
AI Governance Is a Judgment Call, and It Just Reached Coaching
What is AI governance?
AI governance is the standing decision about where an AI system’s output stops and a person’s accountability starts. It names which workflows run without review, which get checked by a human before they leave the building, and which stay human entirely. It is a judgment call with an owner and a date, written down.
Three pieces of coverage landed inside forty-eight hours, aimed at audiences that never read each other. A compliance publication told risk officers their operating model has aged out. A marketing outlet read the 2026 Forbes CMO list and found that governance now separates the leaders who count from the merely visible. An opinion writer described AI executives working closed-door meetings in Washington ahead of a policy deadline.
Different industries, different readers, one question underneath all three.
Who decides where the machine’s output stops and a person is accountable for it?
That question has already walked into coaching. It came in quietly, through a transcription tool somebody switched on to save twenty minutes after each session, and nobody wrote anything down about it. The governance conversation happening in boardrooms is sitting unnamed in most coaching practices right now. It is in almost no coach training curriculum at all.
Key Takeaways
- AI governance is one decision repeated across every touchpoint: runs alone, runs with human review, stays human. Everything else is documentation of those three.
- The layering problem risk functions have at enterprise scale shows up identically in a solo practice. Tools get added one at a time and nobody stands back to ask whether the whole arrangement still holds.
- Regulation sets a floor for the entire market and arrives late, shaped by parties whose interests are not yours. The boundary that protects your client is the one you write.
- Coach training teaches tools in a webinar and ethics in a module. The judgment connecting them gets taught nowhere, and that gap is the actual problem.
- Sorting your AI touchpoints into three bins takes an hour and produces a page you can hand a client. Most practices have never done it.
What AI governance means once you drop the compliance language
AI governance is the set of standing decisions about which AI outputs run without a human, which require review before they go anywhere, and which stay entirely with people. Attach an owner to each call and a record of why you made it, and you have governance. Everything past that is paperwork describing those three decisions.
Compliance Week made the sharpest version of the argument this week, aimed at risk, compliance and internal audit leaders. For years those functions absorbed new capability without changing the structure underneath: continuous controls monitoring, dynamic risk assessments, fresh reporting requirements, each layered onto a model designed for a different era. AI, they argue, should end that habit. Their question is the useful part. If we were designing risk management today, knowing everything we now know, would we build it the same way? For many organizations, the answer is no.
Notice what that question does. It strips the sunk cost out of the room. Almost nobody defends the current arrangement on its merits once asked to design it fresh, which is why it works as well on a two-person practice as on a bank.
The 2026 Forbes CMO list points at the same thing from the commercial side. Forbes evaluated more than 1,500 marketing chiefs against more than 10 billion data points and named 50. Reading the result, MarketScale found the separator was commercial consequence rather than press coverage, and that the executives setting the standard had moved past AI experimentation into AI governance. They had decided which outputs require human review, which workflows can run autonomously, and which creative decisions stay entirely with people.
Three bins. That is the whole job, according to a list of the fifty most influential marketers alive.
One detail from that coverage tells you where this ends up. Provenance, brand compliance and authenticity controls are turning into procurement requirements, which means governance stops being a values question and starts being a revenue one.
The rulebook is being written by people who are not you
External AI regulation will arrive, late, shaped by whoever spent the most to get into the room. It will set a floor for the whole market. It will not tell you whether a note-taker belongs in your client’s session, or what happens to the transcript afterward. That call stays yours regardless of what any rule eventually says.
Writing in Common Dreams, Shaunna Thomas described AI executives shuttling between Capitol Hill and the White House ahead of the deadline to finalize the administration’s AI executive order, backed by record lobbying and super PAC spending, with operatives from both parties carrying the industry’s agenda. Her argument is political. The operator’s reading is duller and more useful.
Days before those meetings, an OpenAI model was implicated in a cyberattack on another company. One fortnight produced both the strongest argument yet for external rules and the clearest picture of who is drafting them.
I am not selling alarm, and I have no stake in the lobbying fight. The practical point is about timing. Regulation is a floor, it is slow, and it is negotiated by people whose interests are not yours. Anything in your practice waiting on it is unattended in the meantime. Risk management inside your own four walls is the only control that runs on your schedule.
Regulation sets the floor for the whole market. The ceiling in your practice is whatever you decided the last time nobody was watching.
This already landed in your practice, probably without a decision
Most coaching practices are already running five or six AI touchpoints: transcription, note-takers, intake summaries, prep research, drafted client emails, scheduling. Almost none arrived through a decision. Each was switched on by whoever found it useful that week, which is the same layering pattern the risk functions have, at practice scale.
Five Tools, Zero Standing Decisions?
A coaching conversation can help you run the inventory, name what’s unattended, and write the page you’d hand a client.
Run the inventory on yourself. Something records or transcribes sessions. Something summarizes what happened. Something drafts the follow-up. Something scores or interprets an assessment. Something writes your marketing. Somewhere along that chain, identifiable client material is passing through a vendor your client never agreed to.
That is the confidentiality problem in one sentence, and there is nothing hypothetical about it.
The practitioner-level answers already exist and they are long. We have written up where AI belongs in a coaching practice, and the four questions that clear AI note-takers in client sessions before you switch one on. I am not repeating any of it here, because repeating it would miss what the last two weeks of business coverage exposed.
Every one of those tool decisions was made in isolation, by whoever happened to be evaluating that tool. Nobody stood back afterward and asked whether the resulting arrangement is one you could defend to a client, a supervisor, or a credentialing body. Standing back and answering that is governance, and in most practices it has never happened once.
A bank has three lines of defense and a chief risk officer to coordinate them. You have you. Having no compliance department does not reduce the obligation by a degree. It removes the safety net, and it removes anyone whose job it is to notice a tool nobody decided on.
A boundary test you can run this week
List every place AI touches your work. Ask three questions of each one: who is accountable if the output is wrong, would the client agree to this if they watched you set it up, and does it replace the thinking or the typing. The answers sort every touchpoint into one of three bins. The sort takes an hour.

Who is accountable if this is wrong? Not who is at fault. Who has to make it right, in front of the client, with their name on it. The answer is always you, so the question becomes what checkpoint the tool needs, sized to how badly it can fail. A mangled calendar invite costs you an apology. A summary that misstates what a client disclosed costs you the relationship.
Would the client agree if they watched you set it up? This beats a consent form, because it catches the tools you would rather not bring up. If narrating the setup out loud makes you uneasy, you have your answer before you finish the sentence. The mechanics of when and how to tell clients you are using AI deserve their own read. The discomfort test tells you which conversations you have been putting off.
Does it replace the thinking or the typing? Typing is transcription, formatting, scheduling, first drafts of things nobody’s growth depends on. Thinking is the judgment you were hired for: what you noticed, what you chose to say, what you decided to leave alone. Automate the typing without apology. Protect the thinking without exception.
Every AI touchpoint you have lands in one of those three bins.
The middle bin is where it gets interesting. Most practices live there, and almost nobody has defined what review means. Review means knowing what this tool gets wrong and looking specifically for that, which requires running it badly on purpose, once, before it touches anything real.
That single habit protects you better than any vendor questionnaire, though a structured way to vet an AI tool before it goes near a client is worth having alongside it. One tells you what the company promises. The other tells you what the tool does at three in the afternoon when you are tired.
Put the sort in writing. One page: the tool, the bin, the reason, the date you decided. Ten minutes per tool. When a client asks what happens to their data, you read from the page instead of improvising, and the improvised answer is the one that gets you into trouble.
What coach training has to teach now
Coach training programs teach AI tools in a webinar and ethics in a module, and the judgment that connects the two gets taught nowhere. Governance belongs in the curriculum as graded work rather than an appendix: sort your own touchpoints, defend the sort to somebody experienced, write the consent language, then say it out loud to a person.
The profession is not short of reference material. The ICF published an AI Coaching Framework and Standards in November 2024, built as six domains, and most credentialed coaches have never opened it. Sit with that for a second, because a reference document nobody consumes fails the same way an ungoverned tool does. Somebody did serious work, and the next stage never picked it up.
Blaming coaches for not reading it misses where the gap sits. Practitioners read what their training told them mattered.
So what belongs in a program? Tool tutorials expire inside a year. Three other things hold their value. The sort itself, run as graded work against the student’s real practice, with a defense. Consent language a student has to speak out loud to another human being, because writing it and saying it are different skills and only one of them happens in front of a client. And the barred list: the places AI does not go at all, starting with anything submitted as evidence of the coach’s own competence. A recording sent for credential review has to be the coach’s work, and a mentor cannot assess a performance that a tool quietly improved.
The format for teaching this already exists. Mentor coaching and coaching supervision are supervised repetitions on real decisions with an experienced practitioner watching, which is how judgment gets built in every field that ever had to build it. A coach training program already owns that pedagogy. It needs to point it at a new decision and grade the result.
Judgment under uncertainty is the competency underneath all of it
Nobody in these three stories was short of tools. Each was short of a defensible answer about where the human line sits and who owns it. Deciding with incomplete information, naming your reasoning, owning the call and revising when it turns out wrong is a trainable capacity, and it is the one coaching develops.
Judgment Is Trainable—With the Right Partner
Deciding with incomplete information and owning the call is what coaching develops. Work with an MCC coach who practices it.
The risk officers, the marketing chiefs and the policymakers all hold more capability than they can govern and less certainty than they need. That is the standard condition of leadership work and AI did not invent it. AI raised the stakes and shortened the clock.
If you coach executives, this is in the room now whether or not it reaches the agenda. Your clients who are already deep into AI are being asked to sign off on systems they cannot fully inspect, on a timeline somebody else set. The coaching move has nothing to do with knowing more about the technology than they do. It is holding the question they have been walking around: what have you decided a machine may not do here, and why?
Most cannot answer it yet. The ones who can were made to practice somewhere, on smaller decisions, with somebody watching who was willing to push back.
Compliance Week’s question works on a coaching practice as well as it works on a risk function. If you were designing your practice today, knowing what these tools can do and what they cost you, would you build it the way it currently runs? Most people have never been asked. The ones who have can tell you their three bins from memory.
Frequently Asked Questions
What does AI governance mean in a coaching practice?
It means a standing, written decision about which AI touchpoints run without you, which you check before anything leaves your desk, and which stay entirely human. Three bins, an owner, a date. A solo practice needs that decision as much as an enterprise does, on one page rather than in a policy suite.
Does the ICF have rules about AI in coaching?
The ICF published an AI Coaching Framework and Standards in November 2024, built as six domains. It is a standard for AI coaching applications rather than a list of approved tools for human coaches. The obligations that already bind you sit in the Code of Ethics, including Standard 2.5 on clear and appropriate boundaries, which is where disclosure runs through.
What belongs in an AI use policy for coaches?
One page. Every tool that touches client material, which bin it sits in, why, and the date you decided. Add where the data lives, whether training opt-out is on, and the retention period. Then a plain sentence in your coaching agreement, plus a spoken moment at intake for anything that runs during a session.
Who owns AI governance in a company with no compliance function?
Whoever is accountable to the customer. In a company that is the executive who signs off on the output. In a practice it is you. Having no compliance function removes the safety net rather than the obligation, along with the person whose job it would have been to notice.
Still Running Ungoverned AI Touchpoints?
Talk through your boundary sort with a coach who’s helped dozens of leaders draw the human line—and defend it.
Book a Free Consultation →


