
ARTICLE | August, 19
Enterprise AI governance: why democratizing access isn't enough
By Florencia Donnarumma
Key takeaways
Ungoverned AI access creates duplicated tools and runaway token spend across teams.
AI frees up individual time, but that time rarely turns into new output for the business.
Real AI governance framework means access controls, a central tool catalog, and cost measurement by team, not a compliance checkbox.
AI adoption in software development brings rising costs, harness engineering to keep agents in check, and a shift from human-in-the-loop to human-on-the-loop oversight.
Table of contents
When a company opens AI access to everyone with no guardrails, two things happen at the same time. The first shows up fast: duplicated tools, nobody tracking what’s actually in use, spend on tokens climbing with no one watching it. The second is quieter and more expensive: the productivity AI unlocks doesn’t always stay in the business. A person finishes a task in a fraction of the time it used to take and spends the rest of that time on something else, not on generating more value for the company.
The business pays the AI bill either way. The return, more often than not, shows up nowhere. A recent McKinsey survey found that fewer than four in ten organizations can point to any impact on their bottom line from AI, and most of those that do put it at under five percent.
AI governance and the challenge of enterprise AI adoption
Democratizing AI access sounds good in a boardroom slide. In practice, without AI governance framework, it tends to create the same problem on two fronts:
- Operational chaos. Every team picks its own tool, runs its own integration, pays for its own license. This is shadow AI, and nobody has a full picture of what’s being used, with what data, at what cost. The AI tool inventory of a mid-size company ends up looking more like an accident than a decision. This is a pattern showing up across the market: sanctioned access to AI has grown sharply over the past year, yet less than 60 percent of employees who actually have access use it in their real day-to-day workflow. Access is not the same thing as adoption, and adoption is not the same thing as impact.
- The invisible productivity paradox. This is the part that gets talked about the least. AI delivers on its promise at the individual level: the task gets done faster. The problem is that speed rarely translates into more output for the business. It gets absorbed into the day, used to offset other inefficiencies, or simply disappears because no one defined what to do with the time it freed up.
Governance stops being a compliance checkbox and becomes a growth lever. Without the access governance layer (who can use what, with what data), a central catalog that keeps every team from reinventing the same solution, and real measurement of usage and cost by team or project, a business has no way of knowing whether AI is generating value or just generating expense. That last piece, cost measurement, is proving to be he biggest differentiator between companies that see AI ROI and companies that don’t. Nearly half of organizations have already had to slow down or cut back AI agent deployments after costs outpaced the value they were getting.
AI-native software development (SDLC)
Engineering is where this tension shows up in its purest form, and it’s where we have the clearest data of our own to share.
The rising cost of AI in engineering
We’ve seen it firsthand: rolling out AI tools across an engineering team is enough to send spending up dramatically almost overnight. An SME can see its AI spending go from zero to USD 20,000 a month. At larger organizations, those numbers multiply by a hundred. The question that follows is the one every business democratizing AI access needs to ask itself: what are we getting for what we’re paying, and what results are we actually seeing?
Some tasks do see real time gains from AI in software development. But as AI makes it possible to run more processes and ship more builds at once, the work itself gets more complex, not less. The time that used to go into writing code now goes into specifying exactly what an agent needs to build, and verifying it did it correctly. The work doesn’t disappear, it moves, and it opens the door to new challenges along the way. What matters is whether that shift is a deliberate decision or an unmanaged side effect.
When something gets cheaper to produce, the response isn’t less production; it’s more. This is a version of Jevons’ paradox. A company that could once afford to invest 10,000 dollars in one system can now build ten systems with that same budget. Software doesn’t become unnecessary, it multiplies, and with it come new problems around coordination, maintenance, and monitoring. Businesses will still need people. They’ll just need them focused on different work.
Harness engineering: the technical version of guardrails
Left unchecked, models want to generate. They take liberties, they hallucinate, they fill in gaps nobody asked them to fill. Our answer wasn’t to trust judgment case by case, but to build deterministic, repeatable controls: automated tests, quality gates, scripts that don’t depend on any one person’s read of the moment. Some of these controls are computational: fast, deterministic, and reliable, the kind that run in milliseconds and either pass or fail with no ambiguity, like tests, linters, or type checks. Others are inferential: semantic, slower, and probabilistic, closer to judgment than to a rule, like having a model review another model’s work. Both have a place, but they’re not interchangeable, and knowing which one a given problem calls for is its own skill. This is, at a technical level, the exact same principle we’re arguing for at the organizational level: AI works when it has guardrails, not when it runs unchecked.
Human on the loop (HOTL) vs. human in the loop (HITL)
Most AI systems start out human in the loop: the workflow pauses at a checkpoint until someone reviews and approves what the AI produced before anything moves forward. That makes sense early on, when trust in the system is still being built, when a wrong call would be costly or hard to undo, or when the volume of decisions is still low enough that review doesn’t slow things down.
Scaling without becoming a bottleneck means moving away from that checkpoint model and toward supervising the system from above. It’s a concrete version of the broader point about productivity: instead of one person doing the same work faster, one person oversees a system that generates more value than they could generate alone. Staying in the loop indefinitely caps how much a team can build, no matter how good the model gets.
The new role AI governance created
We identified early that this requires a dedicated function: the AI or platform engineer, responsible for building the harness, the infrastructure, the controls, and the governance that keep agentic work measurable, monitored, and standardized. AI governance in software development stopped being a good intention and became a job description. This mirrors what we’re seeing play out at scale elsewhere: companies that consolidate agent capabilities into a single platform and catalog, instead of letting every team build its own, eliminate somewhere between 30 and 50 percent of work that was never essential to begin with.
Technology solved the easy part. What does AI transformation actually take?
Creating things today is faster, cheaper, and more accessible than it has ever been. AI got democratized the way software did before it, and the way video and design did before that.
The hard part is organizational, and it looks the same whether you’re talking about a hundred employees with unsupervised access to AI tools or an engineering team running agents in production. It’s building the governance layer that decides who uses what, with what data. It’s having a catalog that keeps ten teams from reinventing the same solution. It’s measuring usage and cost by team and by project with the same rigor applied to any other investment. And above all, it’s redefining what productivity actually means: the time freed up turns into new output for the business, regardless of how much sooner any one person finishes.
The question worth asking goes beyond having access to AI. It’s whether anyone in the business can tell you what that access is actually producing.
AI sends the bill no matter what. It’s governance that decides if the return shows up too.
Ready to move from AI ambition to operational clarity?
Patagonian is a tech consulting partner for operations-heavy industries. If your organization is ready for the next step, take our free AI Readiness Self-assessment or talk to our team about carrying out an Operational Discovery.
Frequently asked questions
1. What does it mean to democratize AI access in the enterprise?
It means giving employees broad, self-serve access to AI tools without a layer that governs who can use what, with what data, and at what cost. Access alone isn’t the problem, the absence of governance around it is.
2. Why doesn’t AI adoption show up in productivity or revenue numbers?
Because the time AI frees up at the individual level rarely gets redirected toward new business output. Without a deliberate plan for what that time should produce, it gets absorbed into the day or offsets other inefficiencies instead of generating value the business can measure.
3. What’s the difference between human-in-the-loop (HITL) and human-on-the-loop (HOTL) AI systems?
Human-in-the-loop means a person reviews and approves AI output at a checkpoint before anything moves forward, useful early on or when a mistake would be costly. Human-on-the-loop means a person supervises the system from above, stepping in only when something breaks, which is what allows a team to scale without becoming the bottleneck.
4. Why do AI costs escalate so quickly in software development?
Because rolling out AI tools across an engineering team multiplies usage fast. An SME can go from spending nothing to USD 20,000 a month within a short rollout window, and that number scales up sharply at larger organizations. Without cost visibility by team or project, spend grows faster than anyone’s ability to justify it.
Sources
- The State of AI in 2025: Agents, innovation, and transformation. McKinsey & Company
- State of AI in the Enterprise 2026. Deloitte AI Institute
- Global AI Pulse Q2 2026. KPMG International
- Harness engineering for coding agent users. Martin Fowler / Thoughtworks
- One year of agentic AI: Six lessons from the people doing the work. McKinsey & Company
Latest blog posts
- All Posts
- Technology
- Insurance
- Healthcare
- Finance
- Energy
- Education


