Thought Leadership

Governing Innovation: Balancing Risk and Breakthrough

Thought Leadership

Governing Innovation: Balancing Risk and Breakthrough

Generative AI has fundamentally changed the innovation conversation.

For years, executives have pushed organisations to innovate faster. Now, generative AI can write, analyse, summarise, code, search, create and increasingly execute tasks. Technologies that once required significant human effort can now be partially or substantially automated across areas such as software development, customer service, legal document review, finance reporting and marketing.

The emergence of AI agents takes this further. Rather than simply answering questions, agents can increasingly perform multi-step tasks and interact with business systems. Google, for example, is developing enterprise agent architectures based around agent identities, access permissions, registries, gateways and auditability.1

This creates a new strategic question for Boards and executives:

How will we use AI, what work should be performed by people, what can be automated, and how should the organisation govern the transition?

The answer is not simply to accelerate innovation or to increase controls. Organisations need controlled acceleration — enabling experimentation while applying progressively stronger governance as uncertainty, autonomy and potential consequences increase.

1. The New Innovation Imperative

Generative AI is compressing innovation cycles.

Previously, automating a repetitive business process might require months of analysis, software development, testing and implementation. Today, an employee can use AI to prototype a solution to a repetitive task in days — sometimes hours.

The problem is that an organisation’s ability to create innovation can now move faster than its ability to govern it.

If governance is too slow, employees may turn to unapproved “shadow AI” tools. If governance is too restrictive, valuable opportunities may never be tested.

The objective should therefore be to control the speed: allow low-risk experimentation while introducing progressively stronger controls as the potential impact increases.

2. Two Levels of Governance: Board and Executive Responsibilities

The Board should not be approving individual AI models or projects. In line with fundamental good governance principles, the Board's role is to establish the strategic and risk boundaries within which management operates.

In relation to AI, the Board should focus on:

  • Strategic direction — What role should AI play in the organisation’s competitiveness?
  • Risk appetite — What level of AI-related risk is acceptable?
  • Capital allocation — How much investment should be directed towards Core, Adjacent and Transformational innovation?
  • Accountability — Who is responsible when AI contributes to a consequential decision?

Executive leadership should then translate these boundaries into an operating system for innovation and establish:

  • An enterprise AI and innovation strategy.
  • AI governance committees or teams.
  • Rules defining which applications require approval.
  • Data, security and privacy controls.
  • Resource and capital allocation processes.
  • Guardrails and development milestones.
  • Monitoring of AI performance against benchmarks set and usage.
  • Human decision and escalation requirements.
  • Clear ownership throughout the AI lifecycle.
  • Processes for stopping initiatives that no longer demonstrate sufficient value or acceptable risk within a specified time period or capital allocation boundary.

Microsoft’s current guidance similarly emphasises enterprise-wide standards, agent identity and access controls, observable behaviour, human escalation and lifecycle ownership. Importantly, Microsoft positions governance as an enabler of adoption rather than simply a restriction on it.2

The overarching principle is straightforward:

The Board sets the boundaries. Management governs the innovation portfolio of initiatives. The organisation experiments and works within these boundaries to deliver outcomes.

3. The Innovation Portfolio: Not Every AI Project Is Equal

Consider three examples:

  1. AI summarises meeting notes.
  2. AI analyses confidential financial information and recommends actions.
  3. An autonomous AI agent accesses systems, changes customer records and initiates financial transactions.

All three involve AI. Their governance requirements should clearly not be the same.

One useful way to distinguish them is the Innovation Ambition Matrix, developed by Bansi Nagji and Geoff Tuff.3 The framework considers two dimensions: where an organisation will play and how it will win. It distinguishes between existing and new markets/customers, and existing and new products/assets.

Innovation Ambition Matrix

The Matrix provides a useful way for Boards and executives to view an innovation portfolio as a whole.

The authors of the Innovation Ambition Matrix examined how organisations’ innovation efforts performed in financial terms. They found that the best-performing organisations (in terms of standard metrics) derived about 70% of their innovation returns from their Transformational efforts, 20% from the Adjacent level, and 10% from the Core.  Interestingly, the realisation relationship was directly inverse to the effort and resources expended. For example, the 70% of innovation effort spent at the Core level yielded only 10% improvement. The Core zone is the safe, blue-chip stock that helps to keep products and services relevant in a stable market.  The big leaps (and several losses) happen at the Transformation level. If a business can get the Transformational initiatives to work, it can potentially offer the most significant ROI in comparison to Core or Adjacent initiatives.

Core Innovation

Core innovation improves or extends the existing business.

Examples include:

  • Document summarisation.
  • Customer-service assistance.
  • Coding support.
  • Automated reporting.
  • Fraud detection.
  • Internal search.
  • Data classification.
  • Administrative automation.

These initiatives generally operate within familiar markets, processes and risk environments. Conventional business cases and governance processes are often appropriate.

Adjacent Innovation

Adjacent innovation extends existing capabilities into new processes, customer groups or markets. For example, an organisation might take an AI capability developed for internal use and apply it to customer-facing services.

These initiatives contain greater uncertainty and may require experimentation before a conventional business case can be established.

Transformational Innovation

Transformational innovation changes the nature of the business itself.

Examples could include:

  • An autonomous digital workforce.
  • An AI-native business model.
  • Products that could not exist without AI
  • Autonomous agents coordinating complex business processes.
  • Replacing a traditional product model with an AI-enabled service.

These initiatives involve substantially greater uncertainty and therefore require a different governance and investment approach.

The Matrix should therefore become more than an innovation classification tool. It can become a governance tool — helping determine the appropriate level of freedom, capital, oversight and evidence required for each initiative. It can also be used to set priorities, benchmarks, KPIs and performance parameters at both the organisational and initiative level.

4. From Automating Tasks to Automating Workflows

Traditional automation generally follows a simple rule:

If X happens, do Y.

Generative AI introduced something different. Systems can understand context, generate content and assist employees with decisions.

Agentic AI goes another step:

Understand the objective → determine the steps → use authorised tools → execute the workflow.

That distinction is critical for governance.

An AI system that drafts an email creates relatively limited risk. An AI agent that can access confidential information, modify a database, send communications or initiate a transaction creates an entirely different risk profile.

Google’s enterprise agent architecture illustrates this direction. Its approach includes agent identities, an Agent Registry, an Agent Gateway, policy enforcement and auditability4.

The governance principle is straightforward: The greater the autonomy, the stronger the governance required.

DimensionConventionalTransformational / Agentic
ObjectiveImprove existing workRedesign how work is performed
Market InformationRelatively understoodMore uncertain
FundingConventional budget Measured / staged investment
Metrics / KPIsROI, cost reduction, productivityLearning velocity, adoption, strategic value
RiskCompliance, operationalAutonomy, data, security, regulatory, reputational
GovernanceExisting controls plus AI guardrailsAdditional AI-specific controls and oversigh
Human involvementPrimarily oversightDefined approval and escalation points
Exit decisionProject completion / milestones statusContinue, pivot or terminate

5. The Duality of Governance

Traditional governance works well when the market, customer, technology and expected costs are reasonably understood. It becomes less effective when the organisation is exploring an uncertain proposition. Requiring a transformational AI initiative to produce a conventional five-year business case can effectively kill the initiative before the organisation has learned enough to know whether the opportunity is real.

A better approach is to consider governance in relation to these two main parts:

1. Core innovation

Use conventional measures such as:

  • ROI;
  • NPV;
  • Payback period;
  • Delivery milestones;
  • Cost reduction;
  • Productivity improvements; and
  • The many other traditional measures.

2. Transformational innovation

We need to ask different questions:

  • What assumption are we testing?
  • What will the next investment allow us to learn?
  • What evidence would justify further funding?
  • What evidence would cause us to stop?
  • What risks must be contained while we experiment?

This is essentially venture-capital logic applied inside an established organisation.

The discipline is not simply deciding whether an idea deserves $5 million. It is deciding how much should be invested now to reduce uncertainty about whether the idea deserves $5 million later.

6. What Leading Companies Are Doing

Leading (or maybe bleeding) technology companies are increasingly embedding governance into the architecture of AI itself.

Microsoft

Microsoft’s guidance for agentic AI emphasises enterprise-wide standards, identity and access controls, monitoring, human escalation, lifecycle ownership and Responsible AI oversight. Its approach also stresses least-privilege access and accountability for agent behaviour.2.4

The important development is that governance is moving from a policy document towards the technical architecture of the AI system.

Google

Google’s enterprise agent architecture gives agents their own identities and incorporates centralised gateways, registries, policy controls and audit trails.1.5

This suggests an important future principle:

An autonomous AI agent should be treated more like an employee or digital worker than a piece of software.

It needs an identity, defined permissions, boundaries, monitoring and an audit trail.

IBM

IBM has similarly emphasised organisational structures, human oversight and technology controls throughout the AI lifecycle. Its recent work on AI assurance focuses on continuous visibility, controls and accountability across models, agents, integrations and automated decisions.6.7

The common theme across these approaches is significant: AI governance is increasingly becoming an operating capability rather than simply a compliance function.

7. The Board’s Emerging AI Questions

Boards should increasingly be asking:

  • Where is AI already being used across the organisation?
  • Which processes are candidates for automation?
  • Are we examining entire workflows rather than individual tasks?
  • What happens when AI makes a mistake?
  • What information can AI access?
  • Which decisions must remain human?
  • How is AI investment being measured?
  • How quickly are competitors adopting AI?
  • What happens if competitors automate faster than we do?

The final question is particularly important. AI creates a new form of strategic risk: The risk of failing to change quickly enough.

Historically, Boards have focused heavily on the risks associated with new technology. With AI, they must also consider the risk of not adopting it.

8. Building an Enterprise Innovation Architecture

A successful innovation system needs multiple routes for ideas to enter the organisation.

Create an AI and Innovation Oversight Committee

A cross-functional group should bring together technology, operations, finance, legal, risk, cybersecurity and business leadership.

Its purpose should not be to create another bureaucratic approval layer.

It should:

  • Accelerate good ideas.
  • Identify risks early.
  • Provide access to expertise.
  • Remove organisational barriers.
  • Review Competitor / Industry AI initiatives.
  • Determine the appropriate governance pathway.

Use risk-based approval

A low-risk experiment should not face the same approval process as an autonomous system handling sensitive information.

Governance should increase according to factors such as:

  • Data sensitivity.
  • Decision impact.
  • Degree of autonomy.
  • Regulatory exposure.
  • Financial consequences.
  • Reputational consequences.

Provide dedicated resources

Innovation often fails because employees are expected to innovate while maintaining their existing responsibilities. Transformational innovation requires dedicated resources, leadership sponsorship and access to technical expertise.

Use milestone / staged funding

Investment should follow evidence. The first investment buys learning. The next investment buys evidence. Later investment buys scale.

This allows the organisation to manage uncertainty without either starving innovation or committing excessive capital too early.

Measure value, not activity

Organisations should measure outcomes such as:

  • Hours eliminated or redeployed.
  • Cycle-time reduction.
  • Customer outcomes.
  • Revenue generated.
  • Error reduction.
  • Employee capacity released.
  • Adoption.
  • Validated learning.
  • Strategic options created.

Counting the number of AI experiments tells the Board very little. Understanding what the organisation has learned, changed and created is far more valuable.

Summary

Generative AI has changed the nature of enterprise innovation.

The opportunity is not limited to creating new products and services. AI can automate labour-intensive tasks, redesign workflows and increasingly delegate entire processes to autonomous agents. That changes the governance challenge. Boards should set strategy, risk appetite and capital boundaries.

Executives should build the operating environment that allows responsible experimentation. Business units should identify and test opportunities.

Technology, risk, legal and security functions should provide the controls that allow innovation to scale safely.

The Innovation Ambition Matrix provides a useful reference framework for distinguishing Core, Adjacent and Transformational innovation. Core initiatives can generally use conventional governance. Adjacent initiatives require greater experimentation. Transformational initiatives need a more venture-like approach to investment and governance.

The same principle applies to AI. An AI system that drafts documents does not require the same controls as an autonomous agent capable of making consequential decisions.

The objective is not innovation versus governance.

It is:

Governance that enables innovation.

The organisations that gain the greatest competitive advantage from AI may not simply be those with the best technology.

They may be those with the best system for turning rapidly evolving AI capabilities into governed, scalable business value.

References:

1 Google Cloud. Gemini Enterprise Agent Platform / Enterprise Agent Architecture. Google Cloud

2 Microsoft. Agentic AI Maturity Model: Security and Governance. Microsoft Learn

3 Nagji, Bansi, and Geoff Tuff. Managing Your Innovation Portfolio. Harvard Business Review

4 Microsoft. Secure Agents. Microsoft Learn

5 Google Cloud. Govern your agents. Google Cloud Documentation

6 IBM. Trustworthy AI at Scale: IBM's AI Safety and Governance Framework. IBM

7 IBM. AI Governance to AI Assurance: What We Shared at Think 2026. IBM

Insights Article - Thought Leadership | gullonegroup | gullone.com | All Rights Reserved

Insights Article - Thought Leadership | gullonegroup | gullone.com | All Rights Reserved

Experience Matters

Since 2007, our boutique advisory firm has driven businesses to success with a 100% success rate in strategic planning. Unlike larger firms, we stay nimble, responding swiftly to client needs and budgets.