This report uses public information available through 2026-07-13. It is an enterprise operating lens, not procurement advice, a compliance certification or a company-specific implementation plan.
Before Monday’s operating review, the leadership team receives an AI-produced sales forecast. It is clear, concise and ready with recommendations. As the meeting turns to budget changes, someone asks three questions: Which snapshot of the order data did it use? Who checked the merged sales notes? If the recommendation is wrong, who can stop what happens next?
The room goes quiet. No one can answer the whole chain.
This does not mean the AI has no value. It means the enterprise has crossed from a relatively easy question - can the system produce a plausible output? - into a harder one: can that output enter real work, survive review and be stopped when something goes wrong?
The core judgment
When AI helps one person search, summarise or draft, that person can often check the result. Once AI begins to influence customer communication, operating forecasts, resource allocation or system records, model performance is only the starting point. The enterprise must also know who owns the outcome, whether the data can be reconstructed and how an AI output earns the right to become an action.
This report calls those requirements the responsibility chain, the data chain and the decision chain. They are not a proposal for another heavy governance layer. They are a practical way to separate work that can be accelerated, work that should remain constrained and work that is missing basic conditions for greater authority.
This is not an IT-only issue. Business owners define acceptable outcomes. Data and technology teams explain how the system reached them. Authorized decision-makers decide when to accept, reject or stop the result. If any one of those roles is absent, the conversation stays focused on model quality while the business consequence remains unowned.
Why this question matters now
AI adoption is moving faster than its integration into formal work. Stanford’s 2026 AI Index reports that 88% of surveyed organizations used AI in at least one business function in 2025. Agent use, however, remained in the single digits across most functions. This is survey evidence, not a census of all enterprises.
McKinsey’s 2025 global survey found that roughly one-third of respondents were scaling AI across their organizations, while 39% reported some enterprise-level EBIT impact. Use, organization-wide scaling and reported profit impact are different measures. None can stand in for the others.
Regional evidence points in the same direction. HKPC surveyed around 800 Hong Kong companies in 2025. Eighty-eight per cent reported employee AI use, 92% planned to integrate AI into workflows, and 54% of firms using recognised platforms lacked complete or ongoing governance arrangements. Those percentages answer different questions and should not be combined into a maturity score.
IMDA reports that AI adoption reached 14.5% among Singapore SMEs and 62.5% among non-SMEs in 2024. AI-using firms also named workforce upskilling, job redesign and IT/data infrastructure as next-stage priorities. These figures describe Singapore; they are not a global benchmark.
The surveys use different samples, questions and denominators. They cannot be added together to produce a global “governance gap”. They support a narrower directional judgment: tools may be entering enterprises faster than workflows and responsibility arrangements are changing around them.
What the three chains do
Name the work the AI output will affect.
Identify the outcome owner and stop right.
Record source, transformation, definition and version.
Define review, action conditions and rollback.
The three chains converge on the same task.
A person with decision rights confirms the result.
The action remains traceable and stoppable.
Add evidence, narrow authority or pause.
Responsibility chain: who owns the result and who can stop it
A responsibility chain is more than a name in a policy document. The team needs to know who requested the task, who permitted AI to read from or write to business systems, who accepts the final business outcome, who handles exceptions and who has the authority to pause the process.
If everyone benefits from speed but no one owns the downside, risk is pushed to the final reviewer or explained only after an incident. A named owner without the authority to stop the process is not effective ownership.
Data chain: what did this judgment use
The data question is not simply whether a report lists sources. It is whether the result can be reproduced. Managers need to know where the data came from, how it was merged or transformed, which metric definition and version were used, whether it was current enough and whether it was permitted for this task.
A genuine source does not guarantee a correct conclusion. Old versions, inconsistent definitions, missing fields and unauthorized data can all produce a polished but misleading result.
Decision chain: where output becomes action
AI can provide a draft, alert or recommendation. It should become action only after it has been reviewed against the required evidence and confirmed by someone with the authority to decide. The chain should also define when to escalate, when to return work to a person, when to stop and how errors are recorded and corrected.
“A human looked at it” is not enough. Review becomes ceremonial when the reviewer lacks context, time or the authority to reject the system’s suggestion.
A concrete example: an AI-produced monthly sales forecast
Imagine an enterprise asking AI to combine CRM opportunities, order data and sales-team notes into next month’s sales forecast. This is an illustrative scenario, not a client case.
The responsibility chain identifies the sales owner for the forecast, the data team responsible for definition issues and the finance team that decides whether the result can enter budget discussions. Any of them can request a pause when a material anomaly appears.
The data chain records the tables used, the cutoff date, the definition of a qualified opportunity and each material transformation. When the forecast misses, the team can return to a specific data decision instead of asking only why the model was wrong.
The decision chain keeps the AI forecast in draft status. Missing key data, conflict with finance records or an unusual movement sends it back for human review. Only after management confirmation can it influence budget and resource allocation.
Remove any one chain and the failure becomes visible. An accountable owner who cannot reconstruct the data is being asked to endorse an opaque process. Complete records without an action boundary allow a recommendation to enter the budget too early. Approval without a stop and correction path lets an error continue through the workflow.
Control should rise with consequence
An AI assistant used only for an internal draft, with full review by someone who understands the work, can operate with light controls. Even without write access, data versions and final judgment ownership matter when the output shapes an operating metric or forecast. If the system can change customer records, send external messages or trigger financial action, permissions, review, logging, incident handling and rollback need to be more explicit.
Low consequence and easy to reverse.
Disclose sources and complete human review.
The output begins to shape judgment.
Confirm the data version and final decision owner.
The output begins to change business records.
Define permission, logging and rollback.
Consequence and affected parties expand.
Define confirmation, stop and notification paths.
Control can also be excessive. Layering approval onto low-consequence, reversible tasks may push employees outside the visible process. The enterprise then loses both efficiency and oversight. Control strength should respond to consequence, permission, reversibility and observability.
Test one live workflow with six questions
Choose a workflow that already uses AI. Give its business, data and technology owners 30 minutes to answer:
- Who accepts the final business outcome, and who can stop the process?
- Can the data the system read and transformed be reconstructed?
- Which metric definition and data version did this judgment use?
- At what point does the AI output gain authority to affect action, and who confirms it?
- Are exceptions, near misses and human edits recorded?
- When an error is found, can the team pause, correct and notify the people affected?
This is not a maturity score or a compliance audit. If several answers are unclear, the safer response is usually to narrow authority, add evidence or name an accountable owner before expanding use.
A small, reversible next step
Do not begin with a programme to “build comprehensive AI governance”. Start with one frequent workflow whose process is visible and whose consequence is clear. Put the participants, data path, review point, action condition and stop mechanism on one page.
Then watch a small set of changes. Did processing time fall? Did rework or exceptions rise? Did human review become the new bottleneck? Can the team return quickly to the previous process when something fails? If the chains are clear and value continues, there is a case to expand. If the chains are clear but value does not improve, reconsider the workflow. If the process cannot be reconstructed, do not expand AI’s authority first.
Evidence boundary and update trigger
This report combines public surveys, official risk-management frameworks and bounded mechanism analysis. The evidence supports a directional claim: in some enterprises, AI adoption is moving faster than workflow adjustment. It does not prove that responsibility, data and decision chains are the dominant bottleneck in every enterprise. It also does not show that more governance spending automatically produces financial return.
First-party workflow reviews, production incident samples and target-reader interviews remain limited. Model quality, integration cost, talent and change management may be more important constraints. Existing identity, data-governance and process controls may already cover much of the three-chain requirement in some organizations. If projects with clear chains continue to fail widely, or lightweight controls keep producing durable value, the report’s judgment should weaken.
The public sources were refreshed on 13 July 2026. IMDA’s 2026 Building AI-Ready Enterprises release is retained as a future update trigger; it is not used here to add a new causal or global market claim. A material source revision, denominator change or link failure should trigger another review.
This report is not procurement advice, a compliance certification or an implementation plan for a specific enterprise.
Sources
- Stanford HAI, 2026 AI Index Report - Economy
- McKinsey, The State of AI: Global Survey 2025
- HKPC, AI Readiness in Workplace Survey 2025
- IMDA, Singapore Digital Economy Report 2025
- Deloitte, State of AI in the Enterprise 2026
- NIST, AI Risk Management Framework 1.0 Core
- NIST, Generative AI Profile
- ISO/IEC 42001:2023, AI management systems
- IMDA, Building AI-Ready Enterprises 2026
Free PDF · £0
Receive the English PDF by email
Complete Stripe's £0 checkout to choose the English edition. No payment card is required. The checkout email is used for report delivery and necessary support only; it is not automatically added to a marketing list.