Centralized, hub-and-spoke, or decentralized

Lesson 2 of 5 in Designing the AI Governance Operating Model.

Every AI governance program answers one structural question before any other: where does the authority to say no live? Three archetypes cover the field, and the choice is driven less by philosophy than by three facts about your organisation — its size, its sector’s regulatory exposure, and how much AI expertise exists outside headquarters.

Centralized

One team reviews everything. A central AI governance office holds intake, assessment, approval, and monitoring for the whole enterprise.

Strengths: maximum consistency; deep expertise concentrated where reviews happen; a single evidence trail regulators love; the only model that works when in-house AI expertise is scarce.

Weaknesses: the central team becomes a bottleneck the moment volume grows — and a bottleneck with veto power breeds workarounds. Business context gets lost: the reviewer approving a clinical triage tool may never have set foot in a hospital.

Fits: smaller organisations, early-stage programs (most programs start here), and heavily regulated single-sector firms where consistency outweighs speed.

Hub-and-spoke (federated)

A central hub sets standards; embedded spokes apply them. The hub owns policy, tiering methodology, tooling, training, and the highest-risk reviews. Trained governance leads inside each business unit run intake and lower-tier reviews locally, escalating what crosses thresholds.

Strengths: scales with volume; keeps business context in the review; the hub still guarantees consistency through shared standards and quality assurance of the spokes. This is where most large programs converge.

Weaknesses: spokes drift without active calibration — same use case, different tier in two divisions. Requires real investment in training the spokes and auditing their decisions. Dual reporting lines create loyalty tension: the spoke works in the business but for the standard.

Fits: large or multi-sector enterprises, global firms navigating multiple regulatory regimes, any program whose central team is drowning.

Decentralized

Each business unit governs its own AI. No central function beyond perhaps a community of practice sharing templates.

Strengths: fastest local decisions; full business context; near-zero central cost.

Weaknesses: almost everything else. No enterprise view of the AI estate, so no one can answer a regulator’s first question ("what AI do you operate?"). Inconsistent standards mean the weakest unit sets the enterprise’s effective risk appetite. Duplicated effort everywhere.

Fits: genuinely rare cases — conglomerates of unrelated businesses with separate legal entities and separate regulators. For everyone else it is not a design; it is the absence of one, and it fails the moment a cross-cutting law like the EU AI Act asks for a single accountable answer.

Choosing an archetype — the trade-offs that decide it
DimensionCentralizedHub-and-spokeDecentralized

Consistency of decisions

Highest — one team, one standard

High if the hub calibrates spokes

Low — the weakest unit sets the floor

Speed at scale

Degrades — central queue becomes the bottleneck

Scales — routine reviews stay local

Fast locally, chaotic globally

Business context in reviews

Weak — reviewers far from the use case

Strong — spokes live in the business

Strongest, but unchallenged

Regulator readiness

Strong — single evidence trail

Strong — hub aggregates evidence

Poor — no enterprise answer exists

Typical fit

Small orgs; program launch; single regulated sector

Large, multi-line, multi-jurisdiction firms

Unrelated-business conglomerates (rare)

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.