One of the most common complaints about AI governance is that it slows things down.
I have seen the opposite.
A document-processing use case came to me already being treated as high risk. Nobody had actually worked through what could go wrong. The concern came largely from the shape of the idea: AI would read incoming documents and extract information from them. That sounded risky, so progress had stalled.
Instead of debating whether the use case belonged in a high-risk category, we traced the decision and failure paths.
The model extracted information. It did not approve anything. It did not make a financial decision. It did not initiate a payment. Outputs below an agreed confidence threshold went to a person for review, and the original document remained the source record.
Once those boundaries were explicit, we could assess the actual risk rather than the perceived risk, put the right controls around it, and move the use case forward.
Governance was not what delayed the initiative.
Governance was what allowed a decision to be made.
That distinction matters.
Without a clear framework, the default response to an ambiguous AI use case is often not "no". It is no decision at all. The proposal moves between technology, risk, privacy, legal and business teams while everyone waits for someone with enough authority to accept the uncertainty.
The project appears to be under review. In reality, it is standing still.
The metric is wrong
Organisations often measure governance through policy coverage, assessments completed, controls implemented or percentage of initiatives approved.
Those measures have a place, but they tell us very little about whether governance is helping the organisation move.
I think a more useful measure is decision latency.
How much time passes between somebody proposing an AI use case and receiving a clear, dated decision with an accountable owner?
On that measure, a no in two weeks can be far more valuable than a yes in five months.
The two-week no releases the team, the funding and the sponsor's attention. People can redirect their effort toward something viable.
The five-month yes may arrive after the opportunity has passed, the team has lost momentum or the cost of waiting has exceeded the value of the initiative itself.
I have seen capable teams lose months without receiving a single formal rejection.
Nothing was declined.
Nothing was decided either.
That is not effective governance.
What actually creates speed
In my experience, three things make the biggest difference.
Set the rules before the use cases arrive
If every AI initiative requires the organisation to decide its risk appetite from first principles, every assessment becomes a negotiation.
Negotiations take time.
When I developed an AI use-case catalogue covering around forty initiatives across ten business domains, we established the zoning criteria first. That meant most proposals could be assessed against an agreed set of boundaries rather than starting another debate about what acceptable risk looked like.
The straightforward cases became easier to move.
More importantly, governance capacity could be concentrated on the small number of initiatives where the answer was genuinely difficult.
Good governance should spend the most time where judgement adds the most value.
Examine failure paths, not labels
Categories are useful for organising work, but they can also create unnecessary anxiety.
"AI reading documents" is a category.
"AI extracts specified fields, does not make the final decision, sends low-confidence results for human review, and retains the original document as the authoritative record" is a control design.
The second description is far easier to evaluate.
What happens if the model is wrong?
Who sees the result?
What decision can the model influence?
Can a person intervene?
Can we reconstruct what happened?
What data is retained?
Those questions turn an abstract discussion about AI risk into something that people can assess and decide.
Map common obligations once
Another source of delay is repeatedly reopening the same compliance discussion.
The framework I built covered eleven dimensions across the AI lifecycle and mapped common control requirements against relevant frameworks and obligations, including the EU AI Act, NIST AI Risk Management Framework, ISO 42001 and APRA CPS 230.
The important part was not producing another framework document.
It was creating a common baseline.
Once the recurring obligations and controls were understood, each new initiative could focus on what was genuinely different about that use case instead of rebuilding the entire governance argument from the beginning.
That is where standardisation creates speed.
Governance also needs to know when to stop
The same framework that allows an initiative to move quickly must also be capable of stopping one.
I had another use case with strong sponsorship and a legitimate underlying business objective.
But the consent and approvals already in place did not clearly support the proposed AI processing, and the required data-handling controls were not yet established.
The use case stayed red.
That was not governance failing to enable innovation.
It was governance doing its other job: protecting the organisation's ability to continue innovating.
There is a tendency to treat every control as friction and every approval as delay. That view ignores what happens after a poorly governed initiative goes wrong.
One avoidable incident can affect far more than the individual project.
It can change executive risk appetite.
It can trigger additional assurance requirements.
It can make every subsequent AI proposal harder to approve.
It can undermine confidence with customers, regulators and employees.
Most importantly, it can cost the organisation the mandate to keep experimenting.
Governance that cannot say no is not fast governance.
It is absent governance.
And absent governance often borrows speed at the beginning of a programme only to repay it, with interest, later.
Ask a different question
If an organisation wants to understand whether its AI governance is enabling progress or obstructing it, I would not start by asking how many use cases were approved.
I would ask:
How long did it take to reach a decision?
Who owned that decision?
Was the reasoning clear enough that the team understood what needed to change?
And when the answer was no, did the team receive that answer early enough to redirect its people, money and attention somewhere more valuable?
Those questions tell us much more about governance performance than an approval percentage.
AI governance should not exist to make every initiative safe enough to proceed.
Its job is to create the conditions for good decisions: move quickly where the risk is understood and manageable, slow down where evidence is missing, and stop when the organisation has not earned the right to proceed.
Acceleration is not the absence of control. It is the presence of a decision.