Submitted:
02 August 2026
Posted:
04 August 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Literature Review
2.1. AI Governance and the Assumption of Organisational Control
2.2. Accountability, Organisational Design, and Structural Fragmentation
2.3. Regulatory Complexity, Proceduralisation, and Control Capacity
2.4. Conceptual Method and Theory-Building Approach
3. The Governance Inversion Hypothesis (GIH)
3.1. From Regulatory Expansion to Control Reduction
- Governance formalisation is the visible establishment of formal structures like AI committees, responsible AI frameworks, ethics policies, governance roles, and compliance systems.
- Governance control is the organisation’s actual ability to exercise authority over AI system behaviour, deployment, modifications, risk exposure, and decision outcomes.
- Fragmentation of authority,
- Symbolic governance expansion,
- Externalisation of control,
- Authority paralysis.
3.2. Mechanism I: Fragmentation of Authority
3.3. Mechanism II: Symbolic Governance Expansion
3.4. Mechanism III: Externalisation of Control
3.5. Mechanism IV: Authority Paralysis
3.6. Integrating the Mechanisms: The Inversion Pathway
3.7. Boundary Conditions and Scope of the Hypothesis
3.7.1. AI Criticality
3.7.2. Organisational Complexity
3.7.3. External Technological Dependency
3.7.4. Symbolic Compliance Pressure
3.7.5. Weak Veto Authority
4. Theoretical Implications
4.1. Reframing AI Governance as a Problem of Control
- It challenges the assumption that governance expansion necessarily strengthens organisational oversight. Existing governance frameworks frequently imply a linear relationship between regulation and control (OECD, 2022; NIST, 2023). The GIH instead proposes that the expansion of governance eventually weakens supervisory coherence under conditions of institutional complexity.
- The framework emphasises governance effectiveness over mere existence. While many organisations have established visible AI governance structures, evidence indicates that these frameworks are often poorly institutionalised, advisory, and disconnected from operational authority (Frimpong & Botchey, 2026).
- The framework views AI governance as an organisational design issue rather than just a compliance matter. Its effectiveness relies on how authority, escalation pathways, technical visibility, and intervention rights are allocated within institutions.
4.2. Extending Institutional Theory: From Decoupling to Inversion
4.3. Rethinking Accountability in AI Governance
4.4. Regulation and Governance Design
5. Managerial and Policy Implications
5.1. Managerial Implications: Governing for Control
5.2. Policy Implications: The Limits of Procedural Governance
6. Future Research Directions
7. Conclusions
References
- Beck, U. Risk Society: Towards a New Modernity; Sage, London, 1992. [Google Scholar]
- Black, J. Constructing and contesting legitimacy and accountability in polycentric regulatory regimes. Regul. Gov. 2008, 2, 137–164. [Google Scholar] [CrossRef]
- Bovens, M. Analysing and Assessing Accountability: A Conceptual Framework1. Eur. Law. J. 2007, 13, 447–468. [Google Scholar] [CrossRef]
- Burrell, J. How the Machine “Thinks”: Understanding Opacity in Machine Learning Algorithms. Big Data Soc. 2016, 3, 1–12. [Google Scholar] [CrossRef]
- Crozier, M. The Bureaucratic Phenomenon; Chicago University Press: Chicago, IL, 1964. [Google Scholar]
- European Union. Regulation - EU - 2024/1689 - EN - EUR-Lex. Eur-Lex.europa.eu. 13 June 2024. Available online: https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
- Floridi, L.; Cowls, J. A Unified Framework of Five Principles for AI in Society. Harv. Data Sci. Rev. 2019, 1, 2–15. [Google Scholar] [CrossRef]
- Frimpong, V.; Botchey, O. K. Where are the AI governance roles? An early-stage empirical mapping of presence, absence, and structure in organisational AI oversight. Businesses 2026, 6(2), 18. [Google Scholar] [CrossRef]
- ISO. ISO/IEC 23894:2023; Information technology—Artificial intelligence—Guidance on risk management. International Organisation for Standardisation, 2023a. Available online: https://www.iso.org/standard/77304.html (accessed on 20 January 2026).
- ISO. ISO/IEC 42001:2023; Information technology—Artificial intelligence—Management system. International Organisation for Standardisation, 2023b. Available online: https://www.iso.org/standard/42001 (accessed on 20 January 2026).
- Jaakkola, E. Designing conceptual articles: four approaches. AMS Rev. 2020, 10, 18–26. [Google Scholar] [CrossRef]
- Koshiyama, A.; Kazim, E.; Treleaven, P.; Rai, P.; Szpruch, Lukasz; Pavey, G.; Ahamat, Ghazi; Leutner, Franziska; Goebel, R.; Knight, A.; Adams, J.; Hitrova, C.; Barnett, J.; Nachev, Parashkev; Barber, D.; Chamorro-Premuzic, T.; Klemmer, K.; Gregorovic, Miro; Khan, S.; Lomas, E. Towards algorithm auditing: managing legal, ethical and technological risks of AI, ML and associated algorithms. R. Soc. Open Sci. 2024, 11(5). [Google Scholar] [CrossRef] [PubMed]
- Meyer, J.; Rowan, B. Institutionalised Organisations: Formal Structure as Myth and Ceremony. Am. J. Sociol. 1977, 83, 340–363. [Google Scholar] [CrossRef] [PubMed]
- Mittelstadt, B. Principles alone cannot guarantee ethical AI. Nat. Mach. Intell. 2019, 1(11), 501–507. [Google Scholar] [CrossRef]
- Morley, J.; Floridi, L.; Kinsey, L.; Elhalal, A. From What to How: An Initial Review of Publicly Available AI Ethics Tools, Methods and Research to Translate Principles into Practices. Sci. Eng. Ethics 2020, 26, 2141–2168. [Google Scholar] [CrossRef] [PubMed]
- NIST. AI Risk Management Framework. Artif. Intell. Risk Manag. Framew. (AI RMF 1.0) 2023, 1(1). [Google Scholar] [CrossRef]
- OECD. Framework for the Classification of AI Systems. In OECD Digital Economy Papers; 2022. [Google Scholar] [CrossRef]
- Papagiannidis, E.; Mikalef, P.; Conboy, K. Responsible Artificial Intelligence Governance: A Review and Research Framework. J. Strateg. Inf. Syst. 2025, 34, 101885. [Google Scholar] [CrossRef]
- Pasquale, F. The black box society: The secret algorithms that control money and information; Harvard University Press, 2015. [Google Scholar]
- Perrow, C. Normal Accidents: Living with High-Risk Technologies; Basic Books: New York, 1984. [Google Scholar]
- Power, M. The audit society: rituals of verification; Oxford University Press Catalogue, 1997. [Google Scholar]
- Power, M. Organised Uncertainty: Designing a World of Risk Management; Oxford University Press, 2007. [Google Scholar]
- Prem, E. From Ethical AI Frameworks to tools: a Review of Approaches. AI Ethics 2023, 3(1). [Google Scholar] [CrossRef]
- Rahwan, I. Society-in-the-loop: programming the algorithmic social contract. Ethics Inf. Technol. 2018, 20(1), 5–14. [Google Scholar] [CrossRef]
- Raji, I. D.; Smart, A.; White, R. N.; Mitchell, M.; Gebru, T.; Hutchinson, B.; Smith-Loud, J.; Theron, D.; Barnes, P. Closing the AI accountability gap: Defining an End-to-End Framework for Internal Algorithmic Auditing. In Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency; 2020; pp. 33–44. [Google Scholar] [CrossRef]
- Shneiderman, B. Bridging the Gap between Ethics and Practice: Guidelines for Reliable, Safe, and Trustworthy Human-Centred AI Systems. ACM Trans. Interact. Intell. Syst. 2020, 10, 1–31. [Google Scholar] [CrossRef]
- Simon, H. Theories of Bounded Rationality. In Decision and Organisation; McGuire, C.B., Radner, R., Eds.; Elsevier: Amsterdam, 1972; pp. 161–176. [Google Scholar]
- Vaughan, D. The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA; University of Chicago Press: Chicago, 1997. [Google Scholar] [CrossRef]
- Weick, K. E.; Sutcliffe, K. M. Managing the unexpected: Resilient performance in an age of uncertainty, 2nd ed.; John Wiley & Sons: San Francisco, 2007. [Google Scholar]
- Wieringa, M. What to account for when accounting for algorithms. In Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency; 2020; pp. 1–18. [Google Scholar] [CrossRef]

| Proposition | Mechanism | Core Claim | Observable Indicator |
|---|---|---|---|
| P1 | Authority fragmentation | Regulatory pressure expands formal AI governance structures while reducing concentration of operational decision authority. | Multiple governance committees, overlapping reporting lines, unclear veto authority, duplicated oversight functions, fragmented escalation pathways. |
| P2 | Symbolic governance expansion | Regulatory pressure increases the visibility of governance structures without a proportionate improvement in operational control. | Ethics frameworks without enforcement power; advisory governance roles; compliance-oriented reporting systems; governance policies disconnected from operational intervention. |
| P3 | Externalisation of control | Reliance on external AI infrastructures weakens alignment between organisational accountability and operational control. | Dependence on proprietary vendors, cloud-based AI services, limited access to model architecture or training data, restricted auditability of third-party systems. |
| P4 | Authority paralysis | Procedural layering reduces the speed and coherence of organisational intervention in AI-intensive systems. | Slow escalation processes, delayed intervention decisions, excessive layers of approval, and governance bottlenecks during AI incidents or system changes. |
| P5 | Governance inversion effect | Organisations with high governance formalisation but weak operational authority are more likely to experience governance inversion. | High governance formalisation combined with weak intervention capability, low authority concentration, fragmented accountability, and an inability to effectively override AI decisions. |
| P6 | Boundary conditions | AI complexity, third-party dependency, and weak internal authority strengthen the regulation–control inversion effect. | High-risk AI deployment, extensive vendor dependency, opaque AI systems, weak institutionalisation of governance, limited technical oversight capacity. |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).