Every executive leading the world's 500 largest companies said, without exception, that they were "governing AI." Then came the follow-up question: "If this AI is causing harm, who has the authority to shut the model down?" This time, most had no answer. Joseph Wallace, director of data and AI governance at Adobe, opens his essay in MIT Sloan Management Review with exactly this silence. The gap between claiming to govern AI and actually being able to stop it is what he zeroes in on — and it's a gap that shows up in companies of every size, which is exactly why the observation travels well beyond the Fortune 500.
Governance statements pile up. Shutdown authority stays blank.
AI governance is no longer an unfamiliar phrase in corporate filings and press releases. What fills that space are AI usage guidelines, ethics-principle documents, internal review processes. Some large companies have gone as far as standing up dedicated committees. From the outside, it looks like a functioning system.
But Wallace points to a gap that opens up inside that system almost by default. Someone drafts the AI policy. Someone defines the ethical standards. Someone distributes the usage guidelines. Yet when an AI system actually malfunctions or causes harm, most organizations have never predetermined who gets to decide to pull it offline or restrict its operation.
"If this AI is causing harm, who is responsible for stopping it?" If you can't name someone on the spot, then no matter how thick the rest of the governance documentation is, the execution structure is still unfinished.
Korea is no exception. More teams are drafting AI usage guidelines, and seminars sharing adoption case studies have become more frequent. But when a customer-service AI tool confidently states something factually wrong, or a marketing automation tool sends out a message in an unintended tone, few teams have already decided who can call an immediate stop. Compared to how fast guidelines are being written, the number of teams that have pre-designed a shutdown structure remains small.
Control is proven by the ability to stop, not the ability to use well
When most practitioners first adopt an AI tool, they focus on using it better — refining prompts, connecting it to more workflows, widening the scope of automation. That's the natural order of things. But Wallace's focus runs in the opposite direction. Evidence that a tool is truly under control shows up not in how well it's used, but in whether it can be stopped.
An organization can only claim it's actually operating the tool, not just deploying it, once the authority to decide to stop is clearly assigned to someone.
"Deciding to stop" actually requires several steps to align: who detects the warning signs coming from the tool, and how; who holds the authority to act once that signal is received; and who decides, by what criteria, when it's safe to resume. In large companies, these roles are scattered across different teams, which makes coordination complicated. In small organizations or solo operations, one person often handles all of it — but rarely recognizes that as their explicit responsibility.
In management theory, separating who executes a decision, who bears ultimate accountability for it, who should be consulted, and who should simply be informed is considered the starting point of organizational risk management. Apply that lens to the decision to shut down an AI system, and you'll find that in most organizations, the "ultimately accountable" seat sits empty. Whether that vacancy has been sitting there for a long time or simply hasn't been noticed yet varies by organization — but the vacancy itself is common to nearly all of them.
Naming a shutdown owner doesn't make the problem disappear
It's worth being honest about the limits here. Designating a single person as the shutdown owner is not, on its own, sufficient AI risk management.
In fact, once a clear owner is named, everyone else tends to stop watching and judging for themselves. The "that's their job" mentality kicks in. Social psychology calls this diffusion of responsibility: the more concentrated accountability becomes in one person, the weaker everyone else's willingness to act. This happens even with a designated owner in place — and if that one person is out of office or burned out, both detection and judgment go dark at the same time.
There's a deeper problem too. Not every kind of AI harm sends a clear "stop now" signal. A subtly biased tone accumulating in customer interactions, internal decisions leaning too heavily on data skewed in one direction, a content recommendation range that quietly narrows over time — none of these register as an obvious incident. Even with a designated owner, without a monitoring system to give that person something to act on, no real line of defense exists. Naming a shutdown owner is the starting point of governance, not its conclusion.
Wallace himself doesn't deny this limitation. The question he poses isn't a formula that resolves every risk. He offers it as a minimum bar for telling whether governance is still just a declaration or has actually become an executable structure.
What practitioners can check right now
A story about Fortune 500 companies might sound like it belongs to a different scale of operation. But the same question applies the moment even a single AI tool is part of your workflow.
Start by simply listing every AI tool currently in use. Slack bots, automatic email sorting, content-draft generation, customer-response automation, meeting-summary tools — just naming and listing them changes how you see the picture. Most small teams have never actually made this list. Once they do, they usually find more tools already embedded than they expected.
Next, for each tool, write down one line answering: "How would I know if this tool produced a wrong result?" Without monitoring, you may not notice a problem until the damage has already spread. Setting even one warning-sign threshold per tool changes how fast you can respond.
Finally, check: "If I decided to stop this tool right now, how quickly could I actually do it?" Knowing in advance whether you can revoke an API key instantly, how many days it takes to cancel a subscription, or whether additional internal approvals are required — all of that changes your decision speed when a real situation hits. This isn't a crisis-response manual. It's basic hygiene for operating any tool.
Middle managers driving AI adoption in Korea have one more thing to check. The people most likely to notice a problem first are the frontline staff actually using the tool, but the authority to decide on a shutdown usually sits higher up. If there's no pre-built path for frontline staff to escalate a warning sign to leadership, the time between noticing and deciding stretches out. Designing that escalation path in advance is a concrete contribution a middle manager can make right now.
Feeling like AI is under control on paper and actually having the structure to stop it are two different things. Naming a shutdown owner isn't glamorous. It doesn't involve forming a committee or announcing a new set of principles. It's just filling one empty seat with a name. I'd argue that governance with that one line left blank isn't yet operational — no matter how thick the rest of the document is.



