Your AI governance gap is why design delivery keeps stalling

Vice President, Digital Experience and Engagement
  • Twitter
  • LinkedIn

The usual sequence goes like this: A design team starts experimenting with AI. It finds genuinely useful applications. Word spreads. And then, somewhere around the point where it touches customer data or a public-facing decision, legal, security, or accessibility asks a question nobody has an answer to.

Which tools are approved? What can be uploaded? Who reviewed this output? What happens when it is wrong?

Without answers, one of three things follows. The team stops, and the capability dies. The team continues informally, and the organization acquires risk it cannot see. Or every project invents its own rules, and the organization acquires inconsistency it cannot audit.

All three outcomes come from the same root: governance arrived after adoption instead of alongside it.

 

What Changed in 2026

This is no longer an internal policy debate. Two regulatory positions moved, and both land directly on experience design work.

EU AI Act transparency obligations took effect August 2, 2026. The Digital Omnibus agreement reached earlier this year postponed the high-risk system deadlines, moving stand-alone Annex III systems to December 2, 2027 and AI embedded in regulated products to August 2, 2028. But Article 50 transparency requirements proceeded on the original schedule, with a four-month grace period for watermarking obligations on systems already in market.

The practical effect for design teams is that AI-driven customer-facing experiences now carry disclosure obligations. That is an interface design problem before it is a legal one, and design is where it gets solved or missed.

European Accessibility Act enforcement began June 28, 2025. The harmonized standard, EN 301 549 v3.2.1, incorporates WCAG 2.1 Level AA in full. Coverage includes e-commerce, banking, electronic communications, and audiovisual media, applying to any organization selling to EU consumers regardless of headquarters. National penalties reach roughly €900,000 in Sweden, €600,000 in Spain, and up to 5 percent of annual turnover for serious breaches in France and Italy.

Set that against the 2026 WebAIM Million: 95.9 percent of top home pages carrying detectable WCAG failures, average errors up 10.1 percent, the first regression in six years, with WebAIM attributing part of it to "automated or AI-assisted coding practices."

Production volume rising, measured accessibility declining, enforcement live. Governance stopped being a philosophical position this year.

 

Proportional Review, or People Will Route Around You

The fastest way to guarantee ungoverned AI use is to require legal review for all of it. People have deadlines. They will use the personal account.

A tiered model handles this, and the tiers should be defined by consequence rather than by tool.

Low consequence. Brainstorming, outlines, meeting summaries, formatting, exploratory concepts using no sensitive information. Approved tools, no special documentation, no review gate. This tier should cover most daily use, and if it does not, the tiering is wrong.

Moderate consequence. Research synthesis, journey analysis, prototype content, heuristic reviews. Approved enterprise systems, named human owner, expert validation before the output informs a decision, source documentation.

High consequence. Anything touching sensitive data, regulated decisions, eligibility, accessibility conformance claims, public communications, or high-impact customer journeys. Full documentation, mandatory human review, defined accountability, and traceability sufficient to reconstruct how a decision was reached.

The discipline is putting work in the right tier honestly. Most organizations either over-classify everything, which kills adoption, or under-classify the one flow that determines whether a customer qualifies for something.

 

Data Rules That People Can Follow

Design work touches customer data, employee data, research recordings, product plans, and intellectual property, frequently within the same file.

The guidance that works is specific rather than principled. Replace "handle data responsibly" with a named list: this information may go into these systems, this must be de-identified first, this never enters a model under any circumstances, this is retained for this long.

Data minimization is the operating principle. Provide only what the task requires. Most teams paste an entire transcript when three anonymized excerpts would do, because pasting the whole thing is easier and nobody told them not to.

Research material deserves particular attention. Participants consented to a study, not to having their words become training context. That is an ethical obligation independent of what any regulation currently requires.

 

Human Accountability, Named

Every AI-assisted activity needs a person who owns the output. Not a team. A person.

That individual reviews what was produced, validates the claims that matter, evaluates whether the context was right, and approves how it gets used. The review depth should track the tier. A brainstorm needs a glance. An eligibility flow needs real scrutiny from someone qualified to give it.

The failure mode is diffusion. Output gets generated by one person, lightly reviewed by another, and presented by a third, and nobody in the chain believes they were the one who verified it. Six months later a claim in a deck cannot be traced to any evidence and nobody remembers whether it came from a customer or a model.

Which is why the single most valuable governance control is also the cheapest: label the provenance of everything at the moment it is created. Real research versus synthetic. Human-authored versus AI-assisted. Verified versus unverified. It costs seconds and it is the only thing that still works when memory fails.

 

Accessibility and Inclusion Need Explicit Treatment

AI helps with accessibility. It generates alternative text, flags contrast failures, reviews language complexity, and extends coverage across pages no human team would reach.

It also has a documented ceiling. Deque's analysis of more than 13,000 pages found automated testing detects 57.38 percent of accessibility issues, mapping to only 16 of the 50 WCAG success criteria. The remaining criteria require understanding what the interface is for, which is exactly what automation cannot supply.

Governance should state where automated checking suffices, where expert review is mandatory, and how conformance claims are substantiated. Given EAA enforcement, a conformance claim is now a legal statement, and "our tool said it passed" is a weak position when 43 percent of issues and 34 of 50 success criteria are outside what the tool assesses.

Inclusion needs separate attention, and the research here is unambiguous. Santurkar and colleagues evaluated language model outputs against the views of 60 US demographic groups and found substantial misalignment, worst for older and widowed respondents. The finding that matters for governance: that misalignment persisted even when the models were explicitly steered toward the specific group.

So a review step that asks "did we prompt it to consider diverse users" does not do the work. Ask instead, as a documented step, whose needs this output has quietly ignored, and validate against real people from those groups when the decision is consequential.

 

Traceability Without Bureaucracy

You do not need to log every prompt. You do need to be able to answer, months later: what source material informed this, where was AI used, who reviewed it, what assumptions were made, what customer evidence existed, and why the decision was approved.

That is six fields, not a compliance regime. It supports quality, learning, reuse, and the audit conversation nobody plans for. It is also the mechanism that lets an organization distinguish work grounded in evidence from work that merely sounds grounded, which becomes harder to tell apart every year.

 

Treat It as a Living Capability

AI tools, regulations, and organizational needs are all moving. The EU AI Act deadlines shifted twice in eighteen months. A policy written to anticipate every scenario will be wrong within two quarters and, worse, will be treated as authoritative while it is wrong.

Establish principles, name owners, define the review process, and schedule a genuine reassessment against new use cases, tool changes, team feedback, quality incidents, and regulatory developments. Governance that is revised on a cadence stays useful. Governance that is published once becomes a document people cite in meetings and ignore in practice.

 

Why This Is an Accelerator

Design teams resist governance because it reads as friction. In practice the absence of it is the friction.

A team that knows which tools are approved, what data it may use, when review is required, and who owns the outcome moves faster than one relitigating those questions on every project. The uncertainty is what slows people down. Clarity is what lets them stop asking.

Governance belongs at the front of an AI-enabled design practice, because it is the condition that makes every other step in this series safe to take at speed.

AdobeStock_1280798065

Schedule an AI-Enabled Experience Design Working Session

Learn more

 

Sources