AI governance often looks strongest in the room where it is discussed and weakest at the moment someone has to use it.
A board can approve a policy, choose the tool, assign an accountable executive and sign off investment. Those decisions matter. None of them tells a care manager what to do when an AI-generated recommendation doesn’t look right.
That gap between governance on paper and judgement in practice is where AI risk becomes real. It's also where the return on the investment gets made or lost.
Ireland's health and social care sector has now been given a particularly clear warning against leaving it open. The EU AI Act requires providers and deployers to take measures that support the development of AI literacy. AI for Care says workforce literacy will be prioritised immediately. HIQA's July 2026 national guidance says services have a responsibility to conduct a training-needs analysis and provide ongoing education adapted to role, technical knowledge and context.
The control environment now includes capability
When executives talk about AI controls, the conversation usually moves towards approved tools, procurement, data protection, security, audit trails and risk registers. Quite right too.
But every control eventually meets a person. Someone decides whether to follow an output. Someone notices when the data looks wrong. Someone explains the use of the tool to a person receiving care. Someone chooses whether to stop, override or escalate.
If they don't understand the tool's purpose, limits, risks and consequences, the control is incomplete. A policy document can't do that on its own. It has to be built into how people actually work, not just what leadership has signed off on.
That makes AI literacy part of the operating model itself. It should be treated with the same seriousness as the policies and technical safeguards around it.
It only works if every layer of leadership buys in
This is where most AI programmes actually fail, and it rarely shows up as a single dramatic failure. It shows up as a slow, expensive stall, and the cause is usually a gap between one layer of leadership and the next.
The board sets risk appetite and signs off the investment case. If the board treats AI literacy as a line in a risk register rather than a condition of the return they're expecting, they'll approve a budget with no mechanism to know if it's working. The consequence is a board that only finds out from an incident report, when a dashboard should have told them first.
The CEO and executive team have to make capability part of how success is measured, not just how the rollout is funded. If AI adoption is tracked on licence numbers and deployment counts alone, leadership will report progress that isn't real. The consequence is a leadership team that believes it has scaled AI when it has really only scaled shelfware.
The CTO owns the technical environment the workforce has to operate inside. If tools are approved and deployed without the CTO also owning how staff are meant to use them safely day to day, technology and practice drift apart, and the workforce ends up building its own workarounds. The consequence is shadow AI use the organisation can't see, audit or defend.
The CDO (or whoever owns data quality and governance) has to be in the room from the start, not brought in to explain a breach after the fact. AI is only as reliable as the data it runs on, and staff can't be expected to spot poor-quality outputs if data governance was never connected to how the tool is used at the point of care. The consequence is an organisation that discovers its data problem through a clinical incident.
Miss any one of these, and the layers below compensate in ways leadership can't see: frontline workarounds, inconsistent practice, governance functions fielding the same escalation over and over because nobody owns the fix. None of that shows up in a completion report. All of it shows up eventually, in cost, in risk, or in a regulator's inbox.
Compliance is the floor
I would not ask a CFO to fund workforce capability only because a regulation mentions literacy. The stronger case is that the same investment supports control and value, and it's a change management investment as much as a learning one.
Organisations are already buying AI-enabled technology. In many cases, useful features are arriving inside platforms they already own. Without shared understanding, adoption becomes patchy: different teams find their own workarounds, governance ends up fielding the same questions on repeat, and leaders can't tell genuine use from optimistic licence numbers.
Role-based capability fixes that, but only if it's treated as change management rather than a course to assign. Done that way, it reduces misuse, makes escalation routes real rather than theoretical, and gives leadership honest evidence about where the organisation is actually ready to scale.
That's the infrastructure the investment actually depends on.
The same course for everyone is not equality
One of the easiest responses is to give every employee the same AI module. It’s measurable, quick to procure and simple to report. It also treats a different problem, changing what people actually do, as if it were a box to tick. It’s easy, but a waste of time.
By reducing the education stage to a one-size-fits-all training course that most people will skim through is foolish. It’s a poor reflection of how responsibility works. An executive approving a use case is making a different decision from a frontline colleague using an AI feature day to day, and both are different again from a procurement team pushing back on a supplier's claims. They need a shared language, a shared understanding, but they don't need identical depth.
A more credible programme starts with the decisions people make and who's affected by them, then asks what each role must be able to understand, challenge and escalate. That's the difference between course completion and actual readiness, and it's a change management question before it's an education one.
Care raises the standard
In health and social care, the person on the receiving end of the decision may be older, unwell, disabled or otherwise in a position of vulnerability. Efficiency matters, but it cannot be the only measure. Dignity, rights, safety, trust and human connection have to survive the introduction of the technology.
That is why I think Ireland's approach matters beyond Ireland. It understands that AI literacy is the link between innovation and care quality, something a compliance plan alone can't capture.
The organisations that get this will know where AI can help, where more control is needed, and where human expertise has to stay firmly in charge. That confidence comes from having built the capability to tell the difference, rather than assuming a policy would.
The board can point the organisation in the right direction. Whether it gets there safely, usefully, and in a way that earns the investment back depends on every layer of leadership beneath it buying in.
Unlock the power of your data & AI
Speak with us to learn how you can embed org-wide data & AI fluency today.


.png)


.png)
.png)



.png)
.jpg)
.png)
.png)
.png)
.png)