---
title: "The Executive Exception Is Killing Governance"
date: "2026-07-28"
summary: "Governance rarely fails because employees ignore the rules. It fails when leaders create exceptions for themselves. Shadow AI is simply the latest example of a much older organisational problem."
canonical: "https://thepragmaticcio.net/articles/the-executive-exception-is-killing-governance/"
tags: "Governance, Leadership, Shadow AI, CIO, Executive Leadership, Corporate Culture, IT Strategy"
---

# The Executive Exception Is Killing Governance

Governance rarely fails because employees ignore the rules. It fails when leaders create exceptions for themselves. Shadow AI is simply the latest example of a much older organisational problem.

![Employees follow leadership far more closely than they follow policies.](exec-exception.png "Employees follow leadership far more closely than they follow policies.")

Most organisations believe governance fails from the bottom up.

Employees ignore policies. Teams find workarounds. Departments create their own processes. IT spends its time chasing Shadow IT, Shadow AI and countless other exceptions.

It's an easy narrative to believe.

It's also usually wrong.

A recent survey found that senior executives are twice as likely to use unauthorised AI tools as regular employees. Most knew the risks. Most understood the security implications. They simply chose speed over the approved route.

At first glance, this looks like an AI problem.

It isn't.

It's a governance problem.

More importantly, it's a leadership problem.

## Governance is a leadership behaviour

Every organisation has policies.

Travel policies.

Procurement policies.

Security policies.

Architecture standards.

Expense policies.

Data classification.

AI governance.

On paper, they often look comprehensive. The assumption is simple: publish the rules, communicate them well enough, and people will follow them.

But that's never how culture works.

People don't learn organisational values from reading policy documents.

They learn them by watching what leaders do.

If the executive team follows the rules, most employees will too.

If the executive team regularly creates exceptions for itself, everyone notices.

Culture doesn't begin with policy.

It begins with behaviour.

## Every organisation has "the exception"

Almost every CIO has encountered it.

There is always someone who needs special treatment.

The executive who insists on using a different collaboration platform.

The department that cannot possibly follow the procurement process.

The senior leader who requires an exception to the travel policy.

The project that simply cannot wait for architecture approval.

The director who uploads confidential information into an AI tool because "it's only this once."

Each exception seems reasonable when viewed in isolation.

The problem is that employees never experience them in isolation.

They see patterns.

And patterns create culture.

Once people conclude that governance only applies to some people, it stops being governance.

It becomes negotiation.

## Shadow AI is simply today's symptom

Much has been written about Shadow AI over the past year.

The technology is new.

The behaviour isn't.

Twenty years ago, it was personal email.

Then it became Dropbox.

Then Google Drive.

Then messaging platforms.

Now it's AI.

The technology keeps changing.

Human behaviour doesn't.

People don't usually bypass governance because they enjoy breaking rules.

They bypass governance because they believe the approved path prevents them from getting their job done.

Executives are no different.

If anything, they are under greater pressure to make decisions quickly, respond to markets and keep organisations moving.

When they choose an unauthorised AI tool, they're often making the same calculation every employee makes.

Which route gets me the answer fastest?

That's uncomfortable.

Because it suggests the problem may not be the individual.

It may be the organisation.

## The danger isn't the exception

Every organisation needs exceptions.

No governance framework should be so rigid that it ignores business reality.

Sometimes the rules genuinely need bending.

The danger comes when exceptions stop being exceptional.

Once leaders repeatedly bypass the approved process, employees receive a completely different message.

The written policy says one thing.

Leadership behaviour says another.

People almost always believe behaviour.

That's why governance doesn't collapse because employees ignore policies.

It collapses because leaders teach them which policies are optional.

## CIOs find themselves in an impossible position

This creates one of the most difficult leadership challenges in technology.

The CIO owns the governance.

The CISO owns the risk.

But neither usually owns the authority to challenge the CEO or the executive team in the same way they might challenge everyone else.

That creates an uncomfortable imbalance.

IT becomes responsible for managing risks it cannot always prevent.

Even worse, attempts to become the "AI police" or the "governance police" rarely succeed.

Governance enforced through fear creates workarounds.

Governance supported through trust creates adoption.

The objective should never be to stop innovation.

The objective is to make the approved route the obvious choice.

## Every exception spends organisational trust

This is the part organisations often overlook.

An executive exception isn't free.

Every time a senior leader bypasses governance, they spend a little organisational trust.

Employees notice.

Managers notice.

Future policy discussions become harder.

The next security initiative faces greater resistance.

The next compliance programme receives less support.

Not because the policies are bad.

Because people have already concluded that some individuals don't have to follow them.

Trust, once spent, is difficult to earn back.

## The real measure of governance

Perhaps organisations are measuring the wrong thing.

Instead of counting policy breaches...

Instead of counting Shadow AI users...

Instead of counting governance exceptions...

Perhaps the better question is this:

**Why do people feel they need an exception in the first place?**

If executives consistently choose the unofficial route, it may be telling us something uncomfortable.

Perhaps approval takes too long.

Perhaps the approved tools aren't good enough.

Perhaps governance has become a process for saying "no" instead of enabling progress.

Perhaps the business has simply outgrown the operating model designed to support it.

These are far more valuable conversations than debating whether another policy should be written.

## Final thought

Governance isn't measured by how many policies an organisation has.

It's measured by whether its leaders believe those policies are worth following.

Employees don't learn governance from the handbook.

They learn it by watching which rules leadership quietly exempts itself from.

Because the executive exception rarely stays in the executive suite.

Sooner or later, it becomes everyone else's exception too.

---

*Originally published on **The Pragmatic CIO**.*

*If this article resonated with you, consider subscribing for weekly insights into technology leadership, governance, organisational design and the realities of modern CIO life.*
