Logo
FrontierNews.ai

Why Governments Are Ditching Complex AI Approval Processes for Speed

Public sector organizations are abandoning slow, duplicative AI approval processes in favor of streamlined frameworks that can actually keep pace with real-world adoption. A new report from Boston Consulting Group, Salesforce, and the Centre for Public Impact reveals that while most governments have established ethical guidelines for AI, they're now facing a critical bottleneck: the day-to-day operational workflows that govern AI deployment are too complex, outdated, and slow to match the speed at which citizens and employees are already using AI tools.

The stakes are high. Weekly AI usage among citizens has risen by more than 25% since 2024, according to global data cited in the report. Yet many AI projects remain stuck in pilot phases or get delayed entirely because approval frameworks are unclear, duplicative, or simply too difficult to navigate. The result is that governments risk leaving enormous public value on the table, even as citizens demand faster, smarter public services powered by AI.

Why Are Governments Struggling to Keep Up with AI Adoption?

The problem isn't a lack of principles or ethical guidelines. Most governments have already established strong foundations for responsible AI governance. The real challenge lies in translating those high-level principles into practical, day-to-day operational processes that actually work for the people implementing AI projects.

Miguel Carrasco, managing director and senior partner at Boston Consulting Group, explained the disconnect: "Applying the principles and frameworks in practice has proven more challenging than necessary for real-world practitioners in the public service. AI projects are delayed or stalled, because frameworks are out-of-date, unclear, duplicative or the process is too hard to navigate. AI could generate significant public value, but without a simpler, more practical approach, many of those benefits risk being left on the table."

"Applying the principles and frameworks in practice has proven more challenging than necessary for real-world practitioners in the public service," said Miguel Carrasco.

Miguel Carrasco, Managing Director and Senior Partner at Boston Consulting Group

The capabilities of AI models are advancing faster than governance frameworks, guidance documents, and operational processes can keep up with. This creates a governance gap where organizations are trying to manage emerging technologies using outdated or overly rigid approval structures. The result is that valuable AI projects get trapped in endless review cycles, while shadow AI adoption continues unchecked in other parts of the organization.

What Does a Streamlined AI Governance Model Actually Look Like?

The report introduces a new operating model that separates organizational roles and clarifies how guardrails are enforced. Rather than creating additional layers of bureaucracy, this approach is designed to eliminate operational gridlocks and enable faster progress while maintaining accountability and risk management.

Real-world examples show how this works in practice. New South Wales, which the report highlights as a leader in governance maturity, compressed a specialist-heavy review process that previously took roughly 40 hours down to an intuitive 15-minute inherent-risk triage. Japan has replaced rigid preapproval mandates with a flexible, tiered report-and-review pathway tailored to project risk levels. The United Kingdom uses a mandatory central transparency standard to create a predictable path for AI usage across public departments.

These practical methods demonstrate that streamlined governance doesn't mean abandoning oversight. Instead, it means rethinking how oversight is structured so that low-risk productivity tools can move quickly while high-risk applications receive appropriate scrutiny.

How to Build a More Effective AI Governance Framework

The report outlines nine practical recommendations for governments looking to modernize their AI governance processes. These focus on simplifying how organizations assess and manage AI risk:

  • Simplify Risk Triage: Replace complex, time-consuming risk assessments with streamlined processes that can quickly categorize AI projects by risk level, allowing low-risk tools to move forward faster.
  • Clarify Accountability Roles: Ensure that everyone involved in AI governance understands who is responsible for what, eliminating confusion and delays caused by unclear decision-making authority.
  • Fast-Track Low-Risk Tools: Create expedited pathways for productivity-focused AI applications that pose minimal risk, so valuable tools don't get trapped in lengthy approval cycles.
  • Adopt a Lifecycle Approach: Use a staged, lifecycle-based methodology that reduces duplication by creating reusable artifacts and processes that can be applied across multiple projects.
  • Build AI Literacy Across Staff: Invest in training so that all employees understand how AI works and what governance requirements apply, reducing misunderstandings and compliance gaps.
  • Shift from Passive to Active Monitoring: Move away from one-time compliance forms toward continuous lifecycle monitoring that catches issues early and enables ongoing improvement.

Gisele Kapterian, public sector strategy lead at Salesforce, framed the broader challenge: "The question is no longer whether to govern AI responsibly, but whether our assurance processes are actually helping the adoption of technology that could transform public services."

"The question is no longer whether to govern AI responsibly, but whether our assurance processes are actually helping the adoption of technology that could transform public services," said Gisele Kapterian.

Gisele Kapterian, Public Sector Strategy Lead at Salesforce

What's the Real Cost of Slow AI Governance?

The economic implications are staggering. By deploying these practical governance methods, public sector organizations could unlock potential productivity gains estimated at $1.75 trillion annually on a global scale. That figure represents not just efficiency improvements, but the genuine value that AI can bring to policy, regulation, and service delivery when it's deployed responsibly and at scale.

However, the challenge extends beyond government. Across the private sector, organizations face similar governance gaps. Research highlighted by PECB found that almost a third of European businesses still do not have a formal AI policy in place, despite growing AI adoption across professional environments. This governance gap is already operational, creating cyber, legal, and reputational risks that many organizations are still underestimating.

The problem is particularly acute for small and medium-sized enterprises, which represent the largest portion of the business ecosystem yet often operate with limited governance resources and overstretched teams. AI tools promise productivity gains and operational efficiencies, which makes adoption difficult to resist. However, AI adoption without governance creates shadow AI environments where employees independently adopt tools without formal approval, security assessment, or oversight.

How Can Organizations Bridge the Gap Between Policy and Practice?

For law enforcement and security contexts, the challenge of operationalizing AI governance is particularly acute. A new external expert report from the ENACT project examines how rights-based governance can be operationalized for AI-enabled intelligence and decision-support technologies used by law enforcement authorities.

The report proposes a structured governance model organized around four complementary layers: legal qualification and purpose limitation; fundamental rights and data protection impact assessment; AI governance, risk management, and human oversight; and societal accountability through transparency, documentation, and independent review.

A key finding is that organizational and governance risks often represent the most significant obstacles to trustworthy deployment, even where technical solutions are available. These include unclear allocation of responsibilities, insufficient accountability, inadequate documentation, limited staff training, ineffective human oversight, and the absence of continuous monitoring.

The broader lesson applies across sectors: effective AI governance requires moving beyond abstract principles and regulatory compliance toward practical, measurable safeguards that can actually be implemented and monitored in real-world operations. Organizations need visibility into where AI is already being used, clear ownership of governance activities, integration of AI risk into existing cybersecurity and enterprise risk processes, and frameworks that are usable by the people who actually deploy AI systems.

As governments and organizations worldwide grapple with how to govern AI responsibly while keeping pace with rapid adoption, the evidence is clear: the organizations that succeed will be those that move beyond high-level principles toward practical, streamlined processes that make governance easier, not harder.