Generative AI has fundamentally changed the innovation conversation.
For years, executives have pushed organisations to innovate faster. Now, generative AI can write, analyse, summarise, code, search, create and increasingly execute tasks. Technologies that once required significant human effort can now be partially or substantially automated across areas such as software development, customer service, legal document review, finance reporting and marketing.
The emergence of AI agents takes this further. Rather than simply answering questions, agents can increasingly perform multi-step tasks and interact with business systems. Google, for example, is developing enterprise agent architectures based around agent identities, access permissions, registries, gateways and auditability.1
This creates a new strategic question for Boards and executives:
How will we use AI, what work should be performed by people, what can be automated, and how should the organisation govern the transition?
The answer is not simply to accelerate innovation or to increase controls. Organisations need controlled acceleration — enabling experimentation while applying progressively stronger governance as uncertainty, autonomy and potential consequences increase.
Generative AI is compressing innovation cycles.
Previously, automating a repetitive business process might require months of analysis, software development, testing and implementation. Today, an employee can use AI to prototype a solution to a repetitive task in days — sometimes hours.
The problem is that an organisation’s ability to create innovation can now move faster than its ability to govern it.
If governance is too slow, employees may turn to unapproved “shadow AI” tools. If governance is too restrictive, valuable opportunities may never be tested.
The objective should therefore be to control the speed: allow low-risk experimentation while introducing progressively stronger controls as the potential impact increases.
The Board should not be approving individual AI models or projects. In line with fundamental good governance principles, the Board's role is to establish the strategic and risk boundaries within which management operates.
In relation to AI, the Board should focus on:
Executive leadership should then translate these boundaries into an operating system for innovation and establish:
Microsoft’s current guidance similarly emphasises enterprise-wide standards, agent identity and access controls, observable behaviour, human escalation and lifecycle ownership. Importantly, Microsoft positions governance as an enabler of adoption rather than simply a restriction on it.2
The overarching principle is straightforward:
The Board sets the boundaries. Management governs the innovation portfolio of initiatives. The organisation experiments and works within these boundaries to deliver outcomes.
Consider three examples:
All three involve AI. Their governance requirements should clearly not be the same.
One useful way to distinguish them is the Innovation Ambition Matrix, developed by Bansi Nagji and Geoff Tuff.3 The framework considers two dimensions: where an organisation will play and how it will win. It distinguishes between existing and new markets/customers, and existing and new products/assets.
Innovation Ambition Matrix
The Matrix provides a useful way for Boards and executives to view an innovation portfolio as a whole.
The authors of the Innovation Ambition Matrix examined how organisations’ innovation efforts performed in financial terms. They found that the best-performing organisations (in terms of standard metrics) derived about 70% of their innovation returns from their Transformational efforts, 20% from the Adjacent level, and 10% from the Core. Interestingly, the realisation relationship was directly inverse to the effort and resources expended. For example, the 70% of innovation effort spent at the Core level yielded only 10% improvement. The Core zone is the safe, blue-chip stock that helps to keep products and services relevant in a stable market. The big leaps (and several losses) happen at the Transformation level. If a business can get the Transformational initiatives to work, it can potentially offer the most significant ROI in comparison to Core or Adjacent initiatives.
Core Innovation
Core innovation improves or extends the existing business.
Examples include:
These initiatives generally operate within familiar markets, processes and risk environments. Conventional business cases and governance processes are often appropriate.
Adjacent Innovation
Adjacent innovation extends existing capabilities into new processes, customer groups or markets. For example, an organisation might take an AI capability developed for internal use and apply it to customer-facing services.
These initiatives contain greater uncertainty and may require experimentation before a conventional business case can be established.
Transformational Innovation
Transformational innovation changes the nature of the business itself.
Examples could include:
These initiatives involve substantially greater uncertainty and therefore require a different governance and investment approach.
The Matrix should therefore become more than an innovation classification tool. It can become a governance tool — helping determine the appropriate level of freedom, capital, oversight and evidence required for each initiative. It can also be used to set priorities, benchmarks, KPIs and performance parameters at both the organisational and initiative level.
Traditional automation generally follows a simple rule:
If X happens, do Y.
Generative AI introduced something different. Systems can understand context, generate content and assist employees with decisions.
Agentic AI goes another step:
Understand the objective → determine the steps → use authorised tools → execute the workflow.
That distinction is critical for governance.
An AI system that drafts an email creates relatively limited risk. An AI agent that can access confidential information, modify a database, send communications or initiate a transaction creates an entirely different risk profile.
Google’s enterprise agent architecture illustrates this direction. Its approach includes agent identities, an Agent Registry, an Agent Gateway, policy enforcement and auditability4.
The governance principle is straightforward: The greater the autonomy, the stronger the governance required.
| Dimension | Conventional | Transformational / Agentic |
|---|---|---|
| Objective | Improve existing work | Redesign how work is performed |
| Market Information | Relatively understood | More uncertain |
| Funding | Conventional budget | Measured / staged investment |
| Metrics / KPIs | ROI, cost reduction, productivity | Learning velocity, adoption, strategic value |
| Risk | Compliance, operational | Autonomy, data, security, regulatory, reputational |
| Governance | Existing controls plus AI guardrails | Additional AI-specific controls and oversigh |
| Human involvement | Primarily oversight | Defined approval and escalation points |
| Exit decision | Project completion / milestones status | Continue, pivot or terminate |
Traditional governance works well when the market, customer, technology and expected costs are reasonably understood. It becomes less effective when the organisation is exploring an uncertain proposition. Requiring a transformational AI initiative to produce a conventional five-year business case can effectively kill the initiative before the organisation has learned enough to know whether the opportunity is real.
A better approach is to consider governance in relation to these two main parts:
1. Core innovation
Use conventional measures such as:
2. Transformational innovation
We need to ask different questions:
This is essentially venture-capital logic applied inside an established organisation.
The discipline is not simply deciding whether an idea deserves $5 million. It is deciding how much should be invested now to reduce uncertainty about whether the idea deserves $5 million later.
Leading (or maybe bleeding) technology companies are increasingly embedding governance into the architecture of AI itself.
Microsoft
Microsoft’s guidance for agentic AI emphasises enterprise-wide standards, identity and access controls, monitoring, human escalation, lifecycle ownership and Responsible AI oversight. Its approach also stresses least-privilege access and accountability for agent behaviour.2.4
The important development is that governance is moving from a policy document towards the technical architecture of the AI system.
Google’s enterprise agent architecture gives agents their own identities and incorporates centralised gateways, registries, policy controls and audit trails.1.5
This suggests an important future principle:
An autonomous AI agent should be treated more like an employee or digital worker than a piece of software.
It needs an identity, defined permissions, boundaries, monitoring and an audit trail.
IBM
IBM has similarly emphasised organisational structures, human oversight and technology controls throughout the AI lifecycle. Its recent work on AI assurance focuses on continuous visibility, controls and accountability across models, agents, integrations and automated decisions.6.7
The common theme across these approaches is significant: AI governance is increasingly becoming an operating capability rather than simply a compliance function.
Boards should increasingly be asking:
The final question is particularly important. AI creates a new form of strategic risk: The risk of failing to change quickly enough.
Historically, Boards have focused heavily on the risks associated with new technology. With AI, they must also consider the risk of not adopting it.
A successful innovation system needs multiple routes for ideas to enter the organisation.
Create an AI and Innovation Oversight Committee
A cross-functional group should bring together technology, operations, finance, legal, risk, cybersecurity and business leadership.
Its purpose should not be to create another bureaucratic approval layer.
It should:
Use risk-based approval
A low-risk experiment should not face the same approval process as an autonomous system handling sensitive information.
Governance should increase according to factors such as:
Provide dedicated resources
Innovation often fails because employees are expected to innovate while maintaining their existing responsibilities. Transformational innovation requires dedicated resources, leadership sponsorship and access to technical expertise.
Use milestone / staged funding
Investment should follow evidence. The first investment buys learning. The next investment buys evidence. Later investment buys scale.
This allows the organisation to manage uncertainty without either starving innovation or committing excessive capital too early.
Measure value, not activity
Organisations should measure outcomes such as:
Counting the number of AI experiments tells the Board very little. Understanding what the organisation has learned, changed and created is far more valuable.
Generative AI has changed the nature of enterprise innovation.
The opportunity is not limited to creating new products and services. AI can automate labour-intensive tasks, redesign workflows and increasingly delegate entire processes to autonomous agents. That changes the governance challenge. Boards should set strategy, risk appetite and capital boundaries.
Executives should build the operating environment that allows responsible experimentation. Business units should identify and test opportunities.
Technology, risk, legal and security functions should provide the controls that allow innovation to scale safely.
The Innovation Ambition Matrix provides a useful reference framework for distinguishing Core, Adjacent and Transformational innovation. Core initiatives can generally use conventional governance. Adjacent initiatives require greater experimentation. Transformational initiatives need a more venture-like approach to investment and governance.
The same principle applies to AI. An AI system that drafts documents does not require the same controls as an autonomous agent capable of making consequential decisions.
The objective is not innovation versus governance.
It is:
Governance that enables innovation.
The organisations that gain the greatest competitive advantage from AI may not simply be those with the best technology.
They may be those with the best system for turning rapidly evolving AI capabilities into governed, scalable business value.
References:
1 Google Cloud. Gemini Enterprise Agent Platform / Enterprise Agent Architecture. Google Cloud
2 Microsoft. Agentic AI Maturity Model: Security and Governance. Microsoft Learn
3 Nagji, Bansi, and Geoff Tuff. Managing Your Innovation Portfolio. Harvard Business Review
4 Microsoft. Secure Agents. Microsoft Learn
5 Google Cloud. Govern your agents. Google Cloud Documentation
6 IBM. Trustworthy AI at Scale: IBM's AI Safety and Governance Framework. IBM
7 IBM. AI Governance to AI Assurance: What We Shared at Think 2026. IBM
Insights Article - Thought Leadership | gullonegroup | gullone.com | All Rights Reserved