Governance theatre is what happens when an AI governance framework produces all the right artefacts – policies, processes, risk registers – without producing any of the substance behind them. The documentation looks complete. The controls are documented. The right language appears in the right places. And the actual governance is largely non-functional.
It is more common than most organisations would admit, and more dangerous than it looks. Not because the people involved are acting in bad faith – most governance theatre comes from organisations trying earnestly to do the right thing – but because it creates a false sense of security that makes the discovery of real gaps considerably more disruptive than if no governance had been claimed at all.
What an AI governance framework looks like as theatre
The signs of governance theatre are recognisable once you know what to look for, and they tend to cluster in predictable ways.
The policy exists but is not operationally embedded. There is an AI acceptable use policy, possibly a comprehensive and professionally formatted one. It was communicated once, at launch, and has not been mentioned since. A significant proportion of staff do not know it exists. Those who do have not read it carefully. The controls it describes are not reflected in how AI tools are actually approved, used, or monitored.
The risk register was created and never maintained. It was produced as part of an initial governance exercise and contains risks relevant at the time. Nothing has been updated to reflect the AI usage that has grown since, the new tools adopted, the supplier changes that have happened, or the new risk categories that have emerged. It provides a historical snapshot and gets treated as a current document.
The approval process exists on paper but not in practice. There is a documented process for assessing and approving AI tools before adoption. In reality, tools get adopted informally, added to the approved list retrospectively when anyone remembers, or simply used without ever being formally assessed. The process describes what should happen rather than governing what does happen.
Accountability is notional. The framework names functions and roles as responsible for various governance activities. In practice, nobody is actively exercising those accountabilities. Nobody owns the risk register update. Nobody is monitoring the approved tool list against actual usage. Nobody is tracking supplier term changes. The accountability structure describes responsibility that is not being fulfilled.
Why governance theatre happens
Governance theatre is rarely deliberate deception. It is usually the result of a governance programme built to satisfy a specific pressure – a board question, an audit requirement, a customer request – rather than to function operationally.
The pressure arrives. Documentation gets produced quickly. The pressure is satisfied. The documentation becomes the governance programme by default, without the operational embedding – training, process integration, ownership, review cadences – that would make it work.
Time pressure is the most common cause. Building governance documentation is faster than building governance operations. Documentation can be produced in weeks. Operational embedding takes months. When the timeline gets compressed, the documentation gets produced and the operational work gets deferred. The deferral often becomes permanent.
Organisational complexity adds to this. AI governance touches IT, security, legal, compliance, HR, and business operations simultaneously. Coordinating across those functions to build something that works in practice is considerably harder than producing documentation each function signs off on without needing to change how it operates.
The test that separates theatre from reality
The most reliable test of whether an AI governance framework is operational or theatrical is to ask operational questions rather than documentation questions.
Not “do you have an AI acceptable use policy?” but “can you tell me, without preparing anything in advance, what your policy says about using AI tools to draft communications that include customer information?”
Not “is there an approval process for AI tools?” but “walk me through the last three tools that went through it: what was assessed, who made the decision, how long did it take, and where is the record?”
Not “do you have a risk register?” but “when was a risk last added or updated, what prompted that, and who owns the register?”
The answers tell you immediately whether governance is operational. Organisations with genuine governance answer these specifically and confidently. Organisations with governance theatre struggle to answer them at all, or answer at the documentation level rather than the operational one.
What operational governance actually requires
Moving from governance theatre to an AI governance framework that actually works requires two things documentation alone cannot provide: genuine ownership and consistent operational practice.
Genuine ownership means named individuals actively exercising their governance responsibilities rather than holding a notional accountability. Someone who maintains the approved tool inventory. Someone who runs the approval process and makes decisions rather than coordinating them. Someone who owns the risk register and updates it based on operational observation. Someone at leadership level accountable for the overall programme who receives regular evidence that it is functioning.
Consistent operational practice means governance embedded in how work happens rather than sitting alongside it. Approval processes that staff actually use. Policies referenced where decisions get made. Review cadences that happen on schedule rather than when someone remembers to organise them. Monitoring that surfaces issues rather than confirming nothing is visibly wrong.
Neither requires a large programme or significant resources. They require intention, follow-through, and the honesty to acknowledge when governance is not functioning and fix it rather than document around it.
If you want an honest assessment of whether your AI governance framework is operational or theatrical, Black Chili’s AI Governance and Guardrails Design service builds the real thing.
If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.