Most organisations are further into AI adoption than they realise. Employees are using tools their companies have not approved, data is flowing through systems nobody has audited, and accountability for what happens next sits in a gap between the legal team, the technology team, and the product team. Nobody owns it.
In this episode of Tech Tomorrow, David Elliman speaks with Zahra Shah, a responsible AI expert who has spent her career helping organisations untangle exactly this problem. She sets up to answer the episode’s central question: Are leaders deploying AI faster than they can effectively govern it?
Meet the guest: Zahra Shah
Zahra Shah serves on the board of NexaQuanta, an AI transformation consultancy, and is chair and a founding member of UKAI’s Women in AI Working Group.
She has extensive experience advising organisations on AI governance, ethics, and responsible AI policy, and works with leaders across sectors to bring accountability and rigour to AI adoption before problems become crises.
Key takeaways from the episode
Shadow AI: the governance problem that is already inside your organisation
One of the sharpest observations in the episode is also one of the simplest: a large number of organisations do not realise they are already using AI. Their employees have adopted tools quietly, without official approval, without any visibility from IT or leadership, and without any of the safeguards that a formal deployment would require.
Zahra calls this shadow AI and believes it is the most crucial and most overlooked aspect of any effective AI system. Before an organisation can govern AI, it has to know where AI already lives.
“A lot of companies do not even realise that they’re already using AI. A lot of their employees are already using what we call shadow AI without their knowledge.”
This is a point David connects to something he has observed repeatedly in software engineering: the most dangerous gaps in any system are not the ones people argue about, but the ones nobody notices.
Shadow AI is exactly that kind of gap. To fix it, teams need to do the kind of requirements analysis and use-case mapping they do at the start of a project, applied to the question of what is already running.
Starting with the right problem matters more than starting fast
A recurring theme in the conversation is the cost of selecting the wrong use case. Zahra is direct: if you choose the wrong problem to solve, you will never see a return on your investment. More than that, you will spend time and money building something that does not serve the people it was designed for.
Her recommended starting point is a low-risk pilot. An HR knowledge assistant, for example, is a practical way to build organisational confidence in AI governance without exposing the business to serious risk. The key is to set realistic KPIs for that pilot stage rather than demanding immediate ROI.
“Instead of the KPI for the pilot being ‘we must get a return on investment straight away’, perhaps the KPI should be: did our guardrails work well, or did we mitigate specific biases? So you can have realistic KPIs at the pilot stage to give everybody the breathing room to come up to speed.”
Zahra also makes a point that rarely gets enough attention in AI conversations: not every company needs a large language model. Different models are suited to different tasks, and a small, targeted model that can be fine-tuned to specific requirements will often outperform a powerful general-purpose system in a narrow context. Choosing the right model for the right problem is an integral part of responsible AI.
Techniques like Retrieval-Augmented Generation (RAG) can further reduce risks like hallucination in production settings, and vendor lock-in deserves as much scrutiny as model capability.
David describes the pattern clearly: a team picks a model that solves an immediate problem, data starts flowing into a proprietary pipeline, and by the time anyone steps back, switching costs have quietly become substantial.
The accountability vacuum nobody wants to talk about
The conversation moves on to accountability. When something goes wrong with an AI system, Zahra states she has seen organisations where the legal team believes it is a technology problem, the technology team believes it is a product problem, and the product team believes it is a legal problem. The result is that nobody acts.
Her argument is that AI is a tool. So, if it is used in finance, accountability should sit with the finance director. If it is used in HR, accountability should sit with whoever runs HR. The technology does not change where responsibility lives.
What she believes helps is a multidisciplinary committee that brings together people from different parts of the business, shares accountability across the group, and does something Zahra describes as a pre-mortem: working through what could go wrong before anything does. The person who understands the business function is best placed to identify operational risks. The AI expert can identify system risks. The legal expert can identify regulatory exposure. Together, they cover the ground that no single individual or team ever could.
This sits at the heart of what mature AI governance actually looks like in practice.
The global regulation picture, and the UK’s unusual opportunity
The conversation moves naturally from governance inside organisations to governance at a national level, and here Zahra draws a picture that is more nuanced than most public debate allows.
At present, the landscape looks roughly like this:
- The US has minimal AI regulation, which has enabled rapid innovation but is beginning to generate visible trust problems.
- The EU has the EU AI Act, which takes a risk-based approach. Zahra’s concern is that this is hard to enforce on systems that are inherently dynamic. A low-risk system used incorrectly can become a high-risk system very quickly.
- The UK sits in the middle, and in Zahra’s view, that is a genuine opportunity. A principles-based, innovation-friendly framework that protects vulnerable people could position the UK as a trusted home for responsible AI development globally.
She points to Singapore’s governance framework for agentic AI, launched at the World Economic Forum, as a model worth studying: agile, iterative, and designed to keep pace with systems that change faster than traditional regulation can follow.
The opportunity Zahra sees for the UK also extends to the people question. David describes the risk of a slow-widening gap between the AI-fluent and everyone else, and Zahra frames it as a national challenge. The UK AI Opportunities Action Plan acknowledges regional hubs, but she is clear that ensuring the benefits of AI reach underserved parts of the country requires deliberate policy, not just good intentions.
So, are leaders deploying AI faster than they can effectively govern it?
Zahra’s answer is yes, in some situations, and she is careful not to make it a criticism. The pace of change is genuinely extraordinary, and many leaders are making decisions under real pressure, afraid of being left behind if they slow down.
“There are companies or nations that are basing decisions on fear. They’re not making decisions based on rational objectivity. They’re driven by this fear: if I don’t do it, I’ll be left behind.”
The more useful framing is that the gap between deployment and governance is not inevitable. It is a product of treating governance as something that follows deployment, rather than something designed in from the start. Ethics by design, safety by design, and accountability by design are not constraints on innovation. They are the conditions under which AI systems actually earn the trust they need to deliver lasting value.
David’s perspective, shaped by four decades in software, is that the discipline is familiar even if the technology is new. Progress comes from knowing what you are building, why it matters, and how you will test whether it is working. That has always been true. AI does not change the principle. It just raises the stakes for getting it right.





