A framing I hear often about AI governance is a fear that it may stand in the way of actually using AI. Legal must approve it. Compliance needs to review it. Security has to sign off. By the time those conversations can be had, the momentum is gone and the tools — or the nature of what the firm is trying to accomplish — have already changed.
I understand why firms and operators may see governance this way. In some cases, that experience may have been true. But it's the wrong way to think about what governance actually does when it's built correctly.
After two years of helping to craft Orion's own AI governance program, I see governance differently: it is not a constraint on momentum or adoption. It is the operating model that helps teams adopt AI in a way that they can explain, monitor, and improve. It gives teams a clear path to move forward with confidence.
The Questions Haven't Changed
Advisory firms have always managed data security, client privacy, and supervision. AI did not create those responsibilities. AI, though, raises the stakes because the tools are more powerful, the risk surface is broader, and adoption can happen quickly. The core questions, though, are familiar.
When I think about what AI governance means at Orion, I come back to this framing: we're answering old questions in new ways. Data security, proprietary information, client privacy — these have long been hallmarks of what financial advisors have cared about and focused on in order to be responsible stewards and advisors to their own clients. AI doesn't change what we're protecting. It changes how we think about protecting it, and what it takes to do that well at scale.
When a firm approaches governance from that standpoint, it changes what the firm is actually building. Instead of a list of restrictions, the firm builds a framework that tells employees what they can do — and why they can trust it. When people understand that a tool has been vetted, that someone has defined what data goes in and what doesn't, and that the firm stands behind the environment, they use it more, not less, and are empowered to review and understand the outputs the tools are generating. That's where the efficiency comes from. Not from removing governance, but from getting it right.
Who Owns This?
One of the most common mistakes I see is treating AI governance as a single function's problem to solve for. Legal owns it, or IT owns it, or compliance owns it. What happens is that the policy ends up reflecting one function's concerns while ignoring the rest.
What I’ve found works in practice is bringing diverse stakeholders to the table before you finalize anything. Legal, compliance, security, product, and operations each bring something the others don't have, and the governance framework that emerges from that conversation is more durable than anything built in isolation. The point isn't design-by-committee. It's that if you understand everyone's needs before you write the rules, the rules are more likely to enable the work rather than obstruct it.
This requires real leadership buy-in. A governance program that lives only at the operational level is fragile. If leadership isn't leaning in — setting the expectation that the firm will adopt AI thoughtfully, investing in the process, removing blockers when they emerge — the program stalls. Governance becomes an enabler only when leadership treats it as an opportunity to apply thoughtful strategy, not as an exercise in compliance. At its core, the technology has the potential to rewrite aspects of a firm's operations, and it should be treated accordingly in terms of strategic oversight.