Artificial intelligence is everywhere. It fascinates, challenges, and transforms our organizations at an unprecedented pace.
In corporations, AI initiatives are multiplying. Opportunities seem infinite and objectives sometimes remain vague, while questions of governance, accountability, and control are frequently relegated to the background.
In this article, Alexandre Ney, Head of Innovation & Digital Solutions, invites you to explore a fictional client case study inspired by trends, studies, and market signals. This projection takes us to the year 2040 to explore the consequences of our decisions.
A story that reminds us that with AI, every decision made today leaves a footprint that could be felt for decades.
When the Lack of AI Governance Becomes a Risk to the Company
Camille Berthier took office as CEO of Terra Vitae on October 4, 2040. She is 47 years old. Until then, she had been heading the cooperative’s Italian operations. The Board recalled her on an emergency basis following the resignation of the previous CEO.
Terra Vitae is a biodynamic cooperative founded in 2021 by 28 farms on the Swiss Plateau to pool Demeter traceability and B2B marketing for Michelin-starred restaurateurs. Nineteen years later:
- 187 member farms across Switzerland, Austria, and Northern Italy;
- 242 employees at the core of the cooperative;
- and 290 million CHF in revenue.
On January 15, 2041, Camille convened the board.
“We no longer know why we make the decisions we make.”
— Camille Berthier, CEO of Terra Vitae, January 15, 2041.
The details she presented were more precise and stark.
WHAT CAMILLE FOUND IN ONE HUNDRED DAYS
- 387 AI agents are in production. No up-to-date mapping lists them.
- 73% of operational decisions are made without human approval.
- No current employee was involved in the design of the central system; the original engineers all left the cooperative between 2030 and 2034.
- The last comprehensive audit of the AI layer was conducted in 2031.
- Three strategic contracts were automatically renewed at a loss. Total: -4 million CHF.
- A European regulator has just launched an investigation into non-compliance with the AI Act, which applies to exports to the EU (transparency and human oversight).
- Three SaaS providers control the models that govern 60% of operational decisions; switching away from them would cost 12 million CHF and take 18 months.
The Board is giving Camille 90 days to come up with a credible restructuring plan. If she fails to do so, Terra Vitae will be placed under receivership.
The incident did not occur on a Tuesday at three o’clock in the morning. Terra Vitae drifted for fourteen years, with absolute confidence, into an opaque zone whose progression no one was measuring.
What is AI governance, and why is it becoming a key issue in 2026?
AI governance is the framework that an organization establishes to define:
- how AI can be used,
- by whom,
- and according to what rules.
It also includes responsibilities, control processes, and risk management. This is precisely what theISO and the NIST.
2026 marks a real turning point. It is no longer just a matter of internal best practices: AI governance is becoming an institutional, regulatory, and operational issue.
There are three very specific factors that explain this.
1️⃣ AI governance is becoming a full-fledged international issue.
On July 6 and 7, 2026, Geneva hosted the first session of the United Nations Global Dialogue on AI Governance. This is theUN’s first platform bringing together all 193 Member States, as well as businesses, researchers, civil society, and the technical community, to address this issue.
Among the topics officially discussed were: system security, human rights, transparency, accountability, human oversight, and compatibility among different governance approaches.
2️⃣ The regulations are beginning to result in specific obligations.
In the European Union, August 2, 2026, marks a major milestone in the implementation of theAI Act : authorities now have enforcement powers for several provisions, and transparency requirements regarding certain AI systems, in particular, are now in effect.
The AI Act is a regulation; AI governance is the framework established by a company to regulate its own use of AI. Effective governance can therefore help identify the systems in use, determine which rules apply to them, and ensure their compliance with the AI Act. Moreover, a Swiss company is not necessarily outside the scope of the AI Act, just as it is not necessarily outside the scope of the GDPR.
3️⃣ Switzerland is also in the process of establishing its framework.
The Federal Council has tasked several departments with preparing a draft regulation by the end of 2026, focusing in particular on transparency, data protection, non-discrimination, and oversight.
👉 If you’re interested in AI tools, check out our articles on Microsoft Copilot, the integration between AI Builder and Copilot Studio, and how to use Copilot.
Four Decisions That Weakened Terra Vitae’s AI Governance
Let’s get back to fiction. The story of Terra Vitae is not a story of incompetence.
Between 2026 and 2030, Terra Vitae did what most cooperatives of its size did: roll out AI everywhere, quickly, in response to business emergencies. 8 agents in 2026. 95 in 2030. More than 300 in 2035.
Each deployment solved an immediate problem:
- weather,
- irrigation,
- traceability,
- B2B reporting,
- customer support.
Each deployment created a dependency that no one took the time to map out.
Four decisions sealed Terra Vitae’s fate
Decision No. 1: Allow each business unit to deploy its own AI agents
The decision was well-intentioned: the IT department was overwhelmed, so marketing, procurement, logistics, and finance were allowed to choose their own tools without any central authority to coordinate them. By 2040, the cooperative was running on six different cloud platforms and four incompatible protocols, with no overall overview.
AI agents don’t communicate with each other, except when they unintentionally trigger one another, and in those cases, no one knows who triggered what.
Decision No. 2: Signing AI contracts without considering reversibility and ownership
No one negotiated a reversibility clause,the export of prompt histories, or ownership of the refined models. As a result, three suppliers hold the keys to a system that Terra Vitae does not own.
Decision No. 3: Do not version or document the prompts
At the time, prompts were considered temporary “technical files” that were never linked to business specifications or accompanied by a history.
Once the original developers had left—all of them by 2034—the prompts became the stuff of legend.
In 2040, no one knows why the pricing agent applies a coefficient of 0.847 to the Southern markets, but he has been doing so for 11 years.
Decision No. 4: Not to train executives on AI issues
This is the most low-key decision with the most far-reaching consequences. The COMEX relied entirely on the information provided by the DSI, which in turn relied on the suppliers.
When strategic decisions had to be made in 2028, 2030, and then 2033, the decision-making process relied on information that no executive could independently verify.
What Terra Vitae Reveals About AI Governance Challenges in 2026
Terra Vitae is fiction; its trajectory is not. Three signals measured today are sufficient to map its curve.
1️⃣ Gartner, August 2025: 40% of enterprise applications will incorporate AI agents by the end of 2026, up from less than 5% in 2025.
This is the fastest adoption curve ever recorded, across all technologies. But 40% of agency projects will be canceled by the end of 2027, due to spiraling costs, unclear business value, and insufficient risk management. The staircase is everywhere. The handrails are nowhere to be found.
2️⃣ McKinsey, State of AI 2025: Only 6% of the organizations surveyed are generating an EBIT impact of more than 5% from their AI investments. And these 6% have one thing in common: they redesigned their business processes before deploying the technology. Not after. The difference isn’t the technology. It’s the order in which things are built.
3️⃣ DORA 2025 (Google Cloud, 5,000 professionals surveyed) sums up the process in one sentence:
“AI doesn’t fix a team; it amplifies what’s already there.”
— DORA 2025 — State of AI-Assisted Software Engineering
AI does not fix an organization that isn’t working. It amplifies its problems—faster, on a larger scale, and with less visibility. Terra Vitae is what an organization becomes when it amplifies its flaws without ever addressing the root cause.
💡 The good news? This issue can be addressed through four key strategies that we’re implementing at Qim info.
The Four Pillars of Effective AI Governance
Each pillar addresses one of the four decisions that compromised Terra Vitae.
None of them is optional. They all must be implemented together, or none of them will work.
Strategy: Mapping and Prioritizing AI Use Cases
Before any deployment,
- We are compilinga list of use cases,
- we prioritize them by business value and risk level,
- And, above all, we address the question that no one likes to ask: What do we deliberately choose NOT to automate, and why?
This is the question that would have saved Terra Vitae, and it is also the one confirmed by McKinsey: successful organizations begin by redesigning their processes before deploying technology. Mapping is not a consultant’s deliverable; it is an annex to the strategic alignment between executive leadership and the IT department.
Technology: Guiding AI Agents Through Architecture
An AI agent shouldn’t just be “properly configured”: its framework must be embedded withinthe infrastructure itself, where a prompt cannot bypass it. This is the essence of zero-trust applied to agents, and it rests on three principles that will remain unchanged, even as the tools that support them evolve:
1- Strong identity and authentication. Each agent has a verifiable identity, explicit permissions, and time-limited access rights—exactly what we expect today from a human or a service. The building blocks of the moment are called OAuth or SPIFFE/SPIRE; tomorrow, they will be something else. The principle, however, remains the same: no agent acts without an identity or a mandate.
2- Standardized and auditable communication. Agents coordinate using open protocols rather than custom integrations, making every exchange traceable and replaceable. The A2A protocol is a current example of this; what matters is not relying on any proprietary dialect.
3- Access to tools and data through a controlled interface. An agent never attacks a system directly: it goes through a layer that exposes what it is authorized to do and logs the rest. This is the role currently played by a protocol such as MCP. The technology will change; the principle of a single, observable point of entry will remain.
In practical terms: a purchasing agent cannot change the production schedule. Not because a prompt prevents them from doing so, but because
- His identity does not give him that right
- and theinterface doesn’t provide that option.
Methodology: Ensuring the Traceability of Prompts and Decisions
Every prompt in production is versioned like code; every automated decision is logged, time-stamped, and replayable; and every agent is defined in YAML with explicit permissions, a list of authorized tools, and a managed lifecycle.
This is what DORA 2025 calls “spec-driven development ”: the business specification is written before the agent is coded, and the agent can be audited against that specification at any time. Without this discipline, you end up automating your bad practices on a large scale and only discover the problem when it’s too late.
Processes and People: Organizing Human Oversight of AI
Three roles emerge in any organization successfully transitioning to agentic AI, and none appeared in job descriptions in 2024.
- The concept architect formalizes the company’s requirements early on, in a language that the agent can execute and that a human can audit.
- The quality supervisor reviews the decisions and code generated by the agents to filter them.
- The escalation manager defines, formalizes in a contract, and enforces the thresholds at which an agent MUST stop and call a human.
Goldman Sachs began this initiative in July 2025: thousands of employees were deployed alongside 12,000 developers, with no job cuts, resulting in:
- +40% increase in productivity,
- –15% fewer bugs in production.
How can we maintain control over our AI systems over time?
Anticipating today what will be needed tomorrow
To every leader we meet, we ask the same question.
In ten years, your decisions will be driven by a system. What will you have done today to ensure it remains understandable by your teams?
In 2026, no one at Terra Vitae asked this question. Neither its leaders, nor its competitors, nor the rest of the market: everyone was too busy to pause for a dystopia that seemed improbable.
- The architecture you’re building today,
- your maps,
- your contracts,
- your versioned prompts,
- your human roles redefined,
are the only viable solution. Everything else is just a vendor’s promise.
How Can You Assess Your AI Governance Today?
Ask yourself 5 very specific questions:
- Do you know which AI systems and agents are currently being used in the company?
- Does every AI system have a clearly identified human in charge?
- Are access rights, decisions, and system changes traceable?
- Do you know what data and which providers are involved in each use case?
- Have you defined the situations in which human validation is required?
FAQ
Why Implement AI Governance in a Company?
Establishing AI governance helps to regulate the use of artificial intelligence before it spreads uncontrollably.
The goal is to minimize risks related to security, noncompliance, vendor lock-in, and opaque decision-making, while still enabling teams to innovate.
Who is responsible for AI governance within a company?
AI governance is not the responsibility of a single department.
- Management must establish the framework and take responsibility for decisions related to risks,
- Operational responsibilities are divided among the relevant teams.
The NIST AI RMF specifies that the roles, responsibilities, and lines of communication related to AI risks must be documented and that executive management is responsible for decisions regarding risks associated with the development and deployment of AI.
And in April 2026, the Swiss Federal Audit Office (CDF) stated the principle very clearly: with agent-based AI, “responsibility always lies with humans.”
💡 Important distinction: We are talking here about organizational responsibility in governance. This is not the same issue as determining who is legally liable.
Sources utilized
- Gartner — 40% of enterprise applications will integrate AI agents by 2026 (August 2025) · 40% of agentic projects abandoned by 2027 (June 2025) · “agent washing”: ~130 real vendors out of thousands (IT Symposium, Dec. 2025).
- DORA 2025 — Google Cloud, State of AI-assisted Software Development. 5,000 professionals. Seven core capabilities. dora.dev
- McKinsey State of AI 2025 — “AI high performers” (6% of respondents) are three times more likely to have redesigned their workflows before AI deployment.
- Goldman Sachs — Marco Argenti, CTO, July 2025: thousands of AI agents + 12,000 developers. +40% time-to-deliver, -15% post-release bugs.
- Linux Foundation · A2A Protocol — Standard Agent-to-Agent, 2026, supported by 150+ organizations including Atlassian, Salesforce, SAP.
- European AI Act — Regulation (EU) 2024/1689. Transparency and human oversight obligations for high-risk AI systems (entry into force of key provisions: June 2026).
Terra Vitae is a fictional biodynamic cooperative. All cited sources and data figures are real and publicly verifiable.