As AI writes code, reshapes work, enters health data ecosystems, powers agents, supports public infrastructure, and changes institutional workflows, leaders need more than enthusiasm for AI. They need minimum defensible governance.
Ungoverned: AI Ethics & Governance for Leaders, Boards & Trustees Newsletter
By Dr. Freddie Seba
© 2026 Freddie Seba. All rights reserved.
Editorial Note
Issue #73 begins with a simple observation:
AI is moving from a tool to an operating infrastructure.
That shift is becoming harder to miss.
This week’s signals point in the same direction. AI is writing more code, moving deeper into personal computing and enterprise workflows, expanding beyond developers to knowledge workers, entering health coaching and medical-record summaries, reshaping higher education, supporting defense capabilities, and becoming part of the systems through which organizations operate.
The question is no longer only whether AI can assist people.
The harder question is whether institutions should allow AI into the operating layer before ownership, evidence, authority limits, accountability, human impact, monitoring, and stop authority have been clearly defined.
That is where AI Minimum Viable Governance — AI MVG, the central framework in my new book, Ungoverned: A Practical Guide to AI Minimum Viable Governance, becomes practical.
AI MVG is not about slowing innovation. It is about establishing a minimum defensible governance floor before AI becomes a normalized infrastructure. If AI writes code, supports workflows, influences employees, guides students, shapes patient experiences, processes public-sector data, supports defense capabilities, syncs medical records, or acts through agents, governance cannot remain advisory.
It has to become operational.
That is the thread of Issue #73:
AI governance is no longer only about what organizations believe.
It is about what they can prove, monitor, limit, explain, and stop.
From My New Book, Ungoverned
When usefulness becomes dependency
In my new book, Ungoverned: A Practical Guide to AI Minimum Viable Governance, I argue that AI governance failures often begin quietly.
A tool enters through a team. A pilot becomes routine. A vendor feature gets turned on. A model starts writing code. A chatbot begins advising customers. An AI assistant drafts clinical messages. A health app starts summarizing personal medical records. A software agent receives access to internal systems. A public agency becomes dependent on one vendor’s platform. A board hears about AI strategy, but not AI authority.
That is how AI becomes infrastructure before governance catches up.
- Not always through scandal.
- Often through normalization.
This happens not because people are careless. It happens because useful tools become habits, habits become workflows, workflows become dependencies, and dependencies become infrastructure.
AI Minimum Viable Governance is designed for this moment. It asks institutions to establish a minimum defensible governance floor before AI becomes embedded in the operating layer.
That floor includes:
- A named owner
- A clear purpose
- A defined use case
- An authority limit
- An evidence standard
- A data access map
- A human impact assessment
- A monitoring plan
- An escalation path
- A stop authority
- A learning loop
The most important question in Issue #73 is not whether AI is useful.
It is useful. The question is whether institutions know when usefulness has become dependency, when assistance has become authority, and when adoption has become infrastructure.
That is the governance test now.
Market Signal
AI is moving from the application layer to the operating layer.
For years, many leaders thought of AI as a tool: a chatbot, a search assistant, a summarizer, a coding helper, a productivity feature, a clinical support tool, or a customer service interface.
- That is changing.
- The signals this week show AI moving closer to the operating layer of institutions.
For readers whose background is outside computer or data science, by operating layer, I mean the systems, workflows, decisions, software, data flows, platforms, devices, and vendor relationships that make organizations function.
This is a different governance problem.
A tool can be tested. A workflow can be reviewed. A vendor can be evaluated. A model can be benchmarked. But infrastructure does something deeper. Infrastructure shapes behavior at scale. It becomes the default. It becomes a dependency. It becomes difficult to remove. It changes the culture around it.
This is why leaders and boards need a different AI governance lens.
- Not only: Where are we using AI?
- But: Where is AI becoming part of how the institution operates?
AI governance translation: AI infrastructure requires operational controls, not just an acceptable-use policy.
Board/leader move: Require an AI operating-layer inventory that identifies where AI writes, acts, advises, executes, monitors, modifies, recommends, coaches, or becomes embedded in systems of record.
The Ungoverned lesson: If AI becomes infrastructure before governance becomes operational, the institution becomes dependent before it becomes accountable.
This Week’s Governance Lesson
Operating Control is the next phase of AI governance.
The first phase of AI governance was principles:
- Fairness
- Transparency
- Accountability
- Safety
- Privacy
- Human-centered design
- Trustworthiness
Those principles still matter. But they are not enough. The next phase is operating control, which asks:
- What can the system access?
- What can it change?
- What can it execute?
- What must be approved?
- What evidence supports use?
- What is logged?
- What is reversible?
- What is monitored?
- Who owns the outcome?
- Who can stop the system?
This is especially important as AI moves into code, work, education, health, finance, public-sector systems, personal devices, and institutional workflows.
- A principle may say human oversight matters.
- Operating Control asks whether the human has enough time, training, information, authority, and evidence to challenge the system. A principal may say accountability matters.
- Operating Control asks who is accountable when an AI-generated change causes a downstream failure.
- A principle may say transparency matters. Operating Control asks whether the institution can reconstruct what happened.
That is the shift.
- AI governance cannot remain a statement of values.
- It must become a system of institutional behavior.
AI governance translation: Principles define intent. Controls define reality.
Board/leader move: For every consequential AI use case, ask whether governance exists at the point of use, not only in the policy document.
The Ungoverned lesson: Governance becomes real when it changes what the system is allowed to do.
Executive Reflection
Human judgment remains a scarce leadership capability.
This week’s signals also point to a deeper leadership question.
As AI becomes more capable, what becomes more important for humans? The answer is not less judgment. It is a better judgment.
Lisa Su’s MIT commencement remarks fit this issue well. She reminded graduates that technology itself does not decide what the future looks like; people do. MIT News also summarized her message as urging graduates to be ambitious about the problems they choose to solve. (MIT News)
That is exactly the leadership challenge of the AI era.
- AI can generate.
- AI can summarize.
- AI can code.
- AI can simulate.
- AI can recommend.
- AI can coach.
- AI can search across records.
- AI can accelerate analysis.
- AI can help build systems.
But AI cannot replace institutional responsibility.
Leaders still have to decide:
- Which problems are worth solving?
- Which risks are acceptable?
- Which values should guide tradeoffs?
- Which communities may be harmed?
- Which claims deserve evidence?
- Which systems should not be deployed?
- Which uses should be paused?
- Which benefits are worth pursuing?
- Which people need protection?
- Which dependencies are too dangerous to normalize?
This is why AI governance is not only a technical function.
It is a leadership discipline. The more AI can do, the more important human judgment becomes. Not judgment as instinct alone.
Judgment informed by evidence, context, humility, ethics, domain expertise, operational knowledge, and accountability.
That is the kind of judgment AI MVG is designed to support.
AI governance translation: Human judgment is not replaced by AI capability. It becomes more consequential because AI capability expands the range of institutional action.
Board/leader move: Require leaders to explain not only what AI can do, but why the organization should use it, under what conditions, and with what accountability.
The Ungoverned lesson: AI can accelerate work. It cannot own the moral and institutional responsibility for that work.
What We Are Seeing: Signals
1. Swiss Science Council — AI in higher education now requires system-level governance
The Swiss Science Council’s working paper on AI in Higher Education is one of the most directly relevant sources for this issue.
The paper argues that generative AI is rapidly entering core academic functions — teaching, assessment, student support, research workflows, and institutional management — faster than governance frameworks, evidence bases, and institutional capacities can adapt. It identifies a governance gap across three areas: context, lifecycle, and coordination.
That matters because higher education is not only using AI. It is also studying, developing, testing, legitimizing, and preparing people for AI.
The Swiss Science Council distinguishes among three different categories:
- Education for AI — AI literacy, critical understanding, and professional competence
- AI for Education — tutoring, feedback, assessment support, analytics, and decision support
- Operational AI use — AI in administration, quality assurance, institutional management, and workflows
Those are not the same use case. They have different purposes, risks, evidence, and governance requirements. The working paper recommends a national reference framework for AI governance in higher education, differentiated sandbox models, expert groups, and education-specific data access and data spaces.
AI governance translation: Higher education cannot treat AI as a single category.
Board/leader move: Require institutional AI governance to distinguish education for AI, AI for education, and operational AI use, with different lifecycle, evidence, privacy, and oversight requirements.
The Ungoverned lesson: A university cannot treat classroom experimentation, student assessment, AI literacy, institutional analytics, and administrative automation as the same governance problem.
2. OpenAI — Codex is moving from a developer tool to a knowledge-work infrastructure
OpenAI says more than 5 million people now use Codex every week. It also says non-developers — including analysts, marketers, operators, designers, researchers, investors, and bankers — now make up about 20% of Codex users overall and are growing at more than three times the rate of developers. (OpenAI)
For readers whose background is outside computer or data science, Codex is an AI software engineering agent. That means it can help write software, fix bugs, answer questions about a codebase, and propose changes for human review. A few useful terms to keep in mind:
- A codebase is the collection of files, instructions, libraries, tests, and documentation that make software work.
- A pull request is a proposed software change that a developer or team reviews before merging it into the main code.
- A cloud sandbox is a controlled environment where the AI can work on a task without directly touching the live production system.
Why does this matter? Because Codex is no longer just a coding assistant for engineers, OpenAI is positioning it as a productivity tool across many roles and workflows. That means nontechnical teams may increasingly use AI to create dashboards, draft internal tools, analyze data, prepare materials, or automate workflows.
Once AI can create or modify internal tools, it is no longer just producing text. It is shaping work.
The governance question becomes:
- Who approved this internal tool?
- What data does it use?
- Who verifies the output?
- What errors could it introduce?
- Does it create a new shadow system?
- Can others rely on it without knowing how it was built?
- Who owns it after the first version is generated?
AI governance translation: AI-generated work artifacts can become operational systems.
Board/leader move: Require AI-generated internal tools, dashboards, code, and workflow automations to have named ownership, review, documentation, lifecycle monitoring, and decommissioning rules.
The Ungoverned lesson: If AI builds the tool, the institution still owns the consequences.
3. Qwen / Alibaba — Qwen 3.7 signals that the global model race is becoming agentic
Qwen 3.7 is not simply another model release.
Qwen is Alibaba’s large language model family, and the new Qwen 3.7 materials position it around the “agent frontier.” Alibaba’s Qwen work matters because it shows that advanced AI model development is not limited to U.S. frontier labs. (Qwen Studio)
For readers whose background is outside computer or data science, a large language model is an AI system trained to generate text, code, analysis, reasoning, and other outputs. An agentic model is increasingly designed not only to answer questions but also to take steps, use tools, pursue goals, and interact with systems. That shift matters for boards. Model selection is no longer only a technology decision. It is also a governance decision.
Leaders should ask:
- Which company provides the model?
- Which jurisdiction governs the provider?
- What are the data-handling terms?
- Is the model open, closed, hosted, or portable?
- What evidence supports its use?
- What happens when the model changes?
- What happens if access changes?
- Can the institution audit, explain, or exit?
AI governance translation: The model race is becoming a vendor, jurisdiction, and dependency-risk race.
Board/leader move: Require model provenance review before consequential use: provider, jurisdiction, data terms, access model, evaluation evidence, update cadence, and exit options.
The Ungoverned lesson: A powerful model is not automatically a governable model.
4. Google Health — AI is moving closer to personal medical data
Google announced that Google Health Coach is becoming available through Google Health Premium. The company describes it as built with Gemini and positioned as a personalized fitness, sleep, and health advisor. Google says the coach can integrate fitness and sleep metrics, nutrition and cycle tracking, environmental context, and personal medical records. (blog.google)
Google also introduced the Google Health app, which allows U.S. users to sync their medical records, including lab results, vital signs, and medications. Google says records are securely stored in the app and that users control how data is used, shared, or deleted. (blog.google)
This is an important governance signal. AI health tools are moving closer to:
- Personal medical records
- Lab results
- Medications
- Vitals
- Sleep data
- Fitness data
- Nutrition data
- Behavioral nudges
- Personalized summaries
- Patient-facing interpretation
That is not only wellness. It is health-adjacent decision support. Even when a company states that features are not intended for medical purposes, the user experience may still shape health behavior, understanding, trust, and escalation decisions. Google’s own notes state that the features are not intended for medical purposes and that users should verify responses for accuracy. (blog.google)
AI governance translation: Patient-facing and consumer health AI require governance even when framed as wellness tools.
Board/leader move: Review health AI tools for consent, privacy, accuracy, escalation, accessibility, protections for vulnerable users, clinical claims, and data-sharing boundaries.
The Ungoverned lesson: When AI sits between people and their health data, governance cannot rely only on product disclaimers.
5. Anthropic — Recursive self-improvement is becoming a governance warning
Anthropic’s “When AI builds itself” article is one of the most important frontier-risk signals this week. Recursive self-improvement means AI helps improve AI systems, which then become better at improving future AI systems. Put simply: AI helps build better AI.
Anthropic is careful that full recursive self-improvement has not arrived and is not inevitable. But the company argues that AI is already accelerating AI development and that, if systems can eventually build their own successors, the ways we secure, monitor, and shape their behavior become much more important. (Anthropic)
This matters beyond frontier labs.
Every organization using AI coding assistants, AI workflow builders, AI agents, or AI-generated automation faces a smaller version of the same question:
If AI can modify the system, who governs the modification?
AI governance translation: Self-improving and AI-modified workflows require change-control governance.
Board/leader move: Require versioning, testing, approval, rollback, audit trails, and ownership for AI-generated code, agent instructions, prompts, workflows, and tool integrations.
The Ungoverned lesson: If the system can change the workflow, governance must cover the change.
6. TechCrunch / NVIDIA — AI-agent computing moves governance closer to the endpoint
TechCrunch reported that NVIDIA is pursuing AI-agent PCs with Microsoft, Dell, HP, Lenovo, ASUS, and others, and that NVIDIA’s RTX Spark Windows PCs are designed to run AI agents securely, with secure sandboxes and enough local compute to run versions of large language models. (TechCrunch)
For readers whose background is outside computer or data science, by endpoint, I mean a device where work happens: a laptop, desktop, phone, tablet, workstation, or local computer.
An AI-agent PC is a device designed to run AI agents locally, not only through cloud-based systems. Why does this matter? Because governance is no longer only about cloud AI platforms.
It is also about what agents can do on devices connected to:
- Files
- Calendars
- Enterprise systems
- Code repositories
- Design tools
- Customer records
- Internal knowledge
- Health data
- Student data
- Financial workflows
The governance questions become immediate:
- What can the agent access locally?
- Can it read files?
- Can it send messages?
- Can it change settings?
- Can it execute code?
- Can it connect to workplace tools?
- Can it act without approval?
- What is logged?
- Who can turn it off?
AI governance translation:
When agents move closer to the device layer, governance must move closer to the point of action.
Board/leader move: Update device management, cybersecurity, identity, access control, logging, and acceptable-use policies for AI agents operating on employee devices.
The Ungoverned lesson: The closer AI gets to the operating layer, the less sufficient the high-level policy becomes.
7. Yale Insights — AI market booms require discipline, not simplistic bubble narratives
An article in Yale Insights, the Yale School of Management’s research magazine, summarizes work by William Goetzmann and co-authors examining stock market booms, crashes, and bubbles in U.S. market history from 1792 to 2024. The piece emphasizes that long historical time series can help test whether apparent booms are truly bubble-like patterns or more complex market phenomena. (Yale Insights)
This belongs in Issue #73 because AI is not only a technology story.
It is also a capital allocation story. AI infrastructure, models, chips, data centers, cloud platforms, agents, clinical AI, and enterprise software all require major investment. Some companies will create durable value. Some will overpromise. Some valuations will compress. Some narratives will fail.
But the governance lesson is not simply to declare:
AI is a bubble. Or: AI is not a bubble. The better leadership question is:
What evidence supports the investment, deployment, or dependency decision?
For boards and leaders, the issue is not only market timing. It is a governance discipline.
- Are we investing because the use case creates measurable value?
- Are we adopting the tool because it solves a real problem?
- Are we depending on a vendor because the infrastructure is resilient?
- Are we measuring productivity, quality, risk, and human impact?
- Are we confusing valuation momentum with institutional readiness?
AI governance translation: AI hype and AI value are not the same thing. Market enthusiasm must be separated from operational evidence.
Board/leader move: Require AI investment and deployment proposals to include use-case evidence, risk-adjusted value, vendor dependency review, cost exposure, implementation burden, and exit options.
The Ungoverned lesson: Governance is the discipline that keeps institutions from mistaking momentum for proof.
8. Lambert and Schindler — Workforce disruption is also apprenticeship disruption
The working paper “The Broken Ladder: AI, Remote Work, and Early-Career Hiring” complicates the simple story that AI alone is replacing junior workers.
The authors argue that exposure to generative AI is strongly correlated with another major post-pandemic shift: working from home. In plain language, some jobs that appear vulnerable to AI may also be jobs in which remote work has changed how firms hire, train, supervise, and evaluate early-career workers. (SSRN)
That matters. The early-career ladder depends on more than tasks.
It depends on mentoring, apprenticeship, feedback, observation, informal learning, trust-building, and opportunities to do lower-risk work while developing judgment. If remote work weakened apprenticeship pathways and AI automates or compresses junior tasks, the labor-market problem is not only job replacement. It is career formation.
The governance question becomes: How do institutions preserve the pathway into expertise when AI changes entry-level work?
AI governance translation: AI workforce governance must distinguish automation risk from apprenticeship collapse.
Board/leader move:
Require AI workforce impact reviews to include early-career hiring, training, mentorship, supervision, promotion pathways, and skills development.
The Ungoverned lesson: Responsible AI adoption must protect not only today’s productivity, but tomorrow’s human capability.
9. Utah clinical AI sandbox and The Lancet Digital Health — Health AI needs independent oversight and meaningful fairness
Utah’s first-in-the-nation AI prescription-renewal pilot shows why health AI governance needs oversight before scale. The University of Illinois College of Law summarized the pilot as allowing AI to renew certain prescriptions for chronic conditions under a special state sandbox, while also noting serious questions about efficacy and legality. (College of Law)
A sandbox is a controlled environment where a new technology can be tested under defined rules, oversight, monitoring, and limits before wider deployment.
That matters because prescription renewal is not just an administrative task. It is connected to clinical judgment, patient safety, medication management, chronic disease care, liability, and trust. The fairness question is also becoming more difficult. The Lancet Digital Health scoping review on fairness metrics for clinical AI highlights that the field still lacks clarity about what fairness means, how it should be measured, and how fairness metrics connect to clinical impact. (The Lancet)
A fairness metric is a way of measuring whether a model performs differently across groups, such as by age, sex, race, language, geography, income, disability, or other sensitive attributes.
But fairness cannot be reduced to one checkbox.
- A model can appear fair under one metric and unfair under another.
- A model can perform well on average and still fail specific groups.
- A model can be technically balanced but clinically harmful.
AI governance translation: Clinical AI governance requires evidence, independent oversight, patient protection, and meaningful fairness in the clinical context.
Board/leader move: Require health AI pilots to include oversight structures, evidence standards, patient protections, clinician accountability, escalation pathways, fairness metrics, and post-deployment monitoring.
The Ungoverned lesson: A clinical AI system is not ready because it is only working in a demo. It is ready only when governance is ready for real-world use.
10. MIT AI Risk Repository — AI risk needs a shared language
The MIT AI Risk Initiative says its work provides authoritative data and frameworks to help identify, prioritize, and manage AI risks. Its AI Risk Repository and related tools organize risks, incidents, governance materials, and frameworks, enabling leaders to compare and prioritize risks more consistently. (MIT AI Risk Initiative)
That matters because one of the biggest problems in AI governance is the language used. Different organizations use different categories. Different teams define risk differently. Different sectors prioritize different consequences.
Even the term AI safety can mean very different things:
- Bias
- Misinformation
- Cybersecurity
- Model failure
- Human dependence
- Loss of Control
- Privacy exposure
- Workforce disruption
- Public-sector accountability
- High-stakes decision error
Shared risk language helps institutions ask better questions.
AI governance translation: Risk taxonomy is not academic housekeeping. It is the foundation for consistent oversight.
Board/leader move: Adopt a risk taxonomy that can be used across product, legal, compliance, cybersecurity, HR, procurement, clinical, education, and board reporting.
The Ungoverned lesson: You cannot manage AI risk if every team defines risk differently.
11. Alan Turing Institute — Defense AI makes resilience part of AI governance
The Alan Turing Institute’s report, Resilient Defense AI: Sustainable and Operationally Effective Capabilities by Design, argues that defense AI must be designed for long-term viability, cost-effectiveness, supply security, resource sustainability, and operational effectiveness. The report emphasizes that resource consumption and cooling requirements must be managed from conception through deployment, and that resilience and sustainability need to be integrated throughout AI capability development and assurance processes. (The Alan Turing Institute)
This belongs in a broader AI governance because defense AI makes visible a truth that applies beyond defense: AI infrastructure is not only digital.
It depends on:
- Compute
- Energy
- Cooling
- Supply chains
- Hardware
- Data centers
- Environmental constraints
- Security of supply
- Operational resilience
- Contingency planning
That is an operating-layer issue. It also activates the Planet and Preparedness dimensions of the Seba 12 Ps.
AI governance translation: AI resilience is not only about cybersecurity. It is infrastructure, energy, supply chain, sustainability, and operational continuity.
Board/leader move: Ask whether critical AI systems depend on fragile compute, energy, cloud, chip, cooling, vendor, or geopolitical supply chains.
The Ungoverned lesson: An AI system is not governable if the institution does not understand the infrastructure that sustains it.
12. McKinsey — AI transformation is organizational redesign, not tool adoption
McKinsey, the global management consultancy, argues that companies truly innovating with AI are not merely adding tools. They are reshaping products, services, core business processes, and organizational systems. The article also emphasizes that every technology and AI transformation is a people transformation. (McKinsey & Company)
That is consistent with the core argument of this newsletter. AI adoption is not a transformation. AI transformation requires redesigning:
- Decision rights
- Workflows
- Data systems
- Talent models
- Operating rhythms
- Risk controls
- Governance structures
- Vendor dependencies
- Measurement systems
- Human accountability
That is exactly why governance must move with the transformation. If AI transformation reshapes core business processes and organizational systems, AI governance cannot sit outside it. It has to be part of the operating model.
AI governance translation: AI transformation without governance transformation creates operating debt.
Board/leader move: Ask management to show not only the AI roadmap, but the governance redesign: owners, controls, risk tiers, evidence standards, monitoring, workforce impact, and escalation.
The Ungoverned lesson: The organization is not transformed by adopting AI. It is transformed when it can govern what AI changes.
The Seba Framework
The 12 Ps of Responsible AI Oversight ©
Issue #73 fits clearly into the full Seba 12 Ps framework:
- Purpose — Why is AI being introduced? Is it solving a meaningful problem or merely accelerating adoption?
- Problems — What problem is actually being solved, and is AI the right tool?
- Profits — Who benefits from AI-driven productivity, automation, infrastructure dependency, and cost reduction?
- People — How are workers, students, patients, citizens, customers, clinicians, developers, and vulnerable users affected?
- Planet — What infrastructure, energy, hardware, cooling, supply-chain, and data-center demands are created by AI scaling?
- Process — What monitoring, testing, escalation, rollback, and learning loops exist?
- Policy — What rules govern AI access, use, disclosure, procurement, evidence, and authority?
- Protections — What safeguards are in place for vulnerable users, early-career workers, patients, students, and the public?
- Privacy — What data can AI systems access, infer, retain, expose, or transfer?
- Provenance — Can the institution trace model outputs, AI-generated code, data sources, tool use, and decision pathways?
- Preparedness — Are leaders, boards, employees, clinicians, educators, and public officials ready to govern AI?
- Product Ownership — Who owns the outcome when AI writes, advises, teaches, coaches, acts, or changes the workflow?
These Ps feel especially active in Issue #73
- Purpose: Because AI adoption must be tied to real problems, not trend pressure.
- People: Because AI affects early-career workers, students, patients, employees, users, citizens, clinicians, educators, and vulnerable communities.
- Profits: Because AI is attracting major capital, valuation attention, productivity claims, and cost pressures that require evidence, not only momentum.
- Planet: Because AI infrastructure now depends on compute, energy, cooling, hardware, supply chains, and long-term sustainability.
- Process: Because AI-generated code, agents, clinical tools, health apps, education platforms, public-sector systems, and defense capabilities require monitoring, escalation, lifecycle governance, and change control.
- Policy: Because AI governance is becoming a global operating environment across higher education, health, defense, public services, financial services, consumer technology, and enterprise software.
- Protections are needed due to dark patterns, patient-facing AI, clinical fairness gaps, student data, public-sector dependency, and workforce disruption, all of which can harm vulnerable groups.
- Privacy: Because agents, health apps, medical records, higher education systems, public-sector platforms, and workplace AI may touch highly sensitive data.
- Provenance: Because institutions need to know what AI generated, what data shaped it, what source material was used, and what changed downstream.
- Product Ownership: Because vendors may provide tools, but institutions own the context in which those tools operate.
Applied Use Case
The AI Operating Layer
Imagine an organization begins with a few AI tools. The engineering team uses Codex or another code-generation tool to fix bugs and draft pull requests. The operations team uses AI to create dashboards. The marketing team uses AI to generate campaign assets. The HR team uses AI to summarize employee feedback. The finance team uses AI to prepare forecasts. The clinical team uses AI to draft patient messages. The health benefits team encourages employees to use AI-powered wellness coaching. The education team uses AI tutoring tools. The public affairs team uses AI to monitor policy and generate briefings. The cybersecurity team uses AI to detect anomalies.
At first, each use case looks separate. But over time, AI becomes part of the operating layer. It writes software. It shapes reports. It drafts communications. It influences customers. It guides employees. It supports clinical work. It coaches behavior. It teaches students. It summarizes risk. It creates internal tools. It connects to data. It changes workflows.
No one may have formally declared: AI is now infrastructure. But functionally, it is.
The governance questions become urgent:
- Where is AI embedded?
- Which systems depend on it?
- What can it access?
- What can it change?
- What decisions does it influence?
- Who verifies outputs?
- What is logged?
- What happens when the model changes?
- What happens when the vendor changes?
- What happens when AI-generated code fails?
- What happens when a health coach gives unsafe advice?
- What happens when student support tools shape learning pathways?
- What happens when a public-sector platform becomes difficult to exit?
- Who owns the outcome?
- Who can stop the system?
Using the 12 Ps in practice
The framework above provides an overview. This use case shows how the Ps surface the governance work.
- Purpose: Is AI being used to solve real problems, or is adoption pressure high?
- Problems: Are the use cases clearly defined, or are teams using AI wherever it feels convenient?
- Profits: Who captures productivity gains, valuation gains, efficiency gains, and cost savings — and who bears the burden of errors, surveillance, deskilling, dependency, or failed investments?
- People: Which workers, patients, students, customers, citizens, and vulnerable groups are affected?
- Planet: What infrastructure, energy, cooling, data center, and hardware demands are created?
- Process: Are there monitoring, review, testing, escalation, rollback, and incident-learning systems in place?
- Policy: Do policies apply to actual use, or only to formal AI projects?
- Privacy: What data can the AI access, infer, combine, retain, or expose?
- Provenance: Can the institution trace what was AI-generated and what sources shaped the output?
- Product Ownership: Who owns outcomes when AI is embedded across workflows?
The Ungoverned Insight
This is where AI Minimum Viable Governance becomes practical.
Before AI becomes the operating layer, the institution needs a minimum defensible governance floor:
- A named owner for every consequential AI system
- A use-case inventory
- A risk tier
- An access map
- Authority limits
- Evidence standards
- Human review rules
- Vendor dependency review
- Monitoring and logging
- Incident and near-miss reporting
- Change-control governance
- Data and privacy review
- Workforce impact review
- Investment and ROI evidence
- Stop authority
That is the difference between saying: “We are using AI across the organization,” and being able to say: “We know where AI is embedded, what it can access, what it can change, who owns the outcome, what evidence supports use, how risks are monitored, and who can stop it.”
That is AI MVG in practice.
Board-Ready Next Step
Require an AI Operating-Layer Governance Sheet
Before scaling AI across code, workflows, devices, clinical systems, health apps, education, public services, defense-adjacent systems, or enterprise platforms, an AI Operating-Layer Governance Sheet is required.
It should be:
- Short
- Practical
- Named-owner based
- Board-reviewable
- Updated after deployment
- Connected to the stop authority
- Grounded in human impact, not only technical performance
At a minimum, it should answer twelve questions.
1. What is the AI system?
Name the tool, vendor, model, workflow, owner, deployment environment, and affected business unit.
2. What problem is it solving?
Define the problem clearly. Avoid vague claims such as “productivity,” “transformation,” or “innovation.”
3. Is this a tool, workflow, agent, or infrastructure dependency?
Classify whether the system is optional support, an embedded workflow, an autonomous agent, a health or education support tool, or a critical operating-layer dependency.
4. What can it access?
Data, files, code, records, emails, calendars, APIs, patient information, student records, customer data, financial systems, public-sector data, internal knowledge, medical records, or external tools.
5. What can it change?
Code, documents, communications, dashboards, schedules, transactions, recommendations, records, permissions, workflows, or downstream outputs.
6. What authority has been delegated?
- Read only.
- Draft only.
- Recommend.
- Prepare.
- Execute with approval.
- Execute within limits.
- Execute autonomously.
7. What evidence supports use?
Vendor evidence, internal testing, external validation, user testing, clinical validation, fairness review, security testing, ROI evidence, and post-deployment monitoring.
8. What is logged?
Inputs, outputs, model versions, prompts, tool calls, approvals, overrides, edits, failures, escalations, and incidents.
9. What is reversible?
Can the institution roll back code, revoke access, restore records, cancel transactions, correct communications, disable the agent, or return the workflow to a safe state?
10. Who is affected?
Workers, students, patients, clinicians, customers, investors, citizens, vulnerable users, public-service recipients, or the broader community.
11. What human judgment remains required?
Name the role, decision point, evidence needed, and conditions under which the human must intervene.
12. Who can stop it?
- Name the role.
- Not the committee.
- Not the vendor.
- Not “IT.”
- Not “leadership.”
- The role.
That sheet turns AI from an adoption story into an accountable institutional practice.
Published Book Update
My new book, Ungoverned: A Practical Guide to AI Minimum Viable Governance, is available on Amazon. Book link: Ungoverned is available on Amazon. Issue #73 is exactly why I wrote it. AI governance is often presented as if institutions must choose between two extremes:
Move fast and accept the risk.
Or:
Wait until governance is perfect.
I do not think either path is sufficient. The practical path is AI Minimum Viable Governance:
- Enough structure to prevent irresponsible normalization
- Enough clarity to assign ownership
- Enough evidence to support deployment
- Enough humility to admit uncertainty
- Enough authority to pause or stop use when conditions change
- Enough iteration to improve as reality changes
This week’s signals make that path more urgent. AI is not staying at the edge of the organization. It is entering the operating layer. When AI writes code, supports knowledge work, changes workflows, powers agents, influences users, touches clinical systems, syncs medical records, supports education, and becomes part of public infrastructure and governance, governance cannot remain abstract. It must become operational. That is the work of Ungoverned.
What I Am Watching This Week
- Whether AI coding agents force stronger change-control governance.
- Whether recursive self-improvement becomes a mainstream board-level AI risk topic.
- Whether Google Health and other consumer health AI tools accelerate patient-facing AI governance.
- Whether higher education adopts lifecycle governance for AI rather than case-by-case improvisation.
- Whether companies distinguish AI workforce disruption from broader changes in remote work and apprenticeship.
- Whether leaders learn to talk about AI honestly with employees rather than relying on vague reassurance.
- Whether AI-agent PCs accelerate the need for endpoint-level AI governance.
- Whether health AI sandboxes become a model for independent oversight.
- Whether clinical AI fairness moves from fragmented metrics to meaningful patient-centered evaluation.
- Whether public-sector AI dependency becomes a larger governance and sovereignty concern.
- Whether resilient AI infrastructure becomes a board-level risk issue.
- Whether boards begin asking where AI has entered the operating layer.
- Whether AI risk taxonomies become part of everyday governance reporting.
- Whether AI market narratives become more disciplined, distinguishing valuation momentum from operational evidence.
- Whether AI MVG becomes part of organizational culture rather than only a policy artifact.
The organizations that lead will not be the ones that use AI everywhere first. They will be the ones who know where AI has become infrastructure — and have the governance discipline to control, evaluate, monitor, and stop it.
Final Thought
The question is no longer only whether AI can help.
It can. The question is what happens when help becomes habit, habit becomes workflow, workflow becomes dependency, and dependency becomes infrastructure. That is where governance matters most.
An AI tool that summarizes is one thing. Another is an AI tool that writes code. Another is an AI agent that acts across systems. An AI tutor that shapes learning is another. An AI health coach that interprets personal data is another. Another is an AI chatbot that influences behavior. An AI model embedded in clinical workflows is another. An AI platform supporting public infrastructure is another. Another AI market narrative that attracts capital before value is proven.
The common question is: Who governs the operating layer? That is the leadership challenge now. Not simply adopting AI. Governing it before it becomes invisible.
The better path is harder — and more useful:
- Name the system
- Define the purpose
- Map the access
- Set authority limits
- Test the evidence
- Protect the people
- Monitor the workflow
- Review the vendor
- Preserve human judgment
- Log what matters
- Recover when needed
- Stop when necessary
- Learn continuously
AI is becoming infrastructure. Governance must become operating Control. That is the work of AI Minimum Viable Governance. That is the work of Ungoverned. And that is the work this newsletter will continue to support.
About the Author
Dr. Freddie Seba is the author of Ungoverned: A Practical Guide to AI Minimum Viable Governance and an AI governance scholar-operator, global executive, and Silicon Valley founder working at the intersection of AI governance, digital health, highly regulated industries, and mission-driven leadership.
With more than 20 years of experience across banking, fintech, digital health, startups, and higher education, he translates fast-moving AI developments into practical, plain-language governance for leaders, boards, and trustees. He holds an EdD in Organizational Leadership from the University of San Francisco, an MBA from Yale, and an MA in International Policy from Stanford.
Gratitude + Mentions
Special appreciation to the readers, practitioners, board members, faculty, students, institutional leaders, podcast guests, and governance communities who continue to shape this work. Special appreciation as well to the communities and institutions advancing responsible AI governance, health informatics, trustworthy implementation, human-centered AI, workforce transition, cyber preparedness, education, public-sector accountability, financial discipline, and practical oversight.
References to organizations, tools, companies, articles, papers, or events are included for commentary and analysis and do not imply endorsement or affiliation unless explicitly stated.
Transparency + Disclaimer
Educational content only. This newsletter does not constitute legal, medical, clinical, insurance, financial, investment, cybersecurity, regulatory, labor, procurement, or professional advice. Any discussion of AI systems, health AI, enterprise AI, agents, workforce impacts, infrastructure, public-sector systems, market dynamics, valuation, or governance practices is intended for general understanding and should not be used as a substitute for advice from qualified professionals.
Drafted and refined with AI-assisted tools for synthesis and clarity. Final editorial control and responsibility remain with the author.
© 2026 Freddie Seba. All rights reserved.
Hashtags
#AIGovernance #ResponsibleAI #BoardOversight #AILeadership #AIEthics #AIMinimumViableGovernance #Ungoverned #AgenticAI #AIInfrastructure #OperatingControl #HealthAI #ClinicalAI #DigitalHealth #AIWorkforce #FutureOfWork #AIInEducation #PublicSectorAI #Cybersecurity #AIProvenance #TrustworthyAI #HumanCenteredAI #HumanJudgment #GovernanceAsCompetitiveAdvantage
Selected References Reviewed This Week
APA-style source list. Links are provided for reader review and context. Inclusion does not imply endorsement.
Book, governance, and AI MVG context
Seba, F. (2026). Ungoverned: A practical guide to AI Minimum Viable Governance. Amazon.
AI in higher education, learning, and institutional governance
Swiss Science Council. (2026). AI in higher education: SSC considerations and recommendations.
Springer. (2026). Governing generative AI in higher education.
https://link.springer.com/article/10.1186/s41239-026-00602-z
AI agents, coding, and operating infrastructure
OpenAI. (2026). Codex for every role, tool, and workflow.
https://openai.com/index/codex-for-every-role-tool-workflow
OpenAI. (2026). Codex is becoming a productivity tool for everyone.
https://openai.com/index/codex-for-knowledge-work
Anthropic. (2026). When AI builds itself: Our progress toward recursive self-improvement, and its implications.
https://www.anthropic.com/institute/recursive-self-improvement
Qwen. (2026). Qwen3.7: The agent frontier.
https://qwen.ai/blog?id=qwen3.7
Qwen. (2026). Qwen3.7-Plus: Multimodal agent intelligence.
https://qwen.ai/blog?id=qwen3.7-plus
TechCrunch. (2026). NVIDIA chases $200B CPU market with AI agent PCs from Microsoft, Dell, and HP.
TechCrunch. (2026). RSI is the new AGI — and it’s just as hard to pin down.
AI transformation, markets, and organizational redesign
McKinsey & Company. (2026). The AI transformation manifesto.
https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/the-ai-transformation-manifesto
Yale Insights. (2026). Over the very long run, stock bubbles are rare.
https://insights.som.yale.edu/insights/over-the-very-long-run-stock-bubbles-are-rare
Goetzmann, W. N., Tyler, J., & Manninen, O. (2026). Bubbles, booms, and crashes in the U.S. stock market, 1792–2024. NBER.
https://www.nber.org/system/files/working_papers/w34903/w34903.pdf
Business Insider. (2026). Uber’s COO says it’s getting harder to justify the money spent on AI token usage.
https://www.businessinsider.com/uber-coo-andrew-macdonald-ai-token-spending-harder-justify-2026-5
Workforce, leadership, and human judgment
Lambert, P. J., & Schindler, Y. (2026). The broken ladder: AI, remote work, and early-career hiring. SSRN.
https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6787638
MIT News. (2026). Commencement address by Lisa Su’90, SM ’91, PhD’94.
https://news.mit.edu/2026/commencement-address-lisa-su-0528
Health AI, personal health data, clinical oversight, and fairness
Google. (2026). Google Health Coach is now available to Premium users.
https://blog.google/products-and-platforms/products/google-health/google-health-coach
Google. (2026). Introducing the Google Health app.
https://blog.google/products-and-platforms/products/google-health/google-health-app
Coalition for Health AI. (2026). CHAI releases comprehensive governance playbooks to streamline AI implementation for health systems.
University of Illinois College of Law. (2026). Is Utah’s first-in-the-nation pilot program allowing AI to renew prescriptions legal and ethical
The Lancet Digital Health. (2026). Critical appraisal of fairness metrics for artificial intelligence-based clinical prediction models: A scoping review.
https://www.thelancet.com/journals/landig/article/PIIS2589-7500(26)00024-5/fulltext
NEJM AI. (2026). Large language models in informed consent — opportunities, evidence, and challenges.
Defense AI, cyber, infrastructure, and resilience
The Alan Turing Institute. (2026). Resilient Defense AI: Sustainable and operationally effective capabilities by design.
New York State Department of Financial Services. (2026). Heightened cybersecurity risks are associated with frontier AI models.
Anthropic. (2026). Project Glasswing: An initial update.
https://www.anthropic.com/research/glasswing-initial-update
GOV.UK. (2026). UK and Australia pact on fast-moving AI security risks.
https://www.gov.uk/government/news/uk-and-australia-pact-on-fast-moving-ai-security-risks
Australian Cyber Security Center. (2026). Opportunities for AI in cyber defense.
Risk language, policy, and global governance
MIT AI Risk Initiative. (2026). MIT AI Risk Repository.
Slattery, P., Saeri, A. K., Grundy, E. A. C., Graham, J., Noetel, M., Uuk, R., Dao, J., Pour, S., Casper, S., & Thompson, N. (2024). The AI Risk Repository: A comprehensive meta-review, database, and taxonomy of risks from artificial intelligence. arXiv.
https://arxiv.org/abs/2408.12622
OECD.AI. (2026). OECD.AI Policy Navigator.
https://oecd.ai/en/dashboards/overview
OpenAI. (2026). Advancing content provenance for a safer, more transparent AI ecosystem.
https://openai.com/index/advancing-content-provenance
Federal Trade Commission. (2026). FTC to require Cox Media Group, two other firms to pay nearly $1 million to settle charges they deceived customers about “active listening” AI-powered marketing service.
