PeopleCert Community

What ITIL AI Governance Teaches Us About Maturity in an AI-Enabled World

What ITIL AI Governance Teaches Us About Maturity in an AI-Enabled World
# AI
# ITIL
# Thought Leadership

Why successful AI governance depends more on organisational maturity than technology.

August 6, 2026
Alex Harding
Alex Harding
What ITIL AI Governance Teaches Us About Maturity in an AI-Enabled World

What ITIL AI Governance Teaches Us About Maturity in an AI-Enabled World

When I opened the new ITIL AI Governance book, it’s not a shock is it that I expected it to be about artificial intelligence. I expected discussions about models, regulations, controls, oversight and risk. It is no surprise that those elements are there, and rightly so. What I didn’t expect was how often the focus moves away from technology and back towards people. As an Agilist (Think People over Process) I really find this powerful.
Again and again the guidance returns to ideas such as trust, stewardship, accountability, decision-making, participation and value creation. Rather than presenting governance as control alone, it frames governance as a balance between appropriate control and thoughtful stewardship, helping organisations use AI responsibly while still creating value. At almost the same time, I was reading the Association of Colleges  Digital Transformation and AI Roadmap . Strangely, I found myself arriving at much the same conclusion. The roadmap talks extensively about leadership, capability, culture, confidence, data foundations and organisational readiness. They are written for different audiences and for different reasons, but they seem to be circling around the same fundamental core. The more I explore both, the more I become convinced that neither is really about AI. Both are fundamentally about organisational maturity.

The Problems AI Did Not Create

One of the things AI governance makes visible is that many of the risks now attracting attention have been with us for years. AI does not create poor data, unclear ownership, weak decision-making, bias or accountability concerns. It simply exposes them faster and more visibly. In some respects, AI now stands as the ultimate stress test for maturity.

The 6C Model Changed How I Thought About AI

One of the most useful ideas within ITIL AI Governance is the 6C AI Capability Model. The model separates AI capability into Creation, Curation, Clarification, Cognition, Communication and Coordination. The more I reflect on it, the more I find myself using it as a mental shortcut.

Figure 1 - ITIL 6C Capability Model
Rather than asking whether AI is risky, we can ask which capability we are actually looking at. An AI capability that creates content does not surface the same questions or risks as one that coordinates activity across systems, or one that supports cognition and decision-making. Having a model that makes these really simple distinctions changes the whole focus by stopping us treating AI as one thing. Definitely if you aren’t very technically aware of the many underlying differences in what we collectively call AI then this is a useful replacement or in fact is useful nonetheless.

Governance Through Multiple Lenses

Another aspect of the book that stands out is the way governance is approached through multiple perspectives rather than a single control framework. Leaders may naturally look for accountability, while security teams tend to see compliance and control. Data teams will often focus on governance and quality, while users are more likely to care about trust, fairness and transparency. In reality, everyone is looking at the same technology through different lenses. That is why both control and stewardship matter. Control gives assurance, boundaries and accountability. Stewardship helps ensure those boundaries are applied with purpose, care and long-term value in mind.

The Typical Risk Profiles are More Useful Than It First Appears

Different AI capabilities create different risk profiles and different governance perspectives highlight different concerns. Risk is not determined solely by the presence of AI. It depends on what the AI is doing, where it is being used, who it affects and how much autonomy it has within the process. This moves the conversation beyond asking whether AI is safe and towards asking whether it is appropriate within a specific context. For me, that is where the risk matrix (Table 2.11 in the book) becomes particularly useful. It helps move the discussion away from broad anxiety and towards proportionate, practical judgement.
One of the strengths of ITIL AI Governance is that it does not stop at theory. The governance models, capability framework and risk approaches are supported by practical guidance that helps organisations assess AI use cases, understand governance requirements and make proportionate decisions. That makes it easier to move from discussing AI governance to actually doing it.

From Governance to Stewardship

What impresses me most about the book is that it does not treat control and stewardship as opposites. Control matters because it gives organisations assurance, accountability and clear boundaries. But control on its own is not enough. Stewardship adds responsibility, ownership, care and long-term thinking. It asks not only whether something is compliant, but whether it is beneficial.

What This Meant For Us

This is where the theory became practical for us. When we began developing our own AI guardrails, I thought we were creating AI controls. Looking back, I am not sure that is what happened. The more we discussed the risks and opportunities, the more we realised that most of the guardrails already existed. Data protection still mattered. Safeguarding still mattered. Professional accountability still mattered. Copyright, assessment integrity and inclusion still mattered. The technology had changed. The responsibilities had not. That mattered because guardrails only work if people recognise them. If they feel like a completely new rulebook, they create distance. If they connect to responsibilities people already understand, they become much easier to apply.

The Hardest Part of AI Governance

That experience reinforced something I kept coming back to as I read the book. The hardest part of AI governance has very little to do with AI. The difficult part is creating organisations that are capable of using it responsibly. That means trusted data, capable people, clear accountability and enough confidence to innovate whilst retaining enough discipline to do so responsibly. Perhaps that is the real contribution of ITIL AI Governance. On the surface it is a book about artificial intelligence. In reality, it is a book about organisational maturity in an AI-enabled world.

My 1TakeOn

The more I read ITIL AI Governance, the more it reminds me of digital transformation. Not because they are the same thing, but because they often succeed or fail for the same reasons. The issues are rarely just technical. They are usually about data, ownership, governance, trust and capability. What impresses me most about the book is that it avoids becoming just another AI control framework, but it does not dismiss control either. The 6C capability model, governance perspectives, risk matrix and practical implementation guidance all point towards a broader idea that responsible innovation needs both clear control and thoughtful stewardship. The emphasis on stewardship feels particularly important because it shifts the conversation from controlling technology alone to enabling value responsibly. The AoC roadmap arrives at a remarkably similar conclusion from a different direction. Leadership, culture, confidence and organisational readiness sit at the centre of successful adoption. AI is important, but maturity is what determines whether it delivers value or simply amplifies existing problems. Perhaps that is why our own AI guardrails ended up looking so familiar. The technology changes, but the responsibilities do not. The organisations that succeed with AI will probably not be those with the biggest governance committees or the most sophisticated models. They will be the organisations that already know how to govern, lead, learn and adapt.

References

Association of Colleges. (2025). Digital Transformation and AI Roadmap. Association of Colleges.
PeopleCert. (2026). ITIL AI Governance. PeopleCert.
Runshaw College. (2026). AI Principles and Acceptable Use Statement. Internal document.

Enjoyed this post? Join the conversation by leaving a comment or sharing your thoughts below, we’d love to hear your experiences and perspectives. Don’t forget to explore our upcoming  events  for more opportunities to learn and connect, and visit the  forum  to continue the discussion.
Sign in or Join the community
Where conversation, connection, and real-world practices come together.
PeopleCert Community
Create an account
Where conversation, connection, and real-world practices come together.
Comments (2)
Popular
avatar

Dive in

Related

Blog
What Owning a Dog May Teach Us About Service Management
By Richard Petti • Mar 13th, 2026 Views 30
Blog
AI Governance in Service Management
By Gabriel Espinosa • May 12th, 2026 Views 183
Blog
The New ITIL Version 5: What It Means in the Real World of Digital Services
By Scott Everett • Feb 5th, 2026 Views 143
Blog
AI Governance in Service Management
By Gabriel Espinosa • May 12th, 2026 Views 183
Blog
The New ITIL Version 5: What It Means in the Real World of Digital Services
By Scott Everett • Feb 5th, 2026 Views 143
Blog
What Owning a Dog May Teach Us About Service Management
By Richard Petti • Mar 13th, 2026 Views 30