Most enterprises don't have the right AI operating model to accelerate value creation while effectively managing risk, resulting in slower adoption and missed competitive advantage. When every use case faces the same level of review, low-risk ones stall behind high-stakes ones and the pipeline backs up. A governance framework built around proportional scrutiny fixes this by routing use cases through different levels of diligence based on their risk profile.
Khwaja Shaik is a board director and IBM CTO recognized for helping CEOs and boards navigate the intersection of technology, governance, and long-term value creation. With more than 25 years of leadership experience across IBM, Bank of America, and PwC, he brings deep expertise in digital transformation, AI, cybersecurity resilience, and culture oversight—areas at the center of modern board leadership.
Shaik argued that companies stall on AI scaling because they don't have a structured intake process that classifies use cases by risk before they enter the pipeline. Without that classification, every initiative competes for the same review bandwidth, whether it touches customer data or an internal workflow. "The question is no longer whether to govern AI, but how to govern it without slowing innovation. Organizations that adopt a risk-based AI operating model can move at the speed of opportunity while maintaining the trust, transparency, and accountability required to scale. In the boardroom, AI governance should be viewed as a source of competitive advantage, not a control function,'" he said.
Start where the risk is lowest: IBM CEO Arvind Krishna mandated that the company use its own AI internally before recommending it to clients. That directive led IBM to begin with HR, an employee-facing domain with simpler privacy and security requirements than customer-facing applications. "With that mandate, we started with the HR domain as the easy use cases because it is employee-facing, not customer-facing, where you don't have such complex privacy and security requirements," Shaik said. The HR proving ground gave IBM reusability and confidence before it extended into higher-risk territory.
Regulated use cases need a longer runway: The second tier covers applications that touch customer data, trigger compliance obligations, or carry regulatory exposure. These require due diligence around privacy, security, and the ability to explain controls to regulators on demand. "You need to make sure you're future-proofing your AI solutions so that if the regulators knock on your doors, your solution is ready to explain how you've taken care of all the security requirements, privacy requirements," Shaik said. In financial services, third-party connectivity compounds the challenge: if a partner in the chain isn't compliant, the entire solution is exposed.
Real-time applications demand autonomous monitoring: The highest tier involves use cases where data arrives dynamically and outputs are served in real time. Human-in-the-loop review alone isn't fast enough. These deployments require production-grade observability that catches failures before customers see them. "Some use cases you can go fast. Some use cases, you need some due diligence. Some use cases, you not only need to have human-in-the-loop practice, but you need to have autonomous operations so that you can do that," Shaik said.
The tiered intake model only works if there's best-in-class AI Operating Model and organizational infrastructure behind it. Shaik described a cross-functional governance committee with representatives from each business unit alongside HR, legal, and security. Each rep acts as a governance ambassador within their own unit, handling training, adoption metrics, and budget coordination. The committee meets quarterly to assess performance and adapt the framework as maturity levels shift.
Tone at the top sets the pace: Distributed governance still requires executive pressure to function. "Without the mandate from the CEO, you can't move fast," Shaik said. "You need to have shared accountability so that everybody is marching towards the common outcomes." That accountability extends to compensation: tying AI security outcomes to executive pay reinforces the framework rather than undermining it.
Maturity isn't uniform: Different business units will be at different stages, and the governance model needs to flex. "It needs to be adaptive. You don't necessarily need to think that it has to be perfect from day one. Some business units will be crawling, others will be walking, and other business units will be running. The folks who are running will be a good role model for the rest of the business units."
Productivity isn't the whole story: Many companies frame AI narrowly around cost savings, but Shaik argued that the intake process should capture a broader range of outcomes. "A lot of companies only think AI is for productivity gains. They need to think beyond that, around the top line, revenue, improving customer experience," he said. The CEO cares about revenue and customer experience. The CFO cares about operating leverage. The CIO cares about simplification. A framework that only optimizes for one stakeholder will underserve the rest.
Management-level governance, even when it's well-designed, needs an accountability layer above it. Shaik advocated for a technology innovation and cybersecurity committee at the board level, a structure he sees as essential for enterprises scaling AI across multiple business units and regulatory environments. "I am a strong proponent of a technology innovation and cybersecurity committee at the board level, so that you're overseeing the management to make sure the governance is in place," he said.
Boards track the trajectory: That committee engages and oversees which business units are scaling effectively, whether AI investment balances operating leverage against top-line growth, and whether the organization is building for the short term or the long term. Shaik compared it to the early cloud cycle, where companies migrated applications without modernizing them and lost the agility benefits they were chasing. "If those applications aren't modernized, then you're not helping the business agility that your business needs," he said.
Two sides of the same coin: Board governance and management governance are reciprocal. An enlightened board demonstrates strategic agility by continuously evaluating emerging opportunities, strategic assets, and competitive options to co-create a long-term AI vision, while management translates that vision into disciplined execution and measurable business outcomes. "The board is looking for the future and the management is making sure that the strategy they've co-created with the board is aligned with the AI strategy so that they can diffuse it faster and gain competitive advantage." Without that alignment, enterprises risk outsourcing their competitive advantage to proprietary model providers.
Shaik identified three pillars that underpin the entire framework: data architecture, talent architecture, and domain architecture. Without clean data pipelines that reflect real-time changes, AI models operate on stale inputs. IBM's $11 billion acquisition of Confluent, completed in March 2026, was driven in part by the need for real-time streaming that keeps AI engines current. Without AI talent like Forward Deployment Engineers distributed across the organization, strategy and execution both suffer. And without domain expertise informing which use cases to prioritize, enterprises deploy AI where it's technically feasible but operationally fragile. "These are the three legs of the stool to diffuse your AI," he said.