There is now broad agreement on what enterprise AI governance principles say. Accountability, transparency, fairness, robustness, and human oversight appear in nearly every published set, with variations of emphasis rather than substance. The agreement is genuine and it is also the least useful part of the material.
A principle constrains nothing until it is translated into something an organisation can fail. "We are accountable for our AI systems" is not a control. "Every model in production has a named individual accountable for its performance, reviewed quarterly, with the register available to internal audit" is one, and the distance between the two sentences is where the work sits.
Accountability and the committee problem
Accountability fails in a characteristic way: it is assigned to a body rather than a person. A steering committee accountable for AI risk is a committee that meets; when something goes wrong there is no individual whose judgement is being examined, and the review becomes a discussion of process.
Frameworks that work name an individual for each system, with the committee as the escalation route rather than the owner. This is uncomfortable to implement precisely because it is a real allocation of risk.
Transparency toward whom
Transparency requirements are frequently written without specifying an audience, and the audiences want incompatible things. A regulator wants the documentation trail. An affected individual wants to know why a decision about them came out as it did. An enterprise customer wants to know what the system was trained on and what it is validated for. A researcher wants the evaluation methodology.
Organisations that write one transparency statement satisfy none of them. The ones that work maintain distinct artefacts for distinct audiences and are clear internally about which is which.
Why the ratings interest changes things
As AI governance disclosure attracts attention from rating agencies, assurance providers and institutional investors, the standard shifts from stated to demonstrable. A framework that reads well and cannot be evidenced becomes a liability rather than a neutral, because the gap between the two is now the thing being examined.
Practically, this pushes documentation toward artefacts generated by the process rather than describing it — approval records, evaluation results, incident logs, register extracts — and away from the narrative policy document as the primary evidence.