Most AI governance failures are not caused by malice. They are caused by recognizable organizational and structural patterns – recurring failure modes that have been identified and named in the literature. Understanding these anti-patterns is the first step to avoiding or remediating them. This chapter names each one directly, explains its mechanism, and suggests remediation.
Ethics Washing
Ethics washing is the practice of using the language of responsible AI – publishing principles, appointing ethics boards, endorsing frameworks – without making the organizational or technical changes that would make AI systems actually accountable. The result is a veneer of governance over unchanged practices.
The academic critique is well established. Brent Mittelstadt’s influential analysis documented that at least 84 public-private initiatives had produced AI ethics principles statements, while actual accountability mechanisms remained largely absent. Thilo Hagendorff’s research on AI ethics guidelines similarly found that the principles most frequently cited – transparency, fairness, accountability – are often selected precisely because they are the easiest to invoke without operationalizing.
Regulators have joined the critique. The SEC charged Delphia (USA) Inc. and Global Predictions Inc. in March 2024 with making false and misleading statements about their AI capabilities – imposing $400,000 in combined civil penalties. Both firms marketed AI capabilities they did not actually possess. The DLA Piper analysis of the SEC’s continued focus on AI washing confirms that the SEC’s enforcement unit has institutionalized AI washing as a priority, extending to any public statement about AI capabilities that crosses from puffery into deception.
Remediation: Connect governance principles to specific, measurable operational requirements. If the principle is “fairness,” specify what fairness metric applies to each system, how it is measured, and what the threshold for action is. Governance principles that cannot be translated into testable requirements are decorative, not functional.
Governance Theater
Governance theater occurs when policies exist on paper – an AI policy document, a responsible AI committee, a vendor assessment process – without those policies being consistently applied in practice. The gap between the governance document and actual deployment decisions is the theater.
The Stanford HAI 2025 AI Index found that AI-related incidents are rising sharply, while standardized responsible AI evaluations remain rare – a finding consistent with widespread theater. McKinsey’s research finds that fewer than 20 percent of organizations track well-defined KPIs for their AI programs, which means most organizations have no mechanism for detecting whether their governance is actually being applied.
Remediation: Require that every AI deployment above a defined risk threshold generate a documented governance artifact – an impact assessment, a model card, a signed vendor questionnaire – before deployment approval is granted. If the governance process produces no traceable documentation, it is not functioning.
Over-Reliance on Technical Fairness Metrics
The proliferation of mathematical fairness metrics – demographic parity, equal opportunity, equalized odds – has created a new failure mode: the belief that demonstrating technical fairness on a chosen metric constitutes governance. It does not.
Cathy O’Neil’s Weapons of Math Destruction (2016) documented how mathematical optimization of measurable outcomes can entrench inequality by treating the optimization target as a proxy for fairness when it is not. Arvind Narayanan’s 21 Definitions of Fairness and Their Politics demonstrates that no single fairness metric satisfies all reasonable fairness criteria simultaneously – choices between metrics are necessarily value judgments, not technical conclusions.
Remediation: Treat fairness metrics as evidence to be interpreted, not conclusions to be declared. Document which fairness metric was selected, why, and who made that decision. Engage the populations affected by high-risk AI decisions in the evaluation process. Include qualitative assessments alongside quantitative metrics.
Audit Fatigue and Check-the-Box Compliance
In heavily regulated environments, governance processes can become compliance rituals – exercises completed to satisfy external auditors, not to generate genuine understanding or improvement. When staff fill out algorithmic impact assessments by selecting pre-approved answer templates, when vendor questionnaires are returned without meaningful review, and when governance committee meetings pass without substantive discussion of AI risk, governance has become check-the-box compliance.
Remediation: Limit the governance burden by focusing documentation requirements on genuinely high-risk systems. Use exception-based escalation: routine AI deployments should flow through streamlined review; only systems with high-impact potential require full governance documentation. This preserves governance effort for where it is most needed.
The One Ethicist Pattern
Designating a single AI ethicist – or a single governance officer – and treating that as a governance solution creates a structural failure: it places responsibility for governance in a role without authority over the systems being deployed. When the ethicist’s concerns can be overridden by a product manager or declined by a business unit, the governance function is advisory at best and performative at worst.
Remediation: AI governance authority must be connected to decision gates that can stop or delay deployments. The governance function needs approval authority over high-risk system deployments, not merely advisory access. This is how risk management functions operate in financial services – the risk function can say no, and that “no” has to be escalated, not ignored.
Incentive Misalignment
Product and development teams rewarded for speed of delivery – measured by features shipped, deployments completed, or quarterly targets hit – face incentives that systematically conflict with governance requirements. When governance slows deployment, and speed is rewarded and slowness penalized, governance loses.
Remediation: Include responsible AI metrics in performance evaluation for product and development teams. If model documentation coverage, bias assessment completion, and incident-free operation are part of how teams are assessed, the incentive structure shifts. McKinsey’s research consistently finds that organizations where governance is connected to business incentives – rather than treated as a compliance tax – achieve better responsible AI outcomes.
Frameworks Without Operationalization
The most common failure pattern across all governance surveys is the adoption of a recognized framework – NIST AI RMF, ISO/IEC 42001, a published set of responsible AI principles – without translating it into specific operational requirements for the organization. The framework sits in a document. Deployments happen without referencing it. The gap between the framework and practice is never bridged.
Remediation: When adopting a framework, immediately translate its highest-priority elements into concrete operational checklists, templates, and approval gates. Start with the inventory (what AI systems do you have?), then the risk triage (which ones matter most?), then the documentation requirements (what must exist before a high-risk deployment is approved?). A framework that generates daily operational artifacts is alive. A framework that generates a policy document is not.