I pass the Apostles’ Gate to the Cathedral in València, Spain, every day walking my daughter to or from school. The gate opens onto Plaza de la Virgen, one of the most beautiful plazas in the city, incredible in both the morning light and in the evening when its fountain is illuminated.
Eight farmers meet at that gate every Thursday at noon. There they sit encircled by a small wrought-iron enclosure. They are the síndics of the Tribunal de les Aigües, each representing one of the irrigation communities whose canals supply water to the region.
They have come to govern that water, as they have done for more than a thousand years in one of the oldest still-operating legal institutions in Europe. It is simple in its form. Complaints are brought. The accused answers. The síndics confer. The verdict is given on the spot. There is no appeal. No written record is kept. The proceedings usually close within minutes, as they have done for a millennium.
Walking past the gate day after day, I have come to think that the Tribunal has something to teach the institutions with whom I spend my days working through the future of artificial intelligence. Not because the Tribunal is old—though it is—but because the Tribunal is fast.
And it is fast for entirely structural reasons. It hears only what the canals and their communities cannot settle amongst themselves. Everything else is settled downstream (pardon the pun) by the people who actually do the work. The proceedings at the cathedral are purposefully narrow, and it is this narrowness that allows them to work quickly.
The pattern
I spend much of my time and energy with the technology leaders of multilateral institutions, public bodies, and highly regulated enterprises working on some variation of how to scale their AI through sound engineering, ethical practices, and in compliance with the law.
This conversation has quietly changed, though.
I remember one particular organization more than two years ago when questions of which models, which cloud, which vendor, and how much dominated our work. That organization and most others at the time lacked vision.
Today, almost nobody lacks a vision (or at least something like it). Leadership is largely on board. Boards and other oversight bodies generally approve of the ambition. Cloud foundations are adequate to one degree or another. Experimentation is rife.
But almost nothing is in production.
This is not an aberration, an exception to the norm. It’s a pattern. And it repeats with regularity that ought to trouble everyone: Ambition, investment, decent foundations, and frenetic activity have largely failed to change how institutions do business. Leaders I speak with know it. Many are on their second or third round of pilots and have begun to quietly suspect that the problem is not the technology they’ve chosen.
That’s a start.
You see, many of these organizations face not a technology problem, but a structure problem.
The pattern does not belong to one sector alone, but rather to any organization that is large, complex, or itself part of a larger operating community. An operating company beneath a corporate parent. An agency within a national government or a federated NGO. A multilateral body among its sister institutions. If your institution answers upward, sideways, and downward all at once, then what follows is written for you. All of it is built upon a conviction that solid structures enable organizations to move quickly.
Do not appoint a Chief AI Officer without a team
It’s well-intentioned...
An institution decides that AI needs an owner. It reprofiles or creates a senior role, sometimes quite a senior one, and names a Chief AI Officer (CAIO). Logical, right?
Most then reason that AI is now sufficiently mainstream that the actual effort to get it done can live where it always has. AI infrastructure remains with the infrastructure team. AI development settles with the development team. Workplace tooling lands with whoever drew the lot of running the productivity suite. The new CAIO will coordinate.
It fails every time for two reasons wholly unrelated to AI.
To understand the first, consider this aphorism that I learned in the Coast Guard:
It is the tradition that with responsibility goes authority and with them both goes accountability.
The Chief AI Officer is handed the responsibility and accountability with none of the authority.
Furthermore, the folks in those teams through which the CAIO will “coordinate” already have jobs. AI arrives on their desks as extra work layered atop an existing set of accountabilities, and human beings treat extra work exactly as one would expect. They defer it, they deprioritize it, or they do it badly whilst doing their real job well. It’s entirely possible that AI will replace or supersede those legacy responsibilities in time, but until it does, the Chief AI Officer—with no one reporting to them and no one whose sole job is AI—spends their days negotiating for attention.
Nothing ships.
The correction is uncomfortable, and the leaders who made it will tell you so. Stand up a small, dedicated team. Second people into it from the existing teams for a fixed term with exclusive focus on delivering AI and nothing else. Accept that the teams they left behind are carrying extra load for the duration. When the term ends, send them back.
That last step matters. Those who return from the AI office are not those who left. They have shipped things. They have made mistakes and learned from them. They carry home a new way of working rather than the legacy of what they left behind. Capability spreads through the organization not by decree, but by messenger.
Distributed responsibility for a new capability is not the same thing as distributed capability. For a period, focus has to be concentrated somewhere, and it has to be someone’s whole job.
The Chief AI Officer is a phase, not a destination
There is a second lesson here, and leaders who have made the appointment sometimes find it hard to hear.
The work is not temporary. The role is.
Those institutions that have travelled furthest tend to follow an arc. They create the role because AI needs a champion and a focal point. They build capacity through it. At some point I suspect they will realize that the organization’s principal—whether executive director, director general, or chief executive—has come to own AI in fact if not in title, because AI has become inseparable from how the institution pursues its mandate. The dedicated role dissolves back into the leadership team, merges with the CIO as “information” and “AI” become indistinguishable, or shrinks to something operational. Nobody should much mind in the end.
This would not be failure. It would be precisely what success looks like. A Chief AI Officer whose remit is still growing three years after appointment is a sign that AI has not yet been absorbed into the business of the institution. The goal was never to have an AI function. The goal was to have an institution that works differently. Once it does, the scaffolding comes down.
Appoint the role, resource it properly, and write its obsolescence into the plan.
Zone your guardrails
Governance is doomed to fail when it cannot tell the difference between a spreadsheet macro and a system that decides who receives assistance.
Paralysis results if everything is treated as high-risk. Every request goes to the same committee. So, the committee is overwhelmed. The institution’s most capable people conclude that the sanctioned route is hopeless. They go around it. Shadow AI flourishes, invisible to the very governance that was meant to see it.
Conversely, a different kind of chaos emerges when nothing is treated as high-risk. Incidents pile up quickly.
Both modes are the same failure working from opposite ends.
This is a structure problem.
Institutions that avoid it did what the canals of València worked out long ago. They decided what the síndics at the Apostles’ Gate would hear, and they let everything else be settled downstream.
Green means build freely: Personal productivity, internal drafting, summarization, the many small things a motivated colleague does with a good tool and an afternoon. No approval required. Guidance is offered. Usage is observed.
Yellow means constraints apply: Anything that touches shared data, is relied upon by others, or shapes a decision. These uses are registered, reviewed against a short set of standards, and monitored.
Red comes to the gate: If it’s external-facing, touches beneficiaries or the public, or is a scenario wherein a mistake carries a cost in trust that the institution cannot afford, then it gets a full review. Full accountability with no exceptions, and, for that reason, very little lands here.
The counterintuitive result is that more delegation produces more control, not less. With the green zone open, the volume of hidden activity collapses because there is now less reason to hide. With the red zone tightly drawn, scarce attention focuses on the handful of things that warrant it. Many small things can happen safely, and the institution sees all of them. The síndics are quick because they are asked so little. As it turns out, so is a good ecosystem design authority or AI review board.
There is a regulatory dimension here that public, multilateral, and highly regulated institutions in particular cannot ignore. In many jurisdictions the zoning is no longer a matter of institutional judgment alone. The European Union’s AI Act, to take a consequential example, defines categories of high-risk AI systems and attaches real obligations to them. An institution that has already zoned its own estate finds that the law maps onto a structure it already has. An institution that has failed to do so is left trying to retrofit a legal framework onto a landscape it cannot see. Zoning is common sense. Increasingly it is also the law, arriving in a form you can actually operate.
Adoption spreads sideways
I have watched institutions learn this the hard way with technologies that emerged long before modern artificial intelligence. You cannot train your way to adoption.
Your training catalogue has its place, but the institutions that have achieved adoption at any sort of scale, meaning adoption that changed how work is done rather than adoption that produced a completion certificate, did it through peers. A colleague in a neighboring team showing another colleague what she built. A department that reorganized a process around AI and let the department next door watch. Peer-to-peer adoption, pursued deliberately rather than left to chance, and pursued at three rather distinct levels.
The first level is individual productivity, and this is where almost every institution I know gets stuck. Colleagues are drafting faster, summarizing faster, searching faster. Real value worth having, but it does not change the institution, and boards are beginning to notice that the productivity story has a ceiling.
The second level is departmental workflow, where a team redesigns how it does a recurring piece of work with AI in the loop. The third is institutional process, where something the whole organization depends upon is rebuilt. The step from the first level to the second and third does not happen on its own. It has to be designed, and it is where peer adoption earns its keep. People change how they work when they see someone like them do it first.
Further, as AI vendors taper the subsidies that they’ve hitherto offered early adopters and the cost of AI rises, the organizations that have spent recent years pointing AI at annoying problems rather than expensive ones are likely to find themselves underwater in their return on investment.
The design question, then, is where the first movers come from. The answer I see working is an open call. Every department is invited to put forward people who want to be part of the change. Not the people who are told to stand there for the proverbial photo op. The number stepping forward is consistently larger than leadership expects. I suppose that ought not surprise anyone who has spent time in great institutions that are often full of people who joined them to change something.
What keeps them engaged is neither money nor title. It is access. The tools before everyone else has them. The APIs. Permission to build something and see it used. A seat in a small group that tests what is coming next before the institution commits to it. These things are cheap to grant and they are the currency that motivated people actually value. Give them access and they will do the adoption work for you, sideways, one colleague at a time.
Mindset is HR’s job
The last pattern is the one I find leaders most reluctant to accept. I have come to think that it is the one that separates institutions hitting a ceiling from institutions that fly the furthest.
Toolset, skillset, mindset is a useful way to think about what AI adoption actually requires. Toolset is the technology, and it belongs to IT. Skillset is the ability to use it well, an ability that IT shares with everyone. Mindset represents a shift in how people understand their work and their own place within the organization. It does not belong to the technology function, nor can it be delegated to it.
Mindset belongs to HR, and to leadership most broadly.
The institutions that have understood this treated AI as a people program with a technology component, rather than a technology program with a change-management workstream bolted on the side or—worse—at the end. This looks in practice like a competency framework describing what fluency with AI means at every level of the organization. An AI objective written into every colleague’s goals, not as a box to tick but as a thing to be asked about and developed over time. Development of every manager, not on the tools but on responsible use and on leading a team that works alongside AI. Protected time to learn, because learning that must be squeezed in after the real work simply does not happen. And explicit permission to experiment and to fail.
None of this is technology. All of it is structure. An institution whose technology leader is trying to drive it alone will find that the culture does not move, no matter how good the tools are, because culture has never been IT’s to move.
The court at the gate
I argued in February of 2025 that organizations treating technology as an ever-expanding cost center will fail, and that those using it to drive out cost and improve what they deliver may survive. Governance built to say no is a different flavor of that same instinct. It treats frontier capability as a liability to be contained rather than a fabric to be woven. It produces the same result, an institution that is very busy but does not change.
Look back across the notions above and you may notice that none asks you to pick a model, a cloud, or a vendor. Each is a decision about how the institution is arranged. Each also removes something. A competing priority, in the case of the dedicated office. An excuse, in the case of the role designed to dissolve, and again in the case of the open call. A bottleneck, in the case of zoning, and again in the case of a technology leader trying to change a culture from the wrong seat. Remove enough of those, and the institution begins to move, not because anyone pushed it but because the things that were holding it in stasis are gone.
The síndics of València understood this before anyone had a word for it. Govern narrowly at the gate. Trust the community with the rest. Be quick, because being quick is the whole point of having a court at all.
If your institution is on its third round of pilots, I would offer that the problem is very likely not the technology you chose. It is the structure you built around it. Structure, unlike technology, is entirely yours to change.
I have written at greater length about how institutions put structures like these in place, and about a good deal else, in Centru 3, published by the Center for Trustworthy AI, which I lead.

