AI

AI Governance: Who Is Actually Responsible?

Ethyca CEO Cillian Kieran on AI governance as an engineering problem, the risk of permissive AI agent access, and what the next five years of AI consolidation looks like.

Liam Lawson
September 25, 2026

AI governance. What really is it? The moment the word comes up, most people tune out, whether they mean to or not. It's not fun, or sexy, as Cillian Kieran put it on a recent episode of The AI Report podcast. And he would know.

As CEO of Ethyca, Cillian has spent seven years building the infrastructure that sits between AI systems and the data those systems access. His customers include the New York Times, Condé Nast, and the IAB, whose 700 member companies now label advertising data using Ethyca's open-source standard. GitHub and Microsoft use it too, to label data flowing through Copilot. The company works with Fortune 500s that need someone to have thought through the governance problem before something goes wrong.

He joined The AI Report to talk about why that problem is bigger than most people realize, and why the word itself might be the first obstacle to solving it.

What Happens When You Click Allow

When someone enables an MCP server that connects their AI to a business tool, they are usually doing it because it makes the tool more useful. What most people miss is what they have just opened up.

Cillian described a scenario that has already played out at real companies: a small business owner connects their AI agent to QuickBooks, Stripe, Shopify, and their social media accounts. Over ten or twelve weeks of asking the agent questions and running tasks, sensitive purchase data, customer credit information, and financial records have quietly moved across system boundaries the user never consciously crossed. No single interaction was flagged. No alert went off. The user just asked questions and things happened.

The issue is not that MCP servers are dangerous by design. They are powerful and useful. The issue is that most people enabling them have no framework for understanding what permissions they carry. They trust that someone clever has thought through the implications. Often, nobody has.

Even Cillian draws a line. Despite his engineering team wanting to explore it, he has never installed OpenClaw on any of his own hardware. His reason: concern about the access footprint it would create across his systems. For the CEO of a governance company, that is a deliberate decision rather than a technical limitation.

Governance Is a Technical Requirement, Not a Legal One

Cillian came to this through a specific experience. His consulting firm was working with Heineken ahead of GDPR coming into effect in Europe, and like most businesses at the time, they were struggling to figure out what compliance actually required. Everyone was treating it as a legal problem for lawyers to solve.

When he looked at it from an engineer's perspective, he saw something different. Strip away the legal language and the GDPR is describing a set of technical requirements: what kinds of data can you collect, where did it come from, what laws apply to it, what are you permitted to do with it, and how do you delete it safely? Those are not compliance questions. They are data engineering questions.

That realization eventually became Ethyca, and more specifically Fides, the company's open-source privacy standard, now the most widely adopted of its kind in the world. Most of the organizations using it have no direct relationship with Ethyca at all. They use the open standard because none of this works if every company has a different way of describing the same data.

The Harness, Not the Guardrail

Back to that word: governance. The reason people tune out is not just that it sounds boring. It is that the vocabulary around it tends to imply restriction, and Cillian has a different frame for it.

Guardrails imply restriction. A guardrail stops you from going somewhere you want to go. Cillian prefers the image of a harness and blinders on a racehorse. A harness is not there to slow the horse down. It is there to direct its energy in one direction, very fast, without jumping the railings. The goal is performance, not restriction. Done well, the right governance layer is what makes AI tools go as fast as they are capable of going, safely.

Governance framed as restriction gets deprioritized. Governance framed as the thing that enables fast, confident deployment gets funded.

Who Is Responsible for Getting This Right

When things go wrong with an AI system, who is accountable? Cillian's answer is clear, and it is not the user.

If a bridge collapses, no one goes looking for the contract a lawyer wrote. Everyone wants to know what the engineers decided, what materials they used, how they designed it. That is how physical infrastructure works. Software has somehow escaped the same expectation, even as it has become just as foundational to daily life.

His preferred illustration is the seatbelt. When seatbelts were first required in vehicles in the United States in the 1950s, almost everyone pushed back. People did not want them. Today, you wouldn't get into a car that didn't have one. It was not driven by users who decided they wanted seatbelts. It was driven by engineers who built them in and made safety the default.

His argument is that AI needs the same shift. Engineers should be building governance in from the start, not assuming users will make the right decisions about access and data. Most users are not equipped to make those decisions, and the more autonomous AI becomes, the more it matters.

AI as Statistical Math

Cillian agrees with a framing he attributes to science fiction writer Ted Chiang: artificial intelligence is a marketing label applied to statistical mathematics. If we had always called it statistical math, he says, it would not be nearly as compelling. But we would probably have a more accurate relationship with what it can and cannot do.

The practical implication is about expectations. Most enterprise uses of AI, things like behavioral analytics, CRM data processing, and document summarization, are tasks where the leading models now perform comparably. The differences are largely at the margin. What actually changes outcomes is the quality of the data those models are fed and the controls around how they use it. That is the real frontier, and it gets far less attention than model benchmarks.

The Consolidation Ahead

Cillian is direct about where the market is heading. He believes most AI startups built in the thin layers above foundation models will not survive the next three to five years. The foundation model providers are moving fast enough that many of those businesses will be absorbed or made redundant. He thinks the venture-backed software model is under more pressure than most founders want to admit.

Where does he see durable opportunity? He has been watching Yann LeCun's work on world models, which take a fundamentally different mathematical approach from current large language models. LeCun has argued that today's models cannot reach AGI from where they are, and that world model architectures may ultimately surpass them. Cillian thinks that research direction is where the most interesting bets are, even if anything usable is five to ten years out.

The Human Question

Late in the conversation, the discussion turned to what all of this means on a human level.

Cillian's observation was quiet but worth sitting with. Every major technology shift over the past fifteen years, social media, remote work, AI, has added a small layer of distance between people and each other. None of it was planned that way. But each one has made it a little easier to spend time with a screen rather than another person. AI is doing the same thing at a new scale, tools that respond, engage, and feel in some ways more predictable than people do.

His hope is simple. If AI genuinely takes over more of the operational work, the time that frees up should go toward spending more of it with people. That would make it worth it.

Watch the full conversation with Cillian Kieran on The AI Report podcast.

Stay up to date with the latest AI news and analysis. Subscribe to The AI Report.

‍

Join the Newsletter
Inchide fereastra