Who Guards the Gate

Who Guards the Gate

By Damien Richburg

Nobody remembers the model being wrong.

They remember the invoice that went out at the wrong price. The revenue that got recognized a quarter early. The forecast the board built a hiring plan around. The vendor commitment that showed up in a contract nobody read closely enough.

That is where AI damage lands.

Not in the output window.

In the record.

A model can be wrong all day and cost you nothing. The cost starts the moment something wrong becomes something booked, promised, or believed.

That is the gate.

And I think most companies are spending too much time thinking about the tool and not enough time thinking about who is standing there.

 

The wrong question

 

The question most companies are asking is some version of:

Who owns AI here?

The CTO. The CIO. A Head of AI. Maybe a committee.

The instinct makes sense. AI is technology, so the person who understands the technology should govern it.

Except the failures that matter usually stop being technology problems before the company feels them.

A hallucinated number is an output problem.

A hallucinated number in a board forecast is a business problem.

An AI-generated contract summary can be wrong.

The real problem begins when someone signs the contract based on it.

The tool doesn’t determine the consequence. The handoff does.

So perhaps the better question isn’t who owns AI.

It is:

Where are our gates, and who owns what happens after something crosses them?

 

Three Gates

 

I see three that matter disproportionately.

The record.

What does the company now say happened?

Entries. Reconciliations. Classifications. Revenue recognition. Anything that enters a system of truth and changes the company’s representation of reality.

The commitment.

What has the company now promised?

Pricing. Terms. Contracts. Offers. Purchase commitments. Anything that creates an obligation outside the company.

The belief.

What does leadership now believe strongly enough to act on?

Forecasts. Models. Scenarios. Hiring plans. Capital allocation. Anything that changes what the company does next.

Before those gates, let AI move.

Draft. Summarize. Search. Analyze. Recommend. Challenge.

The point isn’t to put a human in front of every AI output.

The point is to know when an output becomes consequential enough that somebody needs to own it.

 

The Gatekeepers Already Exist

 

This is why I’m skeptical that AI governance begins with creating an entirely new governance structure.

Most companies already know who owns the consequences.

Legal owns certain commitments.

HR owns certain employment decisions.

Security owns certain access and data decisions.

Operations owns certain safety and production decisions.

And Finance already owns some of the most consequential gates in the company.

  • What gets booked.
  • What gets reported.
  • What leadership believes about financial performance.
  • What gets attested to.

The control environment already exists because companies have always needed someone to answer a very old question:

How do we know this is true?

AI doesn’t eliminate that question.

It dramatically increases the speed and volume at which the company has to answer it.

That same acceleration is reshaping how leadership teams need to rethink hiring in the age of AI agents.

 

Why the CFO Matters

 

The CFO already owns the financial control environment. The audit relationship. Financial reporting. Forecasting. Capital allocation. Often procurement and other areas where commitments become dollars.

AI doesn’t create an entirely new category of responsibility for Finance.

It changes the scale of an existing one.

This is part of why financial leadership itself is evolving in the age of automation.

For years, controls were designed around humans producing work at human speed.

A person prepared something.

Another person reviewed it.

Someone approved it.

AI changes that equation.

Now the work can be generated, analyzed, classified, reconciled, and eventually acted upon at machine speed.

The question becomes:

Can the control environment move as quickly as the system producing the work?

Because if it cannot, one of two things happens.

The business slows AI down until the controls catch up.

Or AI outruns the controls.

Neither is a particularly good operating model.

 

When AI Stands at the Gate

 

Then comes the harder problem.

What happens when AI isn’t simply approaching the gate?

What happens when AI is standing at it?

  • AI prepares the reconciliation.
  • AI identifies the exception.
  • AI evaluates whether the exception is material.
  • AI recommends the action.

Eventually, AI may execute it.

At that point, “human review” isn’t much of a control if the human is simply approving work they no longer have the time, context, or expertise to independently evaluate.

Who audits the auditor when the auditor is a model?

I suspect that will become one of the more important control questions of the next decade.

 

Which CFO

 

But not every CFO is built to hold this gate.

A finance leader who primarily reports on what the system already did can tell you whether yesterday was recorded correctly.

That matters.

But the next version of the job requires something else.

It requires understanding the process well enough to determine what the system should be allowed to do tomorrow.

  • Where can it operate autonomously?
  • Where should an exception trigger review?
  • Where does a human signature still create meaningful protection?

And where is the human signature now theater because nobody signing it can realistically validate what happened underneath?

That isn’t just financial reporting.

That is system design, risk judgment, and organizational leadership.

And stage matters.

At one size, a strong Controller may be perfectly capable of holding the gate.

As the company grows, the systems multiply. The transactions increase. The decisions get larger. The consequences become harder to unwind.

The gate doesn’t move. The consequence of leaving it open does.

Getting that sequence right is its own decision, and often comes down to whether a CFO or a Controller hire comes first.

 

What A Gate Must Not Become

 

There is a version of this that fails in the opposite direction.

Finance decides everything involving AI is risky.

More approvals, reviews, and committees get added.

The company becomes safer and slower until operators begin routing around the process entirely.

Then the gate still exists on the org chart, but nobody walks through it.

The goal isn’t maximum control.

It is appropriate control at the point of consequence.

Which decisions still deserve a human signature?

Which can safely move without one?

And perhaps most importantly:

Which ones stopped deserving a human signature a while ago, but nobody has redesigned the process yet?

 

The Gate Was Always There

 

AI didn’t create the gate.

It made the gate easier to see.

At one size, a Controller holds it and nobody thinks much about it.

At another, it carries the CFO’s name and the board’s exposure.

The underlying responsibility hasn’t changed.

The scale has.

At the Controller level, that scale question also shows up in hiring controllers and senior analysts who can actually hold the gate.

And that is where companies can misdiagnose the problem.

They think they have an AI governance problem.

Sometimes they do.

But sometimes AI has simply exposed something growth was already making true:

The company has outgrown the person standing at the gate.

 

Related Articles