AI Governance

Shift Down: Why AI Governance Belongs in Infrastructure

Written by: Joseph Wallace | Director, Data and AI Governance, Adobe

Updated 10:00 AM EDT, August 18, 2026

post detail image
Joseph Wallace | Director, Data and AI Governance, Adobe Joseph Wallace is Director of Data and AI Governance at Adobe with 15 years of experience leading enterprise data governance and AI risk programs.

Most AI governance programs have the same fatal flaw: they require humans to remember to use them.

Policies exist. Review committees meet. Approval processes are documented. Yet somewhere in the organization, an engineer launches a new agentic workflow or connects a new model to production without ever touching them. Governance didn’t fail because it was poorly designed. It failed because it depended on someone remembering to follow it.

The problem isn’t process. It’s where governance lives.

This is the idea behind what I call the “Shift Down.” Not shift left, which moves governance earlier in the development process. Shift Down moves governance from human processes into technical infrastructure, where systems enforce the governed path by default through the defaults, permissions, and environmental constraints that determine what’s possible before a human ever makes a choice. 

For Chief Data Officers (CDOs), this changes the governance conversation. As AI scales across the enterprise, governance becomes less about reviewing individual use cases and more about ensuring the technical environment consistently enforces organizational policy by default. 

Governance that lives in infrastructure doesn’t depend on anyone remembering to apply it. It happens automatically, whether or not the right person was in the meeting.

Most organizations haven’t made this shift. They are governing through documents when they should be governing through defaults.

What Shift Down looks like in practice

I helped build an enterprise AI governance program from a single unfunded idea into oversight of a portfolio spanning 34 products. The single biggest change in that program’s effectiveness had nothing to do with adding more reviewers or writing better policy. It came from moving controls out of committee meetings and into the deployment pipeline itself.

Early in the program, a data classification decision lived entirely in a policy document: a table that said which data types were Restricted and which teams needed approval to use them. On paper, compliance was excellent. Compliance in practice depended entirely on an engineer remembering to check the table before connecting a new data source. When we moved that same classification logic into the data platform itself, Restricted-tagged sources became structurally incapable of flowing into unauthorized pipelines. The compliance question stopped being a training issue and became a non-issue. Nobody had to remember anything. The infrastructure simply would not allow the wrong thing to happen.

Shift Down, in one sentence, is moving the control from something people have to remember to something the system enforces by default.

The gate vs. the pipe

There are two ways to build governance into a system: you can build a gate, or you can build a pipe.

  • A gate stops things and asks questions. It requires a human to evaluate, approve, and move on. Gates are how most AI governance programs work today. They’re also difficult to scale because they require humans to remember to use them. In organizations deploying AI across dozens of teams and hundreds of systems, that dependence on human memory is unreliable.
  • A pipe makes the governed path the only path. Data classification happens automatically before anything enters the system. Access controls are built into the environment, not bolted on afterward. Logging is default behavior, not optional. Nobody has to remember to govern because the infrastructure governs by default.

Shift Down is the move from gates to pipes.

Four questions infrastructure governance answers

In practice, Shift Down means governing the infrastructure by asking and answering four questions before any AI system gets built.

1. What data can enter this system? 

This isn’t a question of what data should enter the system according to a policy document. It’s a question of what data can enter it structurally, given the classification controls and access permissions in place.

If Restricted data can physically flow into an AI training pipeline, your governance is a document. If Restricted data is blocked at the infrastructure layer from ever reaching that pipeline, your governance is a control.

2. What is physically impossible for this system to do? 

Agentic AI systems make decisions in the gaps between human checkpoints. The governance question isn’t whether those decisions are good; it’s whether the system is structurally capable of making them at all. 

Agentic systems with overly broad database permissions have already deleted production data in seconds — not because anyone approved it, but because nothing prevented them structurally. Constraints built at that layer define the boundary of autonomous action more reliably than any policy about responsible AI behavior.

3. What is the default logging behavior? 

Governance that can’t be audited isn’t governance. If logging is something teams opt into, most of your AI portfolio is invisible to you. If logging is default behavior at the infrastructure layer, you have a record of what happened whether or not anyone thought to turn it on.

4. Who can stop it? 

This is the question most organizations cannot answer cleanly. The model owner thinks it’s the platform team. The platform team thinks it’s the business unit. Nobody has a kill switch. Infrastructure governance builds the kill switch in before the system is deployed rather than after something goes wrong.

Why this is hard

Shifting down into the infrastructure layer requires something most organizations are reluctant to do: make categorical decisions before you have all the information.

Gates feel safer because they evaluate each situation individually. Infrastructure governance makes decisions in advance: this data classification is Restricted; this action type requires human approval; this logging behavior is mandatory. Those decisions will occasionally be wrong for a specific case. That is the cost of governance that actually scales.

The alternative is governance that is theoretically precise and operationally invisible. It’s a policy for every situation, enforced by nobody, remembered by no one, and discovered only when something goes wrong.

Shift Down: Where to start and what comes after

CDOs don’t need to rebuild their entire infrastructure to make this shift. They need one proof of concept, and a plan for what happens once it works.

Pick your highest-risk AI system. Map the data flows into it and ask whether classification controls are structural or policy-based. Map the actions it can take autonomously and ask whether those permissions are granted at the infrastructure layer or assumed by default. Map the logging behavior and ask whether it would survive a team that forgot to turn it on.

The gaps that surface become your infrastructure governance roadmap. Don’t try to close all of them at once. Close the one with the clearest downside first, usually data classification, since it’s the easiest to demonstrate and the hardest to explain away after an incident. Use that first success as proof, not just that the control works, but that it required zero ongoing human effort to maintain. That’s the argument that gets funding for the next one. Infrastructure governance rarely gets budgeted as a program. It gets budgeted one demonstrated win at a time.

These same gaps are also, increasingly, what regulators will ask about when they arrive. A CDO who can point to infrastructure controls answers those questions in minutes. A CDO who can only point to policy documents spends weeks reconstructing what should have been automatic in the first place.

Governance that relies on memory isn’t governance. Governance that lives in infrastructure is.

Every mature engineering discipline eventually moves its critical controls into infrastructure. Engineers don’t remember to encrypt disks, enforce TLS, or authenticate users; those controls already live in the infrastructure. AI governance is following the same path. Organizations that recognize that early will hold fewer committee meetings. They’ll govern by making the right behavior automatic, with infrastructure that already enforces what humans no longer need to remember.

It’s time to Shift Down.

Related Stories

August 27, 2026  |  In Person

Dallas CDO Forum

Omni Las Colinas

Similar Topics
Artificial Intelligence
Data Management
Diversity
Testimonials
background imagebackground image
Community Network

Join Our Community

starElevate Your Personal Brand

starShape the Data Leadership Agenda

starBuild a Lasting Network

starExchange Knowledge & Experience

starStay Updated & Future-Ready

logo
Social media icon
Social media icon
Social media icon
Social media icon
About