Centralized, hub-and-spoke, or decentralized
Lesson 2 of 5 in Designing the AI Governance Operating Model.
Every AI governance program answers one structural question before any other: where does the authority to say no live? Three archetypes cover the field, and the choice is driven less by philosophy than by three facts about your organisation — its size, its sector’s regulatory exposure, and how much AI expertise exists outside headquarters.
Centralized
One team reviews everything. A central AI governance office holds intake, assessment, approval, and monitoring for the whole enterprise.
Strengths: maximum consistency; deep expertise concentrated where reviews happen; a single evidence trail regulators love; the only model that works when in-house AI expertise is scarce.
Weaknesses: the central team becomes a bottleneck the moment volume grows — and a bottleneck with veto power breeds workarounds. Business context gets lost: the reviewer approving a clinical triage tool may never have set foot in a hospital.
Fits: smaller organisations, early-stage programs (most programs start here), and heavily regulated single-sector firms where consistency outweighs speed.
Hub-and-spoke (federated)
A central hub sets standards; embedded spokes apply them. The hub owns policy, tiering methodology, tooling, training, and the highest-risk reviews. Trained governance leads inside each business unit run intake and lower-tier reviews locally, escalating what crosses thresholds.
Strengths: scales with volume; keeps business context in the review; the hub still guarantees consistency through shared standards and quality assurance of the spokes. This is where most large programs converge.
Weaknesses: spokes drift without active calibration — same use case, different tier in two divisions. Requires real investment in training the spokes and auditing their decisions. Dual reporting lines create loyalty tension: the spoke works in the business but for the standard.
Fits: large or multi-sector enterprises, global firms navigating multiple regulatory regimes, any program whose central team is drowning.
Decentralized
Each business unit governs its own AI. No central function beyond perhaps a community of practice sharing templates.
Strengths: fastest local decisions; full business context; near-zero central cost.
Weaknesses: almost everything else. No enterprise view of the AI estate, so no one can answer a regulator’s first question ("what AI do you operate?"). Inconsistent standards mean the weakest unit sets the enterprise’s effective risk appetite. Duplicated effort everywhere.
Fits: genuinely rare cases — conglomerates of unrelated businesses with separate legal entities and separate regulators. For everyone else it is not a design; it is the absence of one, and it fails the moment a cross-cutting law like the EU AI Act asks for a single accountable answer.
| Dimension | Centralized | Hub-and-spoke | Decentralized |
|---|---|---|---|
Consistency of decisions | Highest — one team, one standard | High if the hub calibrates spokes | Low — the weakest unit sets the floor |
Speed at scale | Degrades — central queue becomes the bottleneck | Scales — routine reviews stay local | Fast locally, chaotic globally |
Business context in reviews | Weak — reviewers far from the use case | Strong — spokes live in the business | Strongest, but unchallenged |
Regulator readiness | Strong — single evidence trail | Strong — hub aggregates evidence | Poor — no enterprise answer exists |
Typical fit | Small orgs; program launch; single regulated sector | Large, multi-line, multi-jurisdiction firms | Unrelated-business conglomerates (rare) |
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.