Governing Artificial Intelligence in Regulated Institutions: Permissioned Governance, Accountability, and Fiduciary Duty
Artificial intelligence has shifted from experimental technology to institutional force within regulated environments such as higher education and healthcare. AI systems now influence decisions affecting rights, safety, access, employment, and professional judgment, yet governance structures have not evolved to match this influence. AI is commonly introduced through procurement cycles, pilots, or vendor platforms without an explicit institutional decision that authorizes use, assigns accountability, or defines conditions for refusal. The result is governance failure rather than innovation risk: systems gain influence without permission, while responsibility remains diffuse until harm occurs. This paper argues that artificial intelligence in regulated institutions must be governed as a permissioned activity rather than as a technical asset, tool category, or innovation initiative. The central failure driving AI-related harm is not model error or ethical ambiguity, but the absence of institutional authority exercised before deployment. Where AI operates without explicit permission, institutions inherit liability without deliberation; where accountability is fragmented, frontline professionals absorb risk without power; where refusal authority is undefined, governance becomes reactive and performative. The paper introduces the AI Institutional Decision-Gate Framework, a governance architecture designed for environments where legitimacy depends on law, professional standards, and public trust. The framework establishes a sequence of explicit authorization gates, including strategic justification, risk classification, data legitimacy, human accountability, impact and equity, operational readiness, and continuous oversight. Each gate requires a defined decision, specified evidence, and a clearly identified authority holder with the power to approve, constrain, or deny permission. Authorization is explicit, conditional, and revocable. A regulated AI adoption lifecycle translates this governance architecture into daily institutional practice, disciplining discovery, evaluation, design, piloting, validation, deployment, and oversight. Pilots function as containment mechanisms rather than momentum engines; deployment remains conditional; revocation authority remains active. Central to the model is the principle of non-delegable accountability: every AI system must have a named human authority with both decision power and responsibility for outcomes. Where no such authority can be identified, permission must be denied. The paper further demonstrates how durable AI governance requires policy architecture that embeds permission, accountability, and revocation into existing institutional policies, preserving governance across leadership transitions and crisis conditions. At the board level, AI governance is reframed as fiduciary duty rather than operational preference. Boards are responsible not for technical understanding, but for ensuring that institutional authority is exercised before AI systems influence consequential outcomes.
Paper
The full text of this publication is not hosted on 44B due to licensing.
Read it at OpenAlex