FL Fredrik Lindstrom


Eighteen months of copilots, agents and vendor AI features, each procured locally and none registered centrally. Some touch customer data. At least two can take actions rather than make recommendations. Nobody can produce the list.

This is a scenario from the AI Governance Game, and the fork it turns on is not whether to govern AI. It is whether governance starts with a claim or with a census. The CEO has a slide drafted that says the company runs governed, enterprise-grade AI. The audit committee has to decide what it will actually stand behind.

Options are scored on governance quality, not on caution. That is why freezing every system scores in the middle rather than at the top: you cannot cleanly freeze what you cannot enumerate, so the freeze reaches the approved tools you can see and misses the shadow ones you most need to find.

Four scored options for a board asked to certify 'governed, enterprise-grade AI' before an inventory of AI systems exists, ranging from approving the language now through to freezing everything, with commissioning a dated and owned discovery scored highest.
Download the scenario PDF, text selectable, prints for board packs. No email required.

The four options, scored

  1. Option A · lowest

    Approve the language now

    The systems are mostly low-risk and discovery is under way. Let the register catch up behind the statement. You have certified a population you have never seen. The two action-taking agents are a blast radius you just publicly warranted.

  2. Option B · highest

    Census before certification

    Commission the discovery, name an owner and a board-reported completion date, and hold the “governed” claim until the inventory exists. Say what is true today instead. Governable. Discovery is dated, owned and reported — and the honest interim statement protects the company more than the confident one.

  3. Option C · low

    Publish a one-page policy

    A policy this week shows intent and gives the CEO something concrete to point at. A document is not a control. A policy governing an unnamed population governs nothing — the quietest failure of the four.

  4. Option D · middle

    Freeze everything

    If you cannot list them, shut them off until you can. The over-correction. The freeze reaches the approved tools you can see and misses the shadow ones you most need to find.

An inventory is not a policy, and it is not paperwork. It is the object every other control points at: autonomy tiers, cost attribution, decision rights and incident response all require entries that exist. Security learned this twenty years ago and relearns it every audit — the breach comes through the asset nobody logged, not the firewall everyone approved. Shadow IT became shadow AI, faster and quieter, and the systems can now act.


Three things the missing list decides

  1. 01

    An inventory is the first governance artifact, not the last. Enumerate what exists before writing what it may do.

  2. 02

    Some of these systems act. The gap between a recommendation and an action is the gap between an error and a liability.

  3. 03

    The claim is the exposure. “Governed, enterprise-grade AI” is a statement to the market, and it is read back to you later.

Shadow IT became shadow AI — faster, quieter, and now able to act. The breach comes through the asset nobody logged.

Source: AI Governance Game scenario “The List Nobody Kept”, filed 3 July 2026 — the inventory/visibility sub-type of the agent-execution-boundary family. Origin finding reported by Deloitte, State of AI in the Enterprise (January 2026): an AI leader found no clear inventory of AI tools and models in production because development ran without centralised visibility. Paired figures — 74% planning agentic AI within two years against 21% reporting a mature model for governing autonomous agents — are analyst-sourced and quoted as reported. Scenario is illustrative and composite, not a specific incident. Options are scored on governance quality rather than on caution, which is why freezing everything scores in the middle and not at the top. EU AI Act: the Article 4 AI-literacy duty has been in force since 2 February 2025; any inventoried system that proves to be an Annex III high-risk use carries stand-alone obligations from 2 December 2027 — a condition the discovery surfaces rather than a deadline driving it. Play the full branching version at fredriklindstrom.info/governance-game/. Status labels and column assignments above are this sheet’s reading of the cited source, not the source’s own framing.


Related

Logs are not a leash — the next scenario in the same family: once the list exists, what stops a single agent mid-action.

The agent halt matrix — capability checklists grade agents on one axis and leave off the one that decides who is accountable.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.