AI Strategy
Inverting the Approval Pyramid: A Governance Model for Bottom-Up AI
We wrote recently that AI isn’t the bottleneck, leadership attention is. That piece was a diagnosis. This one is the treatment we recommend.
The short version: most organisations still run an approval model built for a world in which trying something was expensive. It no longer is. The model needs turning over.
The pyramid as it stands
| Traditional model | |
|---|---|
| Who may start something new | Whoever secures executive sponsorship |
| What travels up | Proposals and requests for permission |
| What travels down | Approval and budget |
| Capacity limit | The number of decisions a few senior people can make |
| What happens to good ideas at the edge | They wait, shrink, or leave with the person who had them |
Middle managers sometimes create pockets of initiative, and those pockets tend to close when the manager moves on or a new corporate programme arrives. Nothing in the structure holds them open.
Why AI breaks this model
Two things change at once.
Attempts become cheap. A staff member with a company AI seat can build a working prototype of a process improvement in hours, with no budget and no vendor. Rationing attempts through an executive gate now costs more than the attempts themselves.
Volume rises. If everyone can try things, the number of candidate ideas multiplies. A gate that was already saturated cannot absorb ten times the flow. Either ideas die in the queue or leaders approve without really looking.
Giving executives AI tools helps them decide better. It does not change the arithmetic. The structure has to change.
The inverted model
Five parts. None is complicated. All five are needed.
1. A sandbox with firm edges
Publish what anyone may do without asking. We keep it to a page.
- Tools: the company’s approved AI plan and connectors
- Data: what may be used freely, what needs care, what is never used
- Actions: nothing that contacts a customer or supplier, moves money or changes a system of record without a named person’s approval
- Numbers: exploratory analysis is labelled as such, and the official figure stays official
Inside those edges, permission is not required. That single sentence is the inversion.
2. A register, not a request form
One shared list. For each experiment: who, what problem, what was tried, rough time saved or value created, status. Two minutes to fill in. It exists so that good ideas are visible and duplicated effort is caught, not so that anyone can say no.
3. A promotion path with stated criteria
An experiment is put forward for adoption when it meets any of these:
- more than one person or team wants to use it
- it needs to read from or write to a core system
- it produces something that goes outside the organisation
- it would change a documented process
Below that line it stays a personal improvement, and that is a perfectly good outcome.
4. AI-prepared approval briefs
Every promoted candidate reaches leadership in the same one-page format, drafted by AI from the register entry and the experiment’s own files, then checked by its owner:
- The problem, in a sentence
- What was built and how long it has been running
- Measured benefit
- Data and systems touched
- Risks, and what happens if it fails
- How easily it can be switched off
- What adoption would cost in money and people
Leaders stop assembling information and start judging it.
5. A different job at the top
| Traditional | Inverted | |
|---|---|---|
| Leaders decide | What may be tried | What gets adopted and funded |
| Leaders receive | Proposals | Evidence |
| Leaders’ main output | Permissions | Boundaries, sense checks, sponsorship |
| Time per decision | Long, information-gathering | Short, judgement-focused |
This is a narrower role and a more valuable one. It also scales, because a one-page brief on something already working takes minutes to assess.
Decision rights, made explicit
Ambiguity about who can approve what is where these programmes stall. Write it down.
| Tier | Example | Who approves |
|---|---|---|
| Personal | A routine that drafts my weekly report | Nobody. It is inside the sandbox |
| Team | A shared workflow for the whole finance team | Team lead |
| Cross-team or system-touching | An automation that reads the accounting system | Function head, with IT sign-off on access |
| External or financial | Anything sending to customers or preparing payments | Executive, with a human approval step kept in the process |
What stops it working
Leaders who cannot let go. The model asks senior people to be consulted less. Boards and chief executives have to want that, say so, and then behave accordingly the first time someone acts without asking.
Punishing the fizzles. Most experiments lead nowhere, which is why they need to be cheap. If a failed experiment counts against someone, the register will be empty within a quarter.
Initiative that depends on one sponsor. The register and the promotion path exist so that a good idea survives its champion leaving.
No boundaries. Freedom without edges produces data incidents and conflicting numbers, and then a clampdown. See our guide to AI security and governance for the policy underneath the sandbox.
Start with one team
- Choose a team with a willing lead.
- Publish the one-page sandbox and open the register.
- Run for ninety days, with a thirty-minute review each month.
- At the end, promote one or two experiments using the standard brief.
- Tell the rest of the organisation what happened, including what did not work.
Then widen it, one team at a time. It is a significant shift in how an organisation thinks about authority, and it lands best in small steps.
If you would like help drafting the sandbox, the register and the brief for your organisation, talk to us.
If this sparked something, let's talk.
No pitch, no pressure — just a conversation about what you're working on.
Let's talkRelated posts
AI Strategy
Did AI Just Kill BI? What to Stop Paying For, and Where to Spend Instead
Traditional business intelligence spent most of its budget on integration: ETL, data wrangling and merging systems. AI has collapsed that cost. Here's what leaders should stop funding, what deserves the money instead, and the questions to put to your BI vendor.
AI Strategy
AI Isn't the Bottleneck. You Are.
AI can run 50 projects where you used to run 5. But your organisation can't absorb that. The real constraint on AI isn't capability — it's leadership bandwidth.
AI Strategy
AI Security and Governance: A Practical Guide for Business Leaders
As AI adoption accelerates, security and governance can't be afterthoughts. Here's a practical framework for managing AI risk — without slowing down adoption.