The Modular Briefing · September 3, 2026

What governance actually asks for

Welcome back to the Modular Briefing. Each week: a short, plain-English read on private AI, governance, and owning your infrastructure. No hype, no vendor spin.

No news this week. One argument instead, because it is the place our reporting keeps landing and it has earned a hearing on its own.

AI governance, for a business your size, is four things. An owner. A boundary. A log. And evidence. That is the entire list. Not a model choice, not a budget line, not an AI team. Somebody whose job it is.

Start with the word, because the word is doing real damage. Say governance in a room of thirty people and everybody pictures the same furniture: a committee, a binder, a consultant with a slide deck, something a bank has and you do not. So the sentence that comes next is almost always the same one. We are too small for that. It is true about the binder. It is false about the thing the binder was supposed to hold, which is four answers to four questions.

Question one

Who owns this?

Not who bought it. Not who is good with computers. Who is accountable when it goes wrong. This one matters more than the other three put together, because software with no owner does not sit still. It spreads. Somebody finds it useful, tells two colleagues, and within a quarter it is touching material nobody ever decided it should touch. No one chose that. It happened, the way things happen when it is nobody's job to notice.

Look at what the fix costs. Nothing. You are writing one name next to one tool, and it can be a name already on your organization chart. Their workload does not change. What changes is that the question has somewhere to go. When somebody wonders out loud whether client material belongs in this thing, there is a person whose job it is to have an answer, instead of a shrug that goes around the room and comes back.

Question two

Where does it end?

That is the boundary, and it is the one small organizations skip, because a boundary sounds like a restriction and a restriction sounds like the opposite of why you bought the thing. But a boundary is not a fence around the tool. It is a sentence about your material: what is this allowed to touch, and what is it not.

You already have one, which is the part worth sitting with. Every business we work with already knows which of its files would be a very bad day. The client file. The medical file. The payroll file. The deal that is not signed yet. Nobody had to be taught that, and nobody wrote it down either, which is exactly the problem, because an unwritten boundary cannot be handed to a new hire and it cannot be handed to software at all.

So write the sentence. Two lines is a real boundary. This tool may see our public material and our internal drafts. It may not see client files, personnel files, or anything covered by an agreement we signed. Then the harder half: where does your material go while the tool is looking at it? A boundary you enforce by asking people to be careful is not a boundary. It is a hope. If the material has to stay inside your walls, the tool has to run inside your walls. Your data, your rules. And that includes the AI working on it. Your AI, your rules.

Question three

What happened?

That is the log, and it is worth being clear about what we mean, because the word makes people picture a compliance product with a dashboard and a monthly fee. We do not mean that. We mean the ordinary answer to an ordinary question: which tool, doing what, on whose behalf, and when.

There is one design choice underneath it that decides whether the log is worth keeping. Give the software its own name. Its own login, its own identity, in a class of its own, not borrowed from a person. Because if your AI runs on an employee's credentials, then in your own logs the software and the employee are one actor, and later, when it matters, you cannot answer the only question anybody asks, which is which of you did that. Give the tool its own name and the answer writes itself. That is an afternoon of work.

Question four

Can you show it?

Not describe it. Show it. The name of the owner. The sentence about the boundary. A month of the log. Here is the asymmetry nobody warns you about in advance: evidence is cheap to keep and impossible to build backwards. Nobody has ever manufactured last quarter.

Why this scales down

Notice what is not on the list. Which model you picked. What you spend. Whether you hired anybody. And notice that all four questions scale down, which is the part that keeps getting missed. A thirty person firm can answer all four inside a week. What a large enterprise has is not better governance. It is the same four answers with more people maintaining them.

Which is why we do not think most businesses need an AI department. They need somebody whose job it is: one person, some of the time, who owns the four answers and keeps them current. That is the whole idea behind a fractional chief AI officer. It is not a clever product. It is an honest reading of what four questions cost.

This week's episode: "What Governance Actually Asks For" · 5:19

Arthur and Laura take the same four questions out loud, with the argument for why the fourth one is the one that actually binds. Listen to the edition.

And our question for you: pick any AI tool in your business and answer question one out loud. Who owns this? If a name comes easily, you are further along than you think. Hit reply and tell us which of the four is hardest where you are. A person reads every reply.

Your data, your rules.