June 22, 2026
As AI moves from productivity tools into infrastructure, decision-making, agents, healthcare certification, finance, cybersecurity, public-sector systems, scientific knowledge, and institutional workflows, the governance question is shifting from adoption to control: who has access, who has authority, who verifies, who depends, and who can stop it.
Ungoverned: AI Ethics & Governance for Leaders, Boards & Trustees
By Dr. Freddie Seba
© 2026 Freddie Seba. All rights reserved.
Editorial Note
Issue #73 argued that AI is becoming an operating infrastructure. Issue #74 extended that argument: AI entered the decision stack. Issue #75 moves the argument one layer deeper. AI is now entering the control layer.
By control layer, I mean the institutional layer where access, authority, identity, verification, dependency, continuity, accountability, and stop authority are determined.
That may sound abstract. It is not.
This week’s signals make it concrete. Frontier model access may change due to a government directive. AI agents can receive digital identity credentials. Financial agents can connect to accounts to trade, pay, and execute workflows. Healthcare organizations are moving from AI pilots toward certification. Regulators are shifting from guidance to enforceable architecture. Institutions are beginning to depend on AI systems not only for output, but for operational capacity.
This is the moment Ungoverned was written for. AI Minimum Viable Governance is not about slowing innovation. It is about creating a minimum defensible governance floor before useful tools become institutional dependencies.
The governance question is no longer only:
- Where are we using AI?
- Nor is it only where AI is shaping evidence and judgment?
The better question now is:
- Who controls access, authority, verification, identity, continuity, and dependency when institutions increasingly rely on AI systems?
Across this week’s signals, the same pattern appears again and again. AI is moving closer to the systems through which institutions act. It is entering financial transactions, identity systems, health workflows, public-sector tools, copyright disputes, scientific discovery, newsroom triage, clinical documentation, prediction markets, workforce forecasting, cybersecurity, data privacy, and regulatory oversight.
Some of this is exciting. Some of it is necessary. Some of it is risky. All of it requires governance. This is not a partisan issue. It is a policy issue. It is an institutional issue. It is a board issue. It is a public trust issue. Once
AI begins to mediate access, execute transactions, authenticate agents, shape evidence, influence markets, or become a prerequisite for institutional performance, governance can no longer live only in principles, policies, or acceptable-use statements. It has to become operational.
It has to ask who controls the system, who controls access to it, who verifies what the system does, who is accountable when the system acts, what happens when the system is unavailable, what happens when the vendor changes the terms, and what happens when the system becomes too embedded to remove. That is where Issue #75 begins.
From My New Book, Ungoverned
When Usefulness Becomes Dependency
In Ungoverned: A Practical Guide to AI Minimum Viable Governance, I argue that AI governance failures rarely begin with catastrophe. They usually begin with usefulness.
A team adopts a tool. A pilot becomes routine. A vendor feature is switched on. A model drafts customer responses. A health system adds ambient documentation. A university authorizes the use of AI tools for teaching and research. A financial platform lets agents execute transactions. A government considers digital identities for AI agents. A board hears that AI is improving productivity, but not that AI is creating dependency.
None of these changes looks transformational in isolation. Together, they change institutional control. They change what information is visible, which recommendations rise to leadership, what data moves across systems, and what humans verify versus merely accept.
That is how AI becomes ungoverned: not because every use is reckless, but because useful tools become habits, habits become workflows, workflows become dependencies, and dependencies become control structures.
AI Minimum Viable Governance asks leaders to pause before that point.
- Who owns the system?
- What can it access?
- What authority has been delegated?
- What evidence supports it?
- What happens if access is removed?
- Who is affected?
- Who can stop it?
Once dependency appears, governance is no longer optional. It is what keeps institutional capability from becoming institutional fragility.
This Week’s Governance Lesson
Dependency Is Becoming the Governance Bottleneck
The strongest lesson from this week’s signals is simple: AI dependency is outpacing AI governance.
This is visible in frontier AI, where access to advanced models can become a governance event overnight. It is visible in sovereignty strategy, where governments are trying to reduce reliance on external technology stacks. It is visible in agent identity, where Estonia is exploring digital identities for AI agents. It is visible in finance, where agents are beginning to connect to trading and payment systems. It is visible in healthcare, where certification is moving the field from pilots toward organizational readiness.
Dependency itself is not the problem. Institutions already depend on electricity, cloud systems, payment networks, EHRs, learning platforms, cybersecurity tools, and supply chains. The problem is unmanaged dependency.
An institution can adopt AI responsibly and still become fragile if it does not know what it depends on, who controls access, what happens when access changes, what data moves through the system, what costs scale with use, what humans must verify, and who can stop the system.
AI governance translation: AI dependency must be managed before it becomes a source of institutional fragility.
Board/leader move: Require every consequential AI system to be placed on an AI Dependency Register that identifies the provider, model, access rights, delegated authority, data flows, cost exposure, continuity plan, human review, and stop authority.
The Ungoverned lesson: Governance becomes real when leaders can explain not only what AI does, but what the institution can no longer do without it.
Executive Reflection
Human Judgment Is the Last Line of Control
The more AI can do, the more important human judgment becomes. Not because humans should approve every output, but because institutions need humans who understand what deserves authority, what requires evidence, and what should never be delegated.
AI can summarize, monitor, recommend, authenticate, classify, draft, and act across systems. It can help clinicians document, students learn, scientists discover, compliance teams monitor, finance teams model risk, and agents execute transactions. But it cannot legitimately hold institutional responsibility.
The leadership question is not whether AI can expand capability. It can. The question is whether leaders know what authority has been delegated, what dependency has been created, what still requires human verification, and who owns the outcome when the system acts.
AI governance translation: AI can expand institutional capability, but humans must still decide what deserves authority.
Board/leader move: Require leaders to explain what authority AI has been given, what dependency it creates, what evidence supports its use, what human judgment remains required, and who can stop it.
The Ungoverned lesson: AI can support control. It cannot take responsibility.
What We Are Seeing: 12 Governance Signals
1. AI access is becoming an institutional governance risk.
Sources reviewed: Anthropic’s Fable/Mythos access statement; Anthropic Fable/Mythos launch materials; policy and news coverage of frontier model access.
Anthropic’s Fable/Mythos access suspension remains one of the clearest signals in the move from decision governance to control governance. In Issue #74, this story mattered because access to advanced AI systems was becoming a strategic infrastructure question. In Issue #75, the lesson is sharper: access is control.
If an institution depends on a frontier model for software development, cybersecurity analysis, research synthesis, customer support, clinical documentation, policy drafting, or internal workflow automation, then changes in model access are not merely vendor events. They are governance events.
Institutions need to understand that law, export controls, safety determinations, vendor policies, geopolitical tensions, data residency, contract terms, capacity constraints, public trust, and national security reviews may shape AI access.
Traditional software can often be patched, replaced, or migrated over time. Advanced AI systems may be harder to substitute because the model’s capability, context window, tool ecosystem, training behavior, pricing, retention policy, and provider terms all shape how work gets done.
AI governance translation: Model access is now part of operational resilience.
Board/leader move: Require an AI access-risk review for critical AI dependencies, including provider jurisdiction, access restrictions, user eligibility, data retention, continuity options, substitute models, and emergency downgrade plans.
The Ungoverned lesson: A system is not fully governed if the institution cannot explain what happens when access changes.
2. AI sovereignty is becoming an infrastructure strategy.
Sources reviewed: Europe 2031; European Commission tech sovereignty materials; EU digital strategy resources.
The Europe 2031 scenario is written as a warning, not as a prediction. Its central argument is that Europe risks losing the ability to shape its own future if it does not respond to AI with enough urgency, infrastructure investment, institutional coordination, and strategic clarity.
Whether one agrees with the scenario or not, it is valuable because it makes a governance risk vivid. AI sovereignty is not only about national pride. It is about institutional options.
The sovereignty question asks whether a country, region, university, health system, public agency, or company has enough access to compute, models, talent, infrastructure, security, and governance capacity to make its own choices.
For boards, this becomes practical. Are we building AI capability, or only renting it? Are we developing internal expertise, or only outsourcing judgment? Are we creating resilience, or only accelerating dependency? Are we preserving exit options, or locking ourselves into systems we cannot replace?
The sovereignty question is not only national. It is institutional.
AI governance translation: AI sovereignty is the governance of dependency, not only the politics of technology.
Board/leader move: Require AI strategy reviews to include vendor dependency, model substitutability, data portability, compute exposure, jurisdictional risk, internal capability, and exit planning.
The Ungoverned lesson: Institutions that confuse access with control may discover too late that they have capability without sovereignty.
3. Frontier AI governance is becoming a national capability.
Sources reviewed: Great American Artificial Intelligence Act discussion draft; GovAI Annual Report 2025; frontier governance and standards resources.
The discussion draft of the Great American Artificial Intelligence Act is not law. That distinction matters. But the policy signal is important because it reflects a shift from principles to institutional machinery.
The draft proposes a broad architecture around frontier AI governance, including a Center for AI Standards and Innovation, frontier AI frameworks, transparency reporting, independent verification organizations, whistleblower protections, workforce research, cybersecurity support, testbeds, and international cooperation.
This is what control-layer governance looks like in policy form. It asks who defines frontier AI, who evaluates catastrophic risk, who verifies developers’ claims, who receives confidential incident reports, who reviews safety frameworks, who audits controls, and who protects whistleblowers.
The direction is clear: frontier AI governance is becoming a national capability issue. That does not mean every AI use case belongs at the national security level. Most do not. But the most capable systems increasingly affect critical infrastructure, cyber defense, scientific capability, workforce transformation, and institutional resilience.
AI governance translation: Frontier AI governance requires institutions, expertise, verification, and durable policy capacity.
Board/leader move: Track frontier AI policy developments as part of enterprise risk, not only legal compliance.
The Ungoverned lesson: Principles describe what institutions value. Governance architecture determines what institutions can actually control.
4. AI agents are becoming institutional actors.
Sources reviewed: Estonia digital identity proposal for AI agents; Google AI Mode information agents; agent identity and delegated access discussions.
Estonia’s proposal to create digital identities for AI agents deserves close attention because it represents a governance shift from AI as a tool to AI as an actor.
If an AI agent can act on behalf of a person or institution, then identity becomes governance. The institution must know what was acted under, under whose authority, with what scope, and with what audit trail.
An agent without an identity is hard to verify. An agent with an identity but no authority limit is hard to control. An agent with authority but no audit trail is hard to investigate. An agent with logs but no accountable owner is still not governed.
The same issue appears in information agents that monitor sources, track changes, and produce synthesized updates. These systems are useful because they do not wait passively for a user to ask again. But that usefulness also changes the workflow. The agent begins to monitor, synthesize, prioritize, and prompt action.
AI governance translation: Agent identity, delegation, and auditability are becoming core governance controls.
Board/leader move: Require any AI agent that acts across systems to have a named owner, defined scope, authenticated identity, delegated authority limit, logging, monitoring, and revocation process.
The Ungoverned lesson: An AI agent without a clear identity and authority is not an assistant. It is an ungoverned actor.
5. AI agents are entering finance, trading, and payments.
Sources reviewed: Coinbase for Agents; Coinbase Agentic Wallet; New York State Department of Financial Services proposed stablecoin regulation.
Finance makes the control-layer question immediate. An AI agent that drafts a financial summary is one thing. Another is an AI agent that executes a transaction.
Once AI can move money, buy services, trade assets, pay for APIs, or execute workflows, governance must move from content review to transaction control. The questions become practical: Who authorized the agent? What spending limit applies? What assets can it access? What confirmations are required? What transactions are prohibited? What is logged? What is reversible? Who is liable?
Financial systems already have mature concepts of authorization, custody, suitability, fraud, audit, supervision, and risk management. Agentic finance will test whether those concepts can adapt to non-human actors executing financial tasks under delegated authority.
Stablecoin and digital-asset regulation also matters here because agentic payments may depend on programmable money, wallets, APIs, stablecoins, and machine-to-machine commerce.
AI governance translation: Once AI agents can transact, financial governance must include agent authority, spending controls, auditability, fraud response, and reversibility.
Board/leader move: Require an agentic transaction policy before allowing AI agents to move money, place orders, access financial accounts, or initiate purchases.
The Ungoverned lesson: A bad AI answer can mislead. A bad AI transaction can move assets.
6. Healthcare AI is moving from pilots to certification.
Sources reviewed: Joint Commission Responsible Use of AI in Healthcare certification; CHAI AI Governance Playbooks; healthcare AI governance resources.
Healthcare AI is entering a new phase. For several years, the field focused on pilots, proof-of-concept tools, ambient documentation, triage, imaging, clinical decision support, patient communication, operational analytics, and workflow automation. Now, governance infrastructure is catching up.
The Joint Commission’s Responsible Use of AI in Healthcare certification is important because it focuses on organizational readiness rather than certifying individual AI products. That distinction matters.
Product certification asks whether a tool meets requirements. Organizational certification assesses whether the institution is prepared to govern the use of AI.
That is the right direction for health AI because the risk of clinical and operational AI depends heavily on context. A model can perform well in one setting and fail in another. An AI scribe can reduce documentation burden but create privacy questions. A triage model can improve throughput but create equity risks. A clinical support tool can help clinicians, but it can also create automation bias.
AI governance translation: Health AI maturity is moving from tool evaluation to organizational readiness.
Board/leader move: Require health AI governance to include certification readiness: policy, owners, lifecycle management, monitoring, risk assessment, validation, data governance, vendor oversight, staff training, patient transparency, and escalation.
The Ungoverned lesson: A health AI tool is not governed because it works in a demo. It is governed when the institution can safely manage it in real care.
7. Institutions are demanding ROI, not experimentation.
Sources reviewed: NEJM AI discussion on AI as an ROI multiplier in healthcare; Becker’s reporting on health systems managing AI costs; health AI value discussions.
AI cost is becoming a governance issue. That is not only a financial point. It is a control point. Institutions are moving from “Can we pilot this?” to “Can we justify this?” and from “Can we experiment?” to “Can we sustain this?” In healthcare, the question is especially urgent because many organizations operate on thin margins, face workforce strain, navigate compliance demands, meet patient safety obligations, and manage complex vendor ecosystems.
AI can multiply value when it helps allocate care, reduce burden, improve quality, or support better decisions. But it can also multiply waste if the use case is poorly defined, the workflow is not ready, the model is overused, or the cost structure scales faster than the value created.
This is where AI Minimum Viable Governance becomes financially practical. Governance is not overhead. Governance is cost control. It helps institutions decide which use cases deserve scale, which should be stopped, which require more evidence, and which produce measurable value.
AI governance translation: AI ROI requires governance over use cases, consumption, outcomes, cost exposure, and stop criteria.
Board/leader move: Require AI investment proposals to include measurable value, cost model, token or usage exposure, implementation burden, human workflow impact, vendor dependency, and shutdown criteria.
The Ungoverned lesson: AI value is not proven by enthusiasm. Outcomes, evidence, and disciplined scaling prove it.
8. Evidence generation and public knowledge are becoming AI-mediated.
Sources reviewed: Boston Review, “Knowledge Collapse”; Nature coverage of AI and antibiotic discovery; Generative AI in the Newsroom case study; Anthropic Public Record.
AI is changing how knowledge is discovered, summarized, circulated, and trusted. That is one of the most consequential control-layer shifts because institutions depend on knowledge systems long before they make formal decisions.
AI can help accelerate discovery, identify new scientific leads, synthesize public records, support journalism, and surface patterns that humans might miss. It can also narrow inquiry, obscure uncertainty, privilege certain sources, and make synthetic summaries feel more complete than they are.
The governance issue is not only whether AI-generated content is accurate. It is whether AI is changing what knowledge becomes visible in the first place.
If AI helps find signals, summarize sources, prioritize leads, generate hypotheses, translate evidence, or identify patterns, then AI is shaping what humans see. That can expand knowledge. It can also create dependence on summaries, rankings, synthetic outputs, and hidden assumptions.
AI governance translation: Institutions need governance for AI-mediated knowledge, not only AI-generated content.
Board/leader move: Require evidence-facing AI systems to document source provenance, human review, uncertainty, omissions, conflicts, and whether outputs are used for discovery, decision support, or official conclusions.
The Ungoverned lesson: When AI shapes what knowledge is visible, governance must protect how knowledge becomes trusted.
9. Human judgment and public trust are becoming measurable governance concerns.
Sources reviewed: Anthropic Public Record; OpenAI beneficial reinforcement learning research; Center for AI Safety values dashboard; research on warrant-sensitive reliance. Public trust is not a communications problem alone. It is a control problem.
People want benefits from AI. They also want accountability. They want useful systems. They also want to know who is responsible when harm occurs. They want innovation. They also want safeguards.
This matters because trust does not come from capability alone. It comes from justified reliance. Institutions need to know when to accept an AI output, when to challenge it, when to seek expert review, and when to refuse automation.
Research on beneficial model behavior and values is encouraging. But even a better-aligned model operates inside a workflow, contract, data environment, human culture, and institutional accountability structure.
Institutions cannot outsource judgment to model behavior alone. They must decide when reliance is warranted.
AI governance translation: Trustworthy AI depends on warranted, not blind, reliance.
Board/leader move: Require AI governance to define where human judgment is mandatory, what evidence humans need to review, and what conditions make AI output insufficient for institutional action.
The Ungoverned lesson: AI can become more aligned. Institutions still need judgment about when reliance is justified.
10. Copyright is becoming governance infrastructure.
Sources reviewed: AI copyright litigation map; publisher lawsuits; author lawsuits; publisher/platform negotiations; copyright and training data disputes.
The “Who’s Suing Whom in AI?” visual is useful because it turns a legal landscape into a governance map.
The immediate story is copyrighted. The deeper story is institutional control over data, training inputs, licensing, attribution, compensation, and market power.
Copyright litigation is not just about whether an AI company lawfully used a dataset. It is about the future rules of knowledge production. Who gets paid? Who gets attribution? Who controls reuse? Who decides what counts as fair use? Who has bargaining power? Who can license at scale? Who can refuse?
For boards and institutional leaders, copyright cannot remain a remote legal debate. It affects procurement, vendor review, internal model training, AI-generated content, publishing, education, research, communications, marketing, compliance, and intellectual property strategy.
The governance question is not only “Can we use the tool?” It is also “What rights, licenses, data sources, outputs, and obligations travel with the tool?”
AI governance translation: Copyright is becoming part of AI supply-chain governance.
Board/leader move: Require AI vendor and use-case reviews to include training-data representations, output ownership, indemnity, licensing, attribution, internal data use, and restrictions on reuse.
The Ungoverned lesson: If the institution cannot explain where AI content comes from, it may not understand the rights and risks it is inheriting.
11. Prediction markets are challenging traditional expertise.
Sources reviewed: Prediction Market Accuracy: Crowd Wisdom or Informed Minority?; Yale Insights coverage; prediction market research.
Prediction markets are often described as wisdom-of-crowds systems. The research reviewed this week complicates that story.
The key finding is that prediction-market accuracy may come less from broad crowd wisdom and more from a small minority of persistently skilled traders. That matters beyond prediction markets.
Institutions often treat aggregation as wisdom. More opinions. More data. More dashboards. More signals. More model outputs. But more is not always better. Sometimes accuracy comes from a small number of people who know how to interpret public information better than others.
That is not an argument against participation. It is an argument for understanding where information quality actually comes from.
For boards, the lesson is direct. A model can summarize many documents. A dashboard can aggregate many signals. A market can reflect many trades. A survey can include many responses. But institutional judgment still requires asking who is informed, who is merely active, who has expertise, who has incentive, who is repeating noise, and who is accountable for interpretation.
AI governance translation: Decision systems need the provenance of expertise, not just the aggregation of signals.
Board/leader move: When using AI forecasts, prediction markets, expert panels, or aggregated evidence, require clarity on who contributes signal, who contributes noise, what incentives apply, and how outputs are validated.
The Ungoverned lesson: The crowd may provide volume. Governance still has to identify the sources of trustworthy information.
12. Institutions are moving from AI principles to enforcement architecture.
Sources reviewed: EU AI Act updates; NYDFS proposed stablecoin regulation; WEF data privacy and cybersecurity analysis; UK PoliceAI announcement; The Markup mental health AI privacy reporting; shadow AI and GLBA analysis.
AI governance is moving from aspiration to enforcement.
That shift is visible in certification, audit expectations, stablecoin regulation, AI Act implementation, public-sector AI programs, privacy investigations, and sector-specific compliance concerns. The pattern is clear: AI principles are being translated into reporting, documentation, monitoring, internal controls, risk management, certification, incident response, and enforcement.
This is the right direction, but it raises a practical problem. Many organizations still treat AI governance as a policy document rather than an operating system.
That will not be enough.
The control layer requires proof. What is the system allowed to do? What data does it access? What identity does it use? What is logged? What is disclosed? What is reversible? Who is accountable? What happens when the system fails?
AI governance translation: AI principles are becoming a governance architecture.
Board/leader move: Review whether organizational AI governance is ready for certification, audit, enforcement, incident reporting, regulatory review, and public accountability.
The Ungoverned lesson: A principle is not governance until it changes what the institution can prove, monitor, limit, disclose, and stop.
Common Thread Across the 12 Signals
The common thread across all twelve signals is simple: AI is entering the control layer.
It is shaping access, dependency, identity, transactions, public trust, institutional resilience, evidence generation, verification, and the conditions under which people and institutions act.
The shift is subtle because it rarely arrives as one dramatic event. It arrives through helpful systems. A model improves productivity. An agent monitors information. A tool drafts documentation. A vendor enables workflow automation. A health system scales AI scribes. A financial platform enables agent transactions. A regulator creates a certification path. A government explores digital identity for agents. A newsroom uses AI to find leads. A university adopts AI for teaching and research. A board receives AI-generated summaries.
The institution saves time. The institution gains capacity. The institution accelerates.
Then, gradually, dependence grows.
That is the control-layer moment.
It is not enough to ask whether AI is useful. It is useful. The question is whether the institution can still explain what AI controls, what AI can access, what AI can execute, what AI has changed, what AI has made dependent, what humans must still verify, who owns the outcome, and who can stop the system.
That is the governance test now.
The Seba Framework
The 12 Ps of Responsible AI Oversight ©
Issue #75 fits directly into the full Seba 12 Ps framework. The same framework carried through Issues #73 and #74, and Issue #75 activates all twelve Ps because the control layer touches every part of responsible AI oversight.
Purpose — Why is AI being introduced, and what institutional or public purpose does it serve?
Problems — What problem is actually being solved, and is AI the right tool?
Profits — Who benefits from AI-driven productivity, automation, data access, transactions, platform dependency, and infrastructure concentration?
People — How are workers, patients, students, citizens, clinicians, customers, researchers, and vulnerable users affected?
Planet — What infrastructure, compute, energy, cooling, hardware, supply-chain, and data-center demands are created?
Process — What monitoring, testing, logging, escalation, review, rollback, incident response, and learning systems exist?
Policy — What laws, rules, standards, contracts, procurement requirements, certifications, and institutional policies govern the use case?
Protections — What safeguards exist for vulnerable users, high-risk use cases, sensitive data, consequential decisions, and agentic actions?
Privacy — What data can the AI access, infer, retain, expose, transfer, combine, or act upon?
Provenance — Can the institution trace model outputs, data sources, evidence, citations, agent actions, tool calls, transactions, and decisions?
Preparedness — Are leaders, boards, employees, clinicians, educators, researchers, and public officials ready to govern AI dependency?
Product Ownership — Who owns the outcome when AI advises, writes, acts, authenticates, transacts, monitors, recommends, or changes the workflow?
All twelve Ps are active in Issue #75, but six stand out.
Policy is active because law, regulations, certification and audit requirements, procurement rules, export controls, and institutional policies increasingly shape the control layer.
Process is active because control requires more than intent. It requires monitoring, logging, verification, incident response, access review, cost review, and stop authority.
Privacy is active because agents and AI-enabled workflows may move sensitive data across systems faster than traditional controls were designed to manage.
Provenance is active because institutions need to know what AI generated, what evidence was used, what source material was summarized, what agent acted, and what human approved.
Preparedness is active because boards and leaders need enough AI fluency to distinguish capability from control, access from ownership, and use from dependency.
Product Ownership is active because vendors may provide the system, but institutions own the context in which that system acts.
Issue #75 ultimately comes down to this point: the control layer is where the 12 Ps stop being a framework on paper and become a governance operating system.
Applied Use Case
The Institution That Becomes Dependent
Imagine an institution beginning to use AI to improve operations.
At first, the use cases appear separate. Communications uses AI to summarize public comments. Legal uses AI to review contracts. Clinical teams use AI to draft notes. Compliance uses AI to monitor policies. Research teams use AI to synthesize literature. Finance uses AI to model risk. Cybersecurity uses AI to detect anomalies. Student services uses AI to answer questions. Executives use AI to prepare board materials.
Every use case seems reasonable. Every team saves time. Every team says the same thing: this is only assistance.
Then the workflows mature. The AI tool connects to internal systems. The assistant gains access to documents. The agent begins monitoring external sources. The tool drafts recommendations. The system initiates workflows. The vendor becomes embedded in the operating model.
Eventually, the institution realizes that AI is not only assisting. It is enabling institutional capacity.
People depend on it. Processes depend on it. Reports depend on it. Timelines depend on it. Service levels depend on it. Compliance may depend on it. Cybersecurity may depend on it. Patient experience may depend on it. Board materials may depend on it.
At that point, the governance question is no longer adoption. It is a dependency.
The institution must ask:
- What systems are we dependent on?
- Which teams depend on them?
- Which decisions depend on them?
- Which external providers control access?
- What data flows through them?
- What authority has been delegated?
- Which outputs are verified?
- Which actions are logged?
- Which workflows are reversible?
- What costs scale with usage?
- What happens if the system is unavailable?
- What happens if the provider changes terms?
- What happens if access is restricted?
- Who owns the outcome?
- Who can stop the system?
This is where AI Minimum Viable Governance becomes practical. Before AI becomes part of the control layer, institutions need a minimum defensible governance floor: a named owner, defined purpose, system inventory, dependency map, access map, data-flow map, delegation limit, identity rule, verification process, cost review, provenance record, privacy review, third-party review, continuity plan, rollback process, escalation pathway, and stop authority.
That is the difference between saying, “We use AI across the organization,” and being able to say, “We know where AI is embedded, what it can access, what it can execute, who owns the outcome, what happens if access changes, how risks are monitored, and who can stop it.” That is AI MVG in practice.
Board-Ready Next Step
Require an AI Access, Authority, and Dependency Sheet
Before scaling AI systems that support institutional operations, influence decisions, connect to internal systems, execute transactions, monitor external information, assist clinical work, support public services, or act through agents, a one-page AI Access, Authority, and Dependency Sheet is required.
It should be short, practical, owner-based, board-reviewable, updated after deployment, connected to the stop authority, and grounded in human impact, not only technical performance.
At a minimum, it should answer twelve questions.
1. What is the AI system? Name the tool, vendor, model, agent, workflow, owner, deployment environment, and affected unit.
2. What institutional function does it support? Define whether it supports operations, policy, research, clinical work, education, finance, compliance, communications, cybersecurity, public service, or executive decision-making.
3. What problem is it solving? Define the problem clearly. Avoid vague claims such as productivity, transformation, modernization, innovation, or efficiency.
4. What can it access? Identify data, files, systems, records, messages, code, APIs, financial accounts, patient information, student records, customer data, public records, third-party applications, and external sources.
5. What can it do? Summarize, draft, classify, monitor, recommend, prioritize, route, authenticate, transact, update records, trigger workflows, generate reports, or act through tools.
6. What authority has been delegated? Read only. Draft only. Recommend. Prepare. Monitor. Route. Execute with approval. Execute within limits. Execute autonomously.
7. What identity does it use? Does the system act under a human user account, a service account, a vendor account, an agent identity, or an authenticated institutional identity?
8. What must be verified by a human? Facts, sources, legal claims, clinical claims, financial claims, policy claims, scientific claims, recommendations, transactions, and actions.
9. What is logged? Inputs, outputs, prompts, model versions, sources, tool calls, approvals, overrides, edits, errors, agent actions, transactions, escalations, and final decisions.
10. What dependency is created? What work stops, slows, degrades, becomes more expensive, or becomes unsafe if access changes, the model changes, costs rise, or the vendor becomes unavailable?
11. Who is affected? Workers, patients, clinicians, students, customers, citizens, researchers, public-service recipients, vulnerable users, communities, or the broader institution.
12. Who can stop it? Name the role. Not the committee. Not the vendor. Not “IT.” Not “leadership.” The role.
That document transforms AI dependency from an invisible operating condition into an accountable institutional practice.
Published Book Update
My new book, Ungoverned: A Practical Guide to AI Minimum Viable Governance, is available now.
Issue #75 is exactly why I wrote it. AI governance is often discussed as if institutions must choose between two extremes: move fast and accept the risk, or wait until governance is perfect. I do not think either path is sufficient.
The practical path is AI Minimum Viable Governance: enough structure to prevent irresponsible normalization, enough clarity to assign ownership, enough evidence to support deployment, enough humility to acknowledge uncertainty, enough authority to pause or stop use when conditions change, and enough discipline to manage dependencies before they become invisible.
This week’s signals make that path more urgent. AI is entering the control layer. It is shaping access, authority, identity, dependency, certification, financial transactions, healthcare operations, policy enforcement, scientific discovery, public trust, and institutional resilience.
That means governance cannot remain abstract. It must become operational. That is the work of Ungoverned.
What I Am Watching This Week
- Whether frontier model access restrictions become a recurring institutional continuity risk.
- Whether governments begin treating AI agent identity as part of the digital public infrastructure.
- Whether financial institutions move from human-directed automation to agentic transaction governance.
- Whether healthcare AI certification becomes a mainstream board-level readiness question.
- Whether health systems can distinguish AI return on investment (ROI) from AI enthusiasm.
- Whether AI-mediated knowledge systems strengthen discovery while preserving provenance, human understanding, and verification.
- Whether copyright litigation forces clearer governance over training data, licensing, attribution, and AI-generated outputs.
- Whether prediction markets influence how boards think about expertise, forecasting, and signal quality.
- Whether public-sector AI deployments create stronger standards for evidence, auditability, and public accountability.
- Whether privacy governance evolves fast enough for non-human actors, autonomous workflows, and data moving at machine speed.
- Whether AI governance talent, certification, and independent verification become institutional necessities rather than niche expertise.
- Whether AI MVG becomes part of organizational culture rather than only a policy artifact.
The organizations that lead will not be the ones that delegate the most authority to AI. They will be the ones who know what authority has been delegated, what dependencies have been created, who verifies the system, who owns the outcome, and who can stop the system when control becomes unclear.
Final Thought
The defining governance question of the next decade may not be whether AI becomes more capable. It almost certainly will. The harder question is whether institutions can recognize when useful AI systems begin to control the conditions under which they operate.
The transition will be gradual. A tool becomes a workflow. A workflow becomes a dependency. A dependency becomes infrastructure. Infrastructure shapes decisions. Decisions shape authority. Authority becomes control. By the time control is obvious, governance is harder.
That is why AI Minimum Viable Governance matters. Not because institutions should avoid AI, but because they should understand when usefulness becomes dependency. Capability creates possibility. Access creates leverage. Dependency creates risk. Governance creates legitimacy.
The organizations that lead will not be those that adopt AI the fastest. They will be those who understand where AI shapes access, authority, evidence, identity, transactions, and institutional dependency. They will know what can be trusted, what must be verified, what can be stopped, and who owns the outcome.
AI can support control. It cannot take responsibility. That responsibility remains human. That is the work of AI Minimum Viable Governance. That is the work of Ungoverned. And that is the work this newsletter will continue to support.
About the Author
Dr. Freddie Seba is the author of Ungoverned: A Practical Guide to AI Minimum Viable Governance — the compact framework for boards, trustees, and executives who cannot wait for the perfect policy.
A scholar-operator, Silicon Valley founder, and global executive — EdD USF · MBA Yale · MA Stanford — he translates fast-moving AI developments into practical governance frameworks leaders can deploy now — across healthcare, financial services, higher education, and regulated industries. Non-vendor. Non-partisan. Doctoral research — not advocacy or product placement.
Keynote Speaker · Workshop Facilitator · Panel Moderator
MIT Critical Data · UC Berkeley · Porto Business School · AMIA · AAC&U · English & Spanish.
Unregulated book on Amazon. Book a keynote or workshop: contact@freddieseba.com
Gratitude + Mentions
Special appreciation to the readers, practitioners, board members, faculty, students, institutional leaders, podcast guests, and governance communities who continue to shape this work.
Special appreciation as well to the communities and institutions advancing responsible AI governance, health informatics, trustworthy implementation, human-centered AI, workforce transition, cyber preparedness, education, public-sector accountability, financial discipline, clinical oversight, scientific integrity, privacy, and practical AI oversight.
References to organizations, tools, companies, articles, papers, or events are included for commentary and analysis and do not imply endorsement or affiliation unless explicitly stated.
Transparency + Disclaimer
Educational content only. This newsletter does not constitute legal, medical, clinical, insurance, financial, investment, cybersecurity, regulatory, labor, procurement, or professional advice.
Drafted and refined with AI-assisted tools for synthesis and clarity. Final editorial control and responsibility remain with the author.
© 2026 Freddie Seba. All rights reserved.
The Seba 12 Ps of Responsible AI Oversight © and AI Minimum Viable Governance are author-developed governance frameworks used for educational, board-readiness, and leadership-development purposes.
Hashtags
#AIGovernance #ResponsibleAI #BoardOversight #AILeadership #AIEthics #AIMinimumViableGovernance #Ungoverned #AgenticAI #FrontierAI #AIInfrastructure #HealthAI #ClinicalAI #DigitalHealth #AIWorkforce #FutureOfWork #AIInEducation #AIInScience #PublicSectorAI #Cybersecurity #AIProvenance #TrustworthyAI #HumanCenteredAI #HumanJudgment #GovernanceAsCompetitiveAdvantage
Selected References Reviewed This Week
APA-style source list. Links are provided for reader review and context. Inclusion does not imply endorsement.
Book and Governance Context
Seba, F. (2026). Ungoverned: A Practical Guide to AI Minimum Viable Governance. Amazon.
Center for the Governance of AI. (2026). GovAI Annual Report 2025.
https://cdn.governance.ai/GovAI_Annual_Report_2025.pdf
Frontier AI, Access, and Control
Anthropic. (2026). Statement on the US government directive to suspend access to Fable 5 and Mythos 5.
https://www.anthropic.com/news/fable-mythos-access
Anthropic. (2026). Claude Fable 5 and Mythos 5 announcement.
https://www.anthropic.com/news/claude-fable-5-mythos-5
Anthropic. (2026). Results from the first Anthropic Public Record.
https://www.anthropic.com/news/anthropic-public-record
Europe 2031. (2026). Europe 2031: What getting AI wrong means for us.
European Commission. (2026). Strengthening Europe’s Tech Sovereignty.
https://digital-strategy.ec.europa.eu/en/policies/eu-tech-sovereignty
U.S. Congressional Discussion Draft. (2026). Great American Artificial Intelligence Act of 2026.
Discussion draft reviewed.
AI Agents, Identity, Finance, and Payments
The Register. (2026). Estonia intends to recognize AI agents with digital IDs.
Coinbase. (2026). Coinbase for Agents.
https://www.coinbase.com/blog/coinbase-for-agents
Coinbase Developer Platform. (2026). Agentic Wallet.
https://docs.cdp.coinbase.com/agentic-wallet/welcome
New York State Department of Financial Services. (2026). DFS builds on a stablecoin framework in the new proposed regulation.
https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20260609
Health AI, Certification, ROI, and Privacy
Joint Commission. (2026). Responsible Use of AI in Healthcare certification.
https://www.jointcommission.org/en-us/certification/responsible-use-of-ai-in-healthcare
Coalition for Health AI. (2026). AI Governance Playbooks and AI Governance Workgroup.
https://www.chai.org/workgroup/cross-cutting/ai-governance
NEJM AI. (2026). Artificial Intelligence as a Return on Investment Multiplier in Health Care.
https://ai.nejm.org/doi/full/10.1056/AIpc2600139
Becker’s Hospital Review. (2026). Health systems race to rein in AI costs.
The Markup. (2026). Your medical provider might be recording your mental health care visits.
Evidence, Science, Knowledge, and Public Trust
Boston Review. (2026). Knowledge Collapse.
https://www.bostonreview.net/articles/knowledge-collapse
Nature. (2026). AI is taking on antibiotic resistance — here’s how.
https://www.nature.com/articles/d41586-026-01818-9
Generative AI in the Newsroom. (2026). How Generative AI Helped Two Newsrooms with Story Discovery.
OpenAI Alignment. (2026). Reinforcement learning towards broadly and persistently beneficial models.
https://alignment.openai.com/beneficial-rl
Center for AI Safety. (2026). AI Values Dashboard.
Copyright, Prediction Markets, and Institutional Decision-Making
Information is Beautiful / David McCandless. (2026). Who’s Suing Whom in AI? Notable copyright infringement cases.
Source visual reviewed.
Gómez-Cram, R., Guo, Y., Jensen, T. I., & Kung, H. (2026). Prediction Market Accuracy: Crowd Wisdom or Informed Minority? Working paper.
Yale Insights. (2026). Wisdom of the few: Prediction markets are driven by a small number of skilled traders.
Associated Press. (2026). Publisher and author coverage related to AI copyright litigation.
Enforcement, Privacy, Public Sector, and Cyber Governance
European Parliament. (2026). AI Act: EP approves simplification measures and a ban on “nudifier” apps.
World Economic Forum. (2026). How to update data privacy tools to cut cybersecurity risk in the AI era.
https://www.weforum.org/stories/2026/06/update-data-privacy-tools-cybersecurity-risk-ai-era
GOV.UK. (2026). PoliceAI to speed up investigations and fight crime.
https://www.gov.uk/government/news/policeai-to-speed-up-investigations-and-fight-crime
National Law Review. (2026). When your productivity tools become a regulatory problem: Shadow AI and GLBA.
Additional professional commentary, LinkedIn posts, sector newsletters, research papers, and shared articles were reviewed for trend awareness and contextual signals.
