Project Managers as AI Governance Leaders
Artificial Intelligence is becoming part of everyday project delivery, helping teams summarise meetings, draft documentation, analyse data, generate reports, accelerate development, and support decision-making. The benefits are significant, but so are the responsibilities.
A meeting summary might record a suggestion to postpone testing as an approved decision, prompting the team to change the schedule without authorisation. An automatically generated status report could describe a project as on track while overlooking a delayed supplier component needed for launch. A customer service chatbot might promise a refund based on an outdated policy, creating an expectation the organisation may be unable to meet.
For one of Qubika’s media clients, we built an AI-powered workflow to extract advertising sales information from PDFs and spreadsheets, with additional enrichment through connected tools. A project like this illustrates why successful delivery requires more than accurate extraction, as the team must also establish how incomplete information, conflicting records, and exceptions will be handled.
These questions connect business expectations (such as whether a solution can be delivered on time and within budget) with data quality, engineering, security, and operational ownership.
That responsibility becomes particularly important when a sponsor wants to launch quickly and internal teams have yet to agree on who will review outputs or respond to problems.
In an AI-enabled organisation, governance is becoming part of project leadership.
The New Risks Behind AI Adoption
AI introduces risks that traditional project plans may not fully capture, particularly when incomplete information becomes apparently complete work. A polished output can make assumptions difficult to spot, allowing an unresolved question to influence delivery as though someone had already answered it.
Consider a business analyst using AI to draft requirements from workshop notes about subscription cancellations. The participants agreed that customers should be able to cancel online but left the notice period and refund conditions unresolved; the generated document adds a 30-day notice period and excludes partial refunds without identifying these as suggestions. With the next sprint approaching, reviewers miss the additions and development proceeds, only for a stakeholder to question the rules during a demonstration, creating avoidable rework.
The Project Manager is well placed to raise these concerns early because they understand the business objective and maintain visibility across decisions that might otherwise remain isolated within legal, security, data, or engineering teams. For this use case, that means agreeing on who validates requirements before development, ensuring unresolved questions remain visible, and checking that the tool distinguishes confirmed decisions from assumptions. Testing with incomplete or conflicting notes helps establish where closer review is needed before an output becomes a delivery commitment.
Protecting Personal and Confidential Information
One immediate risk is the accidental exposure of personally identifiable information, or PII, alongside confidential business material. Employees may upload entire files without understanding how the tool processes or retains them, particularly when useful information and sensitive details appear together.
A business analyst identifying recurring customer complaints might submit support records containing account numbers and personal circumstances described in the comments, although neither is needed to understand the main issues. Removing names alone may be insufficient, because someone could still be recognisable from their location, role, or the circumstances of a particular incident.
Project Managers should work with the relevant specialists to establish which platforms are approved for the information involved, what must be excluded, who can access it, and what retention arrangements apply. For the complaints analysis, the team could select fields such as complaint category, product, and resolution time, then review written comments to remove unnecessary personal details. Assigning responsibility and allowing time for this preparation makes careful handling more achievable under delivery pressure.
“A useful principle is simple: an AI system should only receive the minimum information necessary to perform an authorised task.”
The Growing Challenge of Shadow AI
Shadow AI occurs when employees use AI services outside approved processes, often because the available tools cannot meet an immediate need. Easy access and quick results make these alternatives attractive when teams are working towards a deadline.
Imagine an approved tool cannot process the format of a confidential supplier proposal, so a team member uses a personal account on another platform to summarise it. The deadline is met, but the organisation has no record of which service was used or whether it was suitable for the information shared. Adoption may also be less visible, through meeting assistants, browser extensions, or features within familiar applications that employees assume are already approved.
Project Managers can make actual tool use part of onboarding and delivery discussions, including with suppliers and contractors, while identifying where approved options fall short. These conversations need a clear route for requesting additional capabilities, realistic review times, and guidance on how to proceed while a request is assessed. A workable response to unmet needs makes responsible use easier to maintain when delivery pressure increases.
Cybersecurity Must Begin with the Project
Cybersecurity needs to influence architectural choices, vendor selection, and integrations while those decisions are still open. A review near the end of delivery may uncover weaknesses that require substantial rework or restrict capabilities already promised to stakeholders.
Consider an internal assistant answering questions from company documents. When an employee asks about next year’s departmental budget, it includes figures from a restricted financial plan they would not normally be allowed to open. The answer is accurate, but it exposes an access failure that testing focused only on relevance could miss.
The team must also consider instructions hidden within retrieved material, such as text directing the assistant to send information to an external address. If the assistant can send messages or act in connected systems, following those instructions could lead to an unauthorised action.
Project Managers should involve cybersecurity specialists while these capabilities are being defined, ensuring that permission checks, action approvals, and misuse scenarios are included in design and testing. If a weakness remains close to launch, the team may need to restrict the document collection or disable certain actions until controls are validated, with unresolved risks referred to someone authorised to make the release decision.
Human Accountability Cannot Be Automated
AI can analyse information and recommend actions, but responsibility for the consequences remains with the people and organisations using it. This matters particularly when recommendations affect someone’s employment, finances, or access to services.
A recruitment tool might rank applicants in a way that disadvantages people with career breaks, placing suitable candidates further down the list. If recruiters examine only the highest-ranked applications, those candidates may never receive meaningful consideration, even though a person formally approves the shortlist. Effective oversight therefore requires access to the wider evidence and a way to question how the recommendation was reached.
Project Managers should help define what reviewers must check, who has final authority, and how uncertain cases will be escalated, with the effort reflected in staffing and operating procedures. Reviewers also need enough time to investigate and the authority to pause or override a recommendation; performance targets focused solely on speed can otherwise turn the intended safeguard into routine approval.
“Human oversight only works when people have a realistic opportunity to question the system and change the outcome.”
Building Trust Through Transparency
Users need to understand the basis and limitations of AI outputs so they can judge how much reliance to place on them. When that context is missing, a confident recommendation can appear more complete than the evidence supports.
An assistant comparing supplier proposals might recommend one option based on price and delivery time while leaving out support coverage because the documents describe it inconsistently. Without that explanation, the project team may assume all selection criteria were assessed and take the recommendation into a procurement discussion as a complete comparison.
Project Managers can help ensure that assessed criteria, supporting sources, and missing information are visible alongside the recommendation, giving users a practical way to identify what still needs investigation. Demonstrations and training should also include incomplete records and conflicting information, allowing people to practise recognising uncertainty and deciding when further checking is needed. Clear expectations help users make informed use of the system and raise concerns when its behaviour falls outside those expectations.
Governance Continues After Delivery
An AI solution’s usefulness can change as the organisation introduces new products, updates processes, or expands its use. Initial testing therefore needs to be supported by ongoing monitoring and operational ownership.
Consider a tool that routes customer enquiries to support teams. After a new product launches, it begins sending technical questions to the general enquiries queue, causing repeated transfers and longer waits. Overall accuracy may still look acceptable because most enquiries concern established products, so the issue could remain hidden unless someone examines performance across enquiry types and investigates feedback.
Before handover, Project Managers should confirm who monitors results, investigates incidents, and can restrict or pause the service, with enough capacity and budget to carry out those responsibilities. Supplier updates and proposed changes in use also need an agreed review process, while benefits measurement should include correction effort and customer impact alongside time saved. In the routing example, faster assignment has limited value if misdirected enquiries create additional work and delays elsewhere.
The Project Manager as the Connector
AI governance often requires teams to reconcile priorities that cannot be resolved within one function. The Project Manager helps turn those differences into agreements that carry through requirements, testing, and everyday operations.
In an AI-assisted invoice processing project, the sponsor may expect faster payments while finance needs discrepancies reviewed and audit requires traceable authorisation. The teams might agree that invoices matching approved purchase orders within defined tolerances can proceed automatically, with exceptions assigned to a finance reviewer. If that review effort reduces the expected savings, the sponsor needs to understand the effect before confirming the delivery commitment.
The Project Manager’s contribution is to follow these decisions across team boundaries, ensuring that assurances such as “the business has accepted it” lead to a named owner, a clear agreement, and evidence that the necessary work has been completed.
Responsible AI Is Good Project Management
Responsible AI delivery depends on connecting expected benefits to the practical conditions required to achieve them. For Project Managers, governance becomes meaningful when it influences scope, resources, and release decisions, particularly where incomplete evidence may justify a narrower launch or further testing.
Leading well in this environment requires openness to innovation and the judgement to question whether the organisation is ready to use what it has built. By keeping evidence and accountability connected to delivery commitments, Project Managers help make responsible AI use part of how the organisation works.
“AI may allow organisations to move faster, but speed without governance creates risk.”


