the wording.

So, the practical view is simple. Treat the EU standard not as a foreign burden, but as a sensible baseline for what good AI governance looks like and as a fair guide to where the UK and other regulated markets are heading. An organisation built to that standard is not overdoing it. It is sitting ahead of the likely curve instead of scrambling behind it. That is a good place to be. A year behind, explaining to a regulator why you waited, is not.

None of this needs you to predict the exact rules. No one can. It just needs you to see a pattern that has already run once: light-touch oversight, expectations rising while the rulebook stays quiet, responsibility landing on the people already accountable, and a usable standard sitting right there for anyone willing to take it.

The organisations that got resilience right did not see further than everyone else. They just refused to treat “no rule yet” as “nothing to do.” The ones applying that same instinct to AI now are the ones who will look well-judged in a year or two. The ones waiting to be told are setting themselves up to catch up the hard way.

Elie Azzi headshot

About the author, Elie Azzi.

Elie is a Marketing and Business Development professional with a track record in financial services, insurance, and consulting. He focuses on identifying growth opportunities, streamlining operations, and delivering commercially impactful solutions.