Pre-Mortem: The UN’s Global Dialogue on AI Governance

On 6 July 2026, the United Nations opened its first General Assembly-mandated forum on AI governance in Geneva. All 193 member states attended, the first time every country, developing and developed alike, has held a formal seat at an AI governance table. Secretary-General António Guterres named four priorities: common safety standards, human-rights red lines, capacity-building for developing nations, and environmental transparency. After two days, the forum closed with a co-chair summary. Not a treaty. Not an enforcement mechanism. The document records what governments agreed in the room. It does not bind any of them to act on it.

A pre-mortem applies five fixed questions to a public commitment before the outcome is known: what is being bet on, what single assumption underpins it, what was decided before governance existed, who carries it if it fails, and what would prove it worked. This piece applies that format to the public record of the first UN-mandated global AI governance dialogue, convened in Geneva on 6 and 7 July 2026.

 

The Bet

The UN’s bet is that convening all 193 member states repeatedly, Geneva first, New York in May 2027, produces a governance architecture capable of managing AI at global scale before the harms it is designed to prevent have already arrived. The mechanism is norm-setting: shared principles, common language, multilateral dialogue, with no enforcement powers and no treaty obligations. The independent scientific panel, co-chaired by Yoshua Bengio and Maria Ressa, published its first report on 1 July 2026, before the forum opened. Guterres proposed a Global Fund for AI and an AI Child Safety Pledge. Those are specific commitments, publicly made. The bet is that naming four priorities in a room of 193 governments changes what those governments do next.

 

The Assumption

The Dialogue’s credibility turns on a single calculation: that member states, with vastly different AI capabilities, legal systems, and strategic interests, will treat non-binding shared principles as a meaningful constraint on sovereign AI deployment decisions. The Dialogue produces a co-chair summary, not a resolution or treaty. A state that attends, agrees on human-rights red lines, and then deploys AI in ways that cross them faces no published consequence. At the Dialogue itself, the United States delegation argued that voluntary cooperation between government and industry, not binding rules, is the only approach agile enough to govern AI, a preference for exactly the model the Dialogue is testing. The architecture assumes that participation changes behaviour.

 

The Sequence

In 2017, Guterres called for global AI governance. In September 2024, the General Assembly adopted a Global Digital Compact that included AI provisions. In August 2025, the General Assembly established the Global Dialogue by resolution. The first session convened in July 2026. In the same period, the largest frontier AI models were trained, deployed at scale, and embedded in healthcare, finance, law enforcement, and defence, across countries that attended Geneva and agreed that safety is a priority. The Bengio-Ressa panel stated plainly that science currently cannot guarantee AI will not cause catastrophic harm as capabilities increase. The governance structure followed the deployment decisions. That is the sequence.

 

The Pager

Ambassador Egriselda López of El Salvador and Ambassador Rein Tammsaar of Estonia co-chaired the first session. Amandeep Singh Gill, UN Special Envoy for Digital and Emerging Technologies, coordinates the process. When a member state deploys an AI system that crosses the Dialogue’s own human-rights red lines, no document names the consequence. The co-chair summary records what was agreed. It is not a mechanism. The next session is May 2027 in New York. The question of who carries accountability between now and then has no published answer.

 

The Proof

Guterres named four priorities at Geneva. The measure that would prove any of them produced outcomes by May 2027 is at least one of these: a common safety standard that member states have adopted, a documented case where a human-rights red line prevented a harmful deployment, a committed capacity-building fund with named recipients, or an AI environmental reporting mechanism with verified data. The co-chair summary is the output the Dialogue committed to producing. An outcome requires a different commitment entirely.

 

Verdict

If the second session in New York, May 2027, produces a named accountability mechanism for at least one of Guterres’s four priorities, with a state or institution publicly committed to carrying it, the Geneva forum will stand as the first step of something with teeth. Without that, it stands as the moment 193 governments agreed that AI is the most consequential technology of the era, and scheduled a follow-up.

Pre-Mortem: The Big Four’s AI Citation Problem

On 28 July 2026, PwC Middle East responded to an investigation into four of its own published reports. The investigation, run by the AI-detection company GPTZero, had found fabricated citations, non-existent sources, and, in one report, a teenage blogger with 280 followers cited as an authority on a JPMorgan initiative. PwC’s statement: the company “takes the accuracy of our published research seriously” and was “updating a limited number of supporting citations.”

PwC was not first. It was the fourth.

This is the sixteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

Deloitte, EY, KPMG and PwC are betting that a pattern spanning five publicly documented reports, four countries, and under two years can be absorbed as unconnected incidents rather than treated as a shared problem with a shared cause. Each firm has responded on its own terms: a partial refund from Deloitte, quiet withdrawals from EY and KPMG, a promise to update “a limited number” of citations from PwC. None has published a shared verification standard. None has described what changes in how AI-assisted work is reviewed before the next report carries its name. The bet is that four reputations, built over more than a century, can absorb five independently verified failures of the most basic check a research report is supposed to pass: that the sources it cites exist.

 

The Assumption

Every one of the four firms has offered a version of the same explanation once caught. KPMG cited guidelines requiring human oversight to validate content and verify sources. PwC cited quality control processes it expects all its people to adhere to. The assumption underneath both statements: that a written guideline is itself a control, that if a policy exists, a human somewhere is presumed to have applied it before publication. EY’s report, “Points of Attack: Uncovering Cyber Threats and Fraud in Loyalty Systems,” carried the names of two partners and a senior manager in its byline. GPTZero’s analysis put the document at roughly 72 per cent AI-generated content, with more than half its 27 sources failing to correspond to anything real. Two partners and a senior manager reviewed that document before it went out, in name. What “reviewed” required in practice is the question none of the four firms has answered.

 

The Sequence

December 2024. PwC Middle East publishes “Agentic AI: The New Frontier in GenAI,” later found by GPTZero to contain fabricated citations.

October 2025. KPMG publishes “Total Experience: Redefining Excellence in the Age of Agentic AI.” GPTZero later finds 45 citations, 5 accurate, at least 16 fabricated.

October 2025. Deloitte refunds AU$97,000 of its A$440,000 contract with Australia’s Department of Employment and Workplace Relations, after a fabricated Federal Court quote and references to non-existent research papers are identified.

November 2025. Newfoundland and Labrador’s C$1.6 million Deloitte health workforce report is found to contain fabricated citations, including one crediting a Dalhousie University researcher as author of a paper that does not exist. Premier Tony Wakeham calls it “concerning.” Deloitte stands by its findings.

27 April 2026. South Africa’s draft National AI Policy is withdrawn 17 days after publication, after 6 of 67 citations are found fabricated. Minister Solly Malatsi calls it “an unacceptable lapse.”

14 May 2026. EY withdraws “Points of Attack” after GPTZero finds more than half its 27 sources do not correspond to real material.

12 June 2026. GPTZero publishes its investigation into KPMG. Five days later, this series covers a separate KPMG story without connecting the two.

28 July 2026. GPTZero publishes its investigation into four PwC Middle East reports. PwC responds that it is updating “a limited number of supporting citations.”

 

 

The Pager

Five public failures, four countries. Three were identified by the same three researchers, Paul Esau, Om Ogale and Alex Cui, working at GPTZero, not at any of the firms and not at any client who paid for the work. Every firm-level response has stopped at the firm: a refund, a report removed from a website, a statement that guidelines exist. No named individual at any firm has been identified as responsible for approving a document whose sources were not real. The one structural change on record did not come from a firm. Newfoundland and Labrador overhauled its own procurement process, requiring disclosure of AI use in future contracts. The government fixed what the contractor did not.

 

The Proof

None of the four firms has published a verification standard: a description of what checking a citation actually involves before a report carries its name. That is the proof measure, not an apology and not a quiet correction, but a public description of the review step, specific enough to be checked against the next report. The IAASB, the International Auditing and Assurance Standards Board, is revising ISA 500, the international standard governing what constitutes sufficient, appropriate audit evidence. That project is still at the research stage and covers formal audit engagements, not the thought-leadership publishing where three of these five failures occurred. Until one firm publishes what verification looks like in practice, every new report each of them publishes resets the same test.

 

Verdict

If one firm publishes a specific, checkable verification standard before a sixth incident surfaces, it becomes the reference point the other three are measured against, the position peer accountability once created around data breach disclosure, where one actor’s transparency made silence from the others harder to sustain. Newfoundland’s government has already shown the structural fix is available: a procurement clause requiring AI disclosure, written in days. If no firm moves first and a sixth incident surfaces, the pattern stops reading as isolated mistakes and starts reading as an industry’s operating baseline. Five failures in under two years, three caught by the same outside team. The firms selling AI governance advisory to clients have not yet demonstrated they can apply the same standard to their own published work. The next report each of them publishes is the test.

Nobody Owns AI in Your Organisation. That Used to Be Survivable.

 

In most organisations, nobody owns AI, not really. Not officially, not on an org chart, not in a way anyone could point to under pressure. For the last few years, that has been fine. Everyone touched AI a little, so no one needed to own it entirely.

That fuzziness is now expensive.

Two things changed the maths. The first is regulation. From 2 August 2026, the EU AI Act’s transparency obligations became enforceable: AI systems that interact directly with people, generate synthetic content, or use emotion recognition or biometric categorisation now require disclosure (European Commission), with providers facing fines of up to €15 million or 3 per cent of global annual turnover, whichever is higher (Cooley). A regulator does not care whether your organisation has formally assigned AI ownership. It cares who signs the compliance filing.

The second is spend. Global AI spending, including infrastructure capital expenditure, is on track to reach $2.5 trillion this year, a 44 per cent increase on last year, according to Gartner research reported by Fortune. Next year, Gartner expects that figure to climb to $3.3 trillion. That is capital being committed at a scale that normally comes with a name attached to the decision, not pocket-change experimentation.

Except it doesn’t. A Pearl Meyer survey of board members, CEOs, C-suite executives and senior managers found that just 34 per cent of C-suite executives say it is consistently clear which executive or team makes the calls on AI, the lowest confidence score of any group polled. Board members are considerably more settled, at 53 per cent. Senior managers below the C-suite, who carry out the actual AI work day to day, are more confident still, at 57 per cent. The C-suite sits in the middle of that gap, managing expectations from above and execution from below, and is the only group unsure who is actually in charge.

Meanwhile, PwC’s 29th Global CEO Survey, drawn from 4,454 CEOs across 95 countries, found that 56 per cent report no significant financial benefit from their AI investment so far, and only 12 per cent report gains on both cost and revenue (PwC). Spend accelerating, returns lagging, ownership unclear: three symptoms, one disease.

 

Governance Failure Wearing an Investment Story

I have watched this exact pattern play out on transformation programmes long before AI made it fashionable. A programme gets funded because the business case looks compelling on a single slide. Nobody sits down and decides who has the authority to stop it, slow it, or redirect it once it is underway. The absence of that decision does not read as a problem at the time, because everything is moving and everyone is busy. It reads as a problem eighteen months later, when the programme has drifted from its original purpose and there is no single person whose job it was to notice.

AI is running the same play at a faster clock speed. A RACI chart is not corporate theatre. It is the difference between a decision someone made on purpose and a decision that happened to everyone by default. Right now, most organisations have the second kind.

 

What an Actual Owner Looks Like

Contrast that with the UAE’s approach to its own AI commitment. In April 2026, Sheikh Mohammed bin Rashid Al Maktoum announced that 50 per cent of UAE government services and operations would run on agentic AI within two years, making it the first government in the world to commit to autonomous AI at that scale (Khaleej Times). Whatever view you take of the ambition, the governance structure was not an afterthought. Sheikh Mansour bin Zayed Al Nahyan was named to oversee implementation. Mohammad Al Gergawi was named to chair the taskforce running it. Before the programme scaled, someone’s name was attached to it.

It is not that most organisations lack ambition for AI. It is that they have skipped the one governance step that made every other major technology rollout survivable: deciding, on purpose, who is accountable before the spending accelerates past the point where anyone can meaningfully intervene.

 

Three Things That Actually Fix This

Name a single accountable owner for AI decisions at the level where spending actually happens. Not a committee. A person.

Separate who evaluates AI performance from who decides whether to scale it. Those are different jobs, and conflating them is how bad bets survive their first review.

Treat AI spending with no named owner attached to it as a governance red flag before it becomes an investment number on a board slide, not after.

 

None of this requires new technology. It requires the same discipline that used to be applied to every large capital commitment, before AI convinced everyone the normal rules no longer applied. They always did. The bill has simply arrived: from a regulator, from a survey, and from a CEO’s own board asking where the money went.

Pre-Mortem: NHS Federated Data Platform

 

On 3 August 2026, NHS England apologised. The apology confirmed what National Data Guardian Nicola Byrne had identified five days earlier: the Data Protection Impact Assessment (DPIA) for the Federated Data Platform had stated that only NHS staff could access identifiable patient data. That statement was wrong. Palantir staff held access to identifiable patient information within the national data integration environment, an arrangement the DPIA had not disclosed.

This is the fifteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

The Bet

NHS England is betting that a £330 million platform built on Palantir’s proprietary Foundry software can serve as the trusted data infrastructure for NHS analytics, and that the governance commitments made publicly about data access are auditable in practice. The bet has been partially called already. The DPIA that underpinned the programme’s public accountability framework described access controls that did not match operational reality. NHS England acknowledged the error and corrected it. The bet that now matters: that the February 2027 break clause decision, whether to extend or exit, can be made on the basis of accurate information.

The Assumption

The single belief the whole framework rests on: that NHS England can demonstrate meaningful oversight and control of a platform whose codebase NHS analysts cannot read or edit. Palantir owns the Foundry software. NHS analysts work within the platform but cannot examine or modify the code that shapes its outputs. The National Data Guardian (NDG) criticism was triggered by the gap between what was publicly asserted about data access and what was operationally true. If the accountability assertion in the DPIA did not survive scrutiny, the assumption that NHS England can verify what Palantir staff do with patient data inside a proprietary system deserves the same examination.

The Sequence

November 2023. Palantir wins the £330 million FDP contract.

April 2026. Parliamentary debate on the FDP. NHS England officials warned staff internally not to criticise the platform’s performance.

12 May 2026. NHS England confirms Palantir staff have administrative access to identifiable patient data in the national data integration environment, contradicting earlier assurances.

June 2026. The government announces a formal review of the Palantir contract, following a Science, Innovation and Technology Committee report that branded the company “an unacceptable point of weakness” in UK public sector infrastructure.

9 July 2026. The Health and Social Care Committee writes to the Health Innovation Minister recommending the exercise of the February 2027 break clause, citing “serious mistrust” among the public towards Palantir.

29 July 2026. National Data Guardian Nicola Byrne formally criticises NHS England for inaccurate DPIA disclosure.

3 August 2026. NHS England apologises and confirms the DPIA error.

The Pager

The National Data Guardian used her statutory function and the result was a public apology from NHS England. The named individual who authorised the submission of a DPIA that did not accurately describe Palantir staff access has not been identified publicly. Jules Hunt, interim Director General for Technology, Digital and Data, holds the relevant executive function. The chief digital and information officer role has not had a permanent holder since at least early 2025; the most recent interim departed in April 2026, before the DPIA error became public. The programme sits with interim leadership in the window immediately before the most consequential procurement decision of its lifespan.

The Proof

February 2027 is the break clause decision point. The Department of Health and Social Care must actively trigger the first extension; if it does not, the contract lapses in spring 2027. The Health and Social Care Committee’s recommendation is on the public record. The government has not yet responded. The outcome measure is binary and specific: the break clause is exercised or it is not. Whether the platform’s actual adoption record across NHS trusts factors into that decision is the proof measure.

Verdict

If the government exercises the February 2027 break clause, it becomes the first time a cross-party parliamentary committee recommendation, a National Data Guardian rebuke, and a public apology from the contracting body have together produced a procurement exit in NHS technology history. That would be a significant accountability signal for every future public sector AI contract. If the contract is extended, the question shifts to what changed in the governance architecture to justify continuation, and whether the interim executives carrying the programme can demonstrate what that change looks like in operational terms. The break clause is not a threat. It is a proof point with a date.

Pre-Mortem: A Billion Workers Scored in Secret. Is It Legal?

On 20 January 2026, two job applicants filed a class action against Eightfold AI Inc. in a California state court. The complaint alleged that the company had scraped personal data on over one billion workers, scored every candidate on a zero-to-five scale, and discarded low-ranked applicants before any human saw their application. The legal basis is the Fair Credit Reporting Act (FCRA). The plaintiffs’ central claim is not that the algorithm was biased. It is that the algorithm existed in secret.

This is the fourteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

Eightfold AI and the companies deploying its platform are betting that an AI system which aggregates third-party data, including social media profiles, location data, and online tracking cookies, to score individuals for employment purposes does not meet the legal definition of a Consumer Reporting Agency under the Fair Credit Reporting Act. The complaint names Microsoft, Morgan Stanley, Starbucks, BNY, PayPal, Chevron, and Bayer as companies using Eightfold in their hiring process. Co-Founder and CEO Ashutosh Garg responded with a public statement on responsible AI, noting that the platform undergoes third-party bias audits and that data comes from candidates or employers, not third-party scraping. The bet is not about whether the algorithm is accurate. It is about jurisdiction: whether the FCRA, written before algorithmic hiring existed at this scale, reaches far enough to cover what Eightfold built.

 

The Assumption

The single belief the whole framework rests on: that an AI platform scoring candidates for employers is categorically different from a consumer reporting agency, because the platform does not produce a consumer report in the form the FCRA contemplates. Eightfold filed a 35-page motion to dismiss arguing precisely that. The hearing was held on 4 August 2026 before U.S. District Judge Yvonne Gonzalez Rogers in Oakland. No ruling has been published. If the assumption is wrong, the compliance obligations the FCRA places on consumer reporting agencies, including disclosure, consent, and accuracy mechanisms, apply to every AI hiring platform operating on third-party data at comparable scale.

 

The Sequence

20 January 2026. Class action filed by former EEOC Chair Jenny R. Yang and the nonprofit Towards Justice. The complaint: Eightfold AI functioned as an unregistered consumer reporting agency across a dataset of over one billion workers.

18 June 2026. Plaintiffs’ opposition to Eightfold’s motion to dismiss filed.

22 June 2026. In the parallel Mobley v. Workday case, a federal judge denied Workday’s motion to dismiss claims of race, age, and disability discrimination through AI hiring tools.

9 July 2026. Eightfold reply brief filed.

4 August 2026. Motion to dismiss argued in Oakland before Judge Yvonne Gonzalez Rogers. No ruling published as of 16 August 2026.

13 August 2026. Eightfold AI named “Agentic AI HR Solution of the Year” at the HR Tech Breakthrough Awards.

 

The Pager

Kistler et al. v. Eightfold AI Inc., No. 3:26-cv-01768 names Eightfold AI as defendant. No talent acquisition leader or CHRO at Microsoft, Morgan Stanley, Starbucks, or any other company deploying the platform has been named as a defendant, and no deploying company has publicly committed to disclosing the tool’s existence to applicants. The pager sits with the vendor. The question of who carries it at the companies deploying the platform remains unanswered.

Garg’s public statement on responsible AI is a creditable position. It does not address what obligations the companies using Eightfold carry, or what those companies owe to the candidates who may have been scored and discarded before a human saw their application.

 

The Proof

The motion to dismiss ruling is the first proof point. A denial advances the FCRA question to discovery and the merits. It would be the first federal answer on whether AI candidate scoring constitutes consumer reporting. A grant sends the question back to the FTC and Congress, where progress has not matched the scale of deployment. The outcome measure worth watching is not which side wins the motion. It is whether any major Eightfold client commits to applicant disclosure before the court decides whether disclosure is legally required.

 

Verdict

If Judge Gonzalez Rogers denies the motion to dismiss, the case advances and the FCRA question gets its first federal answer in the context of AI hiring tools. That ruling will matter to every organisation using algorithmic screening, not only Eightfold’s clients. A denial does not mean Eightfold loses; it means the question gets answered in a setting with evidence, argument, and binding precedent. If the motion is granted, the accountability gap returns to regulatory and legislative channels, where the pace has not matched the scale of the deployment. What would change this assessment is action of a different kind: a major employer publicly committing to applicant disclosure before the court makes the decision for them.

Prompt Injection Is a Governance Failure Wearing a Technical Costume.

Every prompt injection headline reads like a technical failure. A model got tricked. A filter didn’t catch it. The vendor needs to patch something.

That framing is comfortable, and it is wrong. The technical trick is real. The governance failure sitting underneath it is the actual story, and it is the one almost nobody in the room wants to own.

 

Why the Trick Works in the First Place

The mechanism is architectural, not a bug in the usual sense. Large language models treat the system prompt, the user’s request, and any text retrieved from an external source as a single stream of tokens. There is no reliable internal boundary between an instruction and a piece of data. A hostile sentence buried in a document, a web page or a support ticket can carry the same authority as a command typed directly by a trusted user, because the model was never built to tell the difference.

OWASP’s 2026 State of Agentic AI Security and Governance report found prompt injection now maps to six of its ten top categories for agentic applications, up from a mostly theoretical concern in the 2025 edition to one backed by documented breaches and tracked vulnerabilities. Coding agents dominate the attack data, and only 37% of organisations report having a policy in place to even detect unauthorised AI deployments running inside their own environment.

 

The Failure Is a Control Boundary, Not a Model Flaw

This is where the governance framing actually matters. Prompt injection succeeds because enterprise workflows assume the model can reliably tell trusted instruction apart from hostile text, an assumption that fails the moment one interface carries user intent, retrieved content and tool-facing control signals in the same session. Most organisations respond by treating guardrails as a static filter list rather than a real system of content separation, monitoring and authorisation. A filter can catch a known bad phrase. It cannot answer the actual governance question, which is who controls what the system is allowed to do once it has been steered.

Security researcher Simon Willison’s “lethal trifecta” names the actual risk condition plainly: an AI agent with access to private data, exposure to untrusted content, and the ability to communicate externally, all three at once, is where exfiltration happens. Meta’s own internal guidance treats those three properties as a budget rather than a checklist. Combine all three and the agent needs a human in the loop before it acts, not after.

 

Why This Keeps Getting Treated as IT’s Problem Alone

Handing this to the security team as a patching exercise misses what the data is actually showing. A model update might close one exploit path. It will not answer who approved an agent’s access to a customer database, why that same agent can also send emails externally, or what happens the day it does both at once because nobody ever wrote down that it should not be allowed to. Those are ownership questions, not model questions, and ownership questions do not get solved by a vendor release note.

 

What Governance-First Actually Requires

Start by classifying every channel an agent reads from according to trust level, and keep untrusted content out of instruction scope entirely rather than hoping the model sorts it out at runtime. Quarantine tool access behind explicit policy gates, so an agent combining private data access, untrusted content and external communication needs sign-off before it can act, not a retrospective audit after it already has. Treat a pattern of near-miss prompts as an abuse signal worth escalating, not a string of isolated one-off incidents each closed out individually.

All of it is the same governance discipline organisations already apply to identity and access management, pointed at a new kind of actor that happens to run on language instead of credentials, not a new technology purchase.

 

Who Approved This, and Did They Know What They Were Approving

Before the next prompt injection incident gets logged as a technical exploit, ask who actually approved the access the exploit relied on.

If nobody can answer that cleanly, the model was never the vulnerability. The governance around it was.

Pre-Mortem: The Accountability Question the Mills Review Left Open

On 6 July 2026, the Financial Conduct Authority published the Mills Review, its examination of how AI will reshape retail financial services in the UK. The review covers seven recommendations across the regulatory perimeter, oversight architecture, and the transition to autonomous decision-making. It names the accountability gap at the centre of autonomous AI trading. It does not close it.

This is the thirteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

UK firms deploying autonomous trading AI are betting that the Senior Managers and Certification Regime (SMCR), the framework that holds named executives personally accountable for conduct failures in their area of responsibility, covers their position through general senior manager oversight. The FCA has been clear that delegating a decision to an algorithm does not transfer senior manager liability to the algorithm. The bet is that this principle, correctly stated and on the public record, can be demonstrated in practice before an enforcement case defines what demonstrating it actually requires.

 

The Assumption

Seven recommendations. One question still without an answer:

When an autonomous trading system executes a decision at machine speed, without pausing for human approval of the individual trade, which specific senior manager function is accountable if that decision causes a customer loss, and what does demonstrating adequate oversight of a system like that actually require?

The Mills Review acknowledged the problem directly. Without guidance, the review found, the combination of greater opacity in AI-mediated decisions and factors such as model drift makes it harder for the regulator to identify a de facto responsible individual, or for senior managers to evidence meaningful human control. Stakeholder feedback throughout the review called for clearer guidance on what constitutes the “reasonable steps” expected of senior managers. The review recommends the FCA develop it. The FCA has not yet published it. Every firm currently deploying autonomous trading AI is operating on the assumption that its existing accountability structure covers the gap. That assumption has not been tested in an enforcement case.

 

The Sequence

December 2019. SMCR extended to all FCA solo-regulated firms, completing its rollout across financial services.

27 January 2026. The FCA launched the Mills Review, acknowledging that AI in retail financial services had developed faster than the regulatory frameworks designed to govern it.

24 February 2026. Call for input closed.

6 July 2026. The review published seven recommendations. The FCA committed to adapting its regulatory frameworks as the transition to autonomous models continues. No guidance named a specific senior manager function as accountable for autonomous trading decisions. No guidance defined what “reasonable steps” requires for a system executing at machine speed without human review of individual decisions.

The capability reached the market before SMCR was tested against it. The review arrived after the capability. The guidance has not arrived yet.

 

The Pager

The FCA has confirmed there will be no dedicated Senior Manager Function for AI, and that accountability falls on existing functions. That is a clear policy position and it deserves credit for being stated plainly. The Treasury Select Committee has urged the FCA to publish guidance specifying the level of assurance expected of senior managers for AI-related harm. The Mills Review carried that request forward into its recommendations. The harder question is the one seven recommendations did not answer: when an autonomous trading system causes a customer loss, which specific function holder carries the call?

 

The Proof

There are no enforcement cases. The first case will establish what “reasonable steps” means in an AI trading context. The Mills Review is a process measure: it produced recommendations. The outcome measure worth watching is whether the FCA’s follow-on guidance names a specific function and defines the oversight standard in operational terms rather than principles alone. A principle restated is not a gap closed.

 

Verdict

If the FCA’s follow-on guidance names the senior manager function accountable for autonomous trading AI and defines what “reasonable steps” requires at the operational level, UK financial services will have resolved an accountability gap that every other major jurisdiction is still navigating. The review’s existence, the named individual who led it, and the seven published recommendations are genuine evidence that the FCA identified the problem and moved on it. Without operational guidance, the gap stays open. The first enforcement case will write the rule in the least comfortable setting available. That is a considerably worse way to write it.

The $5.5 Trillion Bill for Doing Nothing About AI Skills

IDC put a number on the cost of enterprises not knowing what to do about AI skills: $5.5 trillion. Not by 2030. By the end of 2026.

That is not a distant workforce-planning problem. It is the price tag on decisions organisations are making, or more often deferring, this quarter.

The number comes from IDC’s survey of enterprise IT leaders across the US and Canada. It measures a specific kind of pain: product delays, lost competitiveness, and business walking out the door because the people needed to build and run AI capability were not there when the work needed them.

An IDC Spotlight Paper distributed via workforce-skills platform Workera applies the same figure directly to the AI skills conversation, and the application largely holds up. Most of what IDC’s original survey describes as a broader tech talent shortage is, in practice, an AI capability shortage wearing a wider label.

Three other figures make the same point from different angles. The World Economic Forum’s Future of Jobs Report 2025, surveying over a thousand employers and 14 million workers across 55 economies, found that 59% of the global workforce will need reskilling or upskilling by 2030, and that 11% of that group are unlikely to receive it. Indeed’s hiring data shows the share of job postings with “AI” in the title has more than tripled since 2022, from 2.6% to 8.3%. And PwC’s 2026 Global AI Jobs Barometer, built on more than a billion job advertisements, found that AI-skilled workers now command a 62% wage premium over comparable peers, up from 57% the year before and roughly 25% two report cycles before that.

These numbers describe a market that has already repriced itself, not a future state, while most enterprise workforce plans are still budgeted as though it hasn’t.

 

The Premium Is the Market Telling You Something

Wages move slowly almost everywhere except where genuine scarcity exists. A skill premium that has climbed from roughly 25% to 62% across three consecutive PwC survey cycles is not a normal labour-market signal. When a specific skill commands 62% more pay than the equivalent role without it, and that gap is still widening year over year, that is the market pricing in a shortage faster than most HR functions can respond to it, not a talent management curiosity.

Second Talent’s 2026 research puts a shape on that shortage: roughly 1.6 million open AI-related roles globally against around 518,000 candidates qualified to fill them, a demand-to-supply ratio a little over three to one. Every organisation competing for AI capability right now is competing inside that gap, and every quarter spent treating reskilling as a training-budget line item rather than a capital allocation decision is a quarter spent losing that competition to whoever moved first.

 

Why This Belongs in the Risk Register, Not the Learning and Development Plan

Most organisations still route AI reskilling through the same governance as any other training initiative: an L&D budget line, a completion metric, a once-a-year review. That treatment made sense when the skills in question were incremental. It does not hold up against a $5.5 trillion cost estimate and a wage market moving by double digits year over year.

A capital risk gets tracked differently to a training initiative. It gets a named owner, a quantified exposure, and a review cadence tied to the business calendar rather than the HR calendar. Few organisations apply that discipline to AI skills, because the function historically responsible for skills, HR, was never built to run risk registers, and the function that runs risk registers, finance and the PMO, was never asked to own workforce capability.

That gap in ownership is the reason the $5.5 trillion figure keeps compounding instead of shrinking, not a technicality.

 

What Actually Changes the Trajectory

Closing this gap requires three specific shifts most organisations have not made, not a bigger training budget.

Put a named executive owner on AI capability risk, distinct from whoever owns general L&D, with the same reporting rigour as any other material risk on the register. Measure the capability gap in the terms the wage market already uses: roles you cannot fill, roles you are overpaying to fill, and work you are declining because you lack the people to do it, not completion percentages on a training platform. And treat the reskilling decision as time-sensitive capital allocation, where every quarter of delay is a quarter in which the 62% premium, and the competitors already paying it, get further ahead.

 

The Window Is a Cost Curve, Not a Deadline

There is no single date after which the AI skills gap becomes unrecoverable. What exists instead is a cost curve that gets steeper the longer it is ignored, priced daily by a labour market that has already decided what AI capability is worth.

The organisations that treat this as a 2027 problem will be paying 2026 prices for it well into the decade. The ones already moving are the ones setting the price.

Pre-Mortem: The Liability Chain Medicare’s AI Prior Auth Model Has Not Drawn

On 1 January 2026, the Centers for Medicare and Medicaid Services in USA launched the WISeR model in six states, introducing prior authorisation to procedures that traditional Medicare had always provided without it. Contracted companies now assess medical necessity using AI. Human clinicians are required to sign off on any denial. The Senate voted 46-50 in July 2026 to keep the programme running. One question has not been answered.

This is the twelfth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

CMS is wagering that AI-assisted prior authorisation reduces unnecessary Medicare spend without producing the patient-safety incident that forces a political reversal. If WISeR delivers measurable waste reduction without a documented causal chain from AI denial to patient harm, it becomes the template for prior authorisation across Medicare nationally. If it produces that chain, a documented line from AI recommendation to denial to patient harm, it does not just end WISeR. It becomes the reference point that makes AI prior auth politically untouchable in federal health programmes for a generation.

 

The Assumption

CMS has answered every operational question about WISeR except this one:

When an AI recommendation leads a contracted clinician to deny care and a patient is harmed as a result, where does liability sit?

The model design places a human clinician between the AI output and the denial decision. That establishes a paper trail. It does not establish a liability framework. Contractors earn between 10 and 20 per cent of the savings generated by denials and lose that payment when a denial is overturned on appeal. That is a commercial penalty, not a clinical one. The Federal Tort Claims Act does not cover contracted entities. No federal court has tested whether a contracted clinician reviewing AI recommendations at volume carries the same duty of care as a treating physician making an independent clinical judgement.

The assumption doing all the work in this model is that the human review layer is accountability enough. That assumption has not been tested.

 

The Sequence

1 July 2025. CMS published the WISeR notice in the Federal Register and did not submit it to Congress under the Congressional Review Act. That omission would matter later.

1 January 2026. WISeR launched in New Jersey, Ohio, Oklahoma, Texas, Arizona, and Washington.

17 March 2026. The Washington Post published an exclusive: Medicare’s new AI gatekeeper was delaying care for seniors. The University of Washington’s medical system had nearly 100 patients waiting for epidural injections. In Arizona, Phoenix pain specialist Dr Matthew Crooks told Medscape that every epidural injection submitted in the first three months had been denied and described the system as completely nonfunctional and unsustainable. In Texas, initial AI approval rates ran at 62 per cent, against a 92 per cent national approval rate across Medicare Advantage.

25 March 2026. The Electronic Frontier Foundation filed a FOIA lawsuit against CMS in federal court in California, seeking records on WISeR’s AI algorithms, training data, bias safeguards, and the financial incentives paid to contractors. The suit confirmed that CMS had not made its AI methodology or vendor compensation structure publicly available seven weeks after launch.

6 April 2026. CMS published a Federal Register notice delaying prior authorisation implementation for certain services within the model to allow additional time for operational readiness. CMS also issued a corrective action order against one of its AI contractors. Both confirmed that the model’s operational design had not performed as intended in the first quarter.

12 May 2026. The Government Accountability Office issued its determination: WISeR met the Administrative Procedure Act definition of a rule and was subject to the Congressional Review Act. CMS had not made the required submission to Congress before the model took effect.

20 May 2026. Senator Ron Wyden and Representatives Suzan DelBene and Greg Landsman introduced resolutions of disapproval in both chambers, seeking to repeal WISeR under the CRA.

6 July 2026. Gold carding launched in Washington state. Providers achieving a 90 per cent affirmation rate across a minimum of ten prior authorisation requests become exempt from further review for covered services. Quarterly rollout to the remaining five states is planned.

16 July 2026. The Senate voted 46-50 against advancing the disapproval resolution. Party line. WISeR survived. The liability question the GAO had exposed survived with it.

The Pager

Dr Mehmet Oz, Administrator of the Centers for Medicare and Medicaid Services.

The message: WISeR’s accountability chain has not been drawn. The model places a contracted clinician between an AI denial recommendation and a Medicare beneficiary, but no published document establishes where negligence sits when a patient is harmed following an AI-assisted denial. The Federal Tort Claims Act does not cover contractors. Contractors point to the human clinician. Clinicians are reviewing AI output under volume pressure with no published duty-of-care standard for that specific context. When the first federal lawsuit tests this configuration, and one will, CMS will need a published framework, not a contract clause. That framework is easier to write before litigation than after.

 

The Proof

Gold carding is the model’s self-correction mechanism. If quarterly rollout reaches all six states and the 90 per cent affirmation threshold functions as a genuine quality signal, the AI layer contracts over time as trust is established. Proven providers exit prior auth. New entrants face the review. The model becomes calibrated rather than blanket.

If gold carding stalls or rollout criteria are applied inconsistently across jurisdictions, the AI layer expands without a release valve. Prior auth burden accumulates regardless of provider track record. The model becomes a cost-reduction instrument with no exit for providers who have earned one.

The proof of the bet is not the aggregate savings figure. It is whether WISeR, by the end of 2026, has published a liability framework and delivered gold carding in all six states. Without both, the model is running on the same untested assumption it started with.

 

Verdict

If CMS publishes a liability framework for AI-assisted denials before a federal case forces the question, and gold carding delivers consistent rollout across all six states, WISeR will be the strongest government evidence yet that AI-assisted utilisation review can reduce Medicare waste without a patient-safety crisis. The accountability design would become the reference for every federal health programme that follows.

Without the liability framework, WISeR accumulates its risk quietly. Not through a single dramatic incident, but through the gap between AI recommendation volume and human review capacity, compounded by an accountability vacuum no published document has yet closed. That gap does not stay open indefinitely.

Pre-Mortem: The US Government’s 3,611 AI Use Cases

On 3 April 2025, the White House issued OMB Memorandum M-25-21, directing every major federal agency to appoint a Chief AI Officer, expand the use of artificial intelligence across government operations, and manage risk proportional to each system’s impact on citizens. Twelve months later, the Federal Agency AI Use Case Inventory records 3,611 AI use cases across 56 agencies, more than double the prior year’s total. A May 2026 survey of more than 200 technology executives across civilian and defence agencies found 53% are actively planning agentic AI pilots. Only 8% of those agencies have incident response frameworks in place.

This is the eleventh piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

The US government is betting that embedding AI across 3,611 federal workflows covering benefits decisions, immigration adjudications, healthcare determinations, and law enforcement, will make government faster and more efficient before the accountability architecture governing those decisions is clarified. OMB M-25-21 requires Chief AI Officers, public AI inventories, and risk management proportional to impact. The hard compliance deadline for role-specific AI training arrives in September 2026. If that architecture catches up to the deployment before a consequential wrong decision reaches a citizen with no named relief, the bet holds.

 

The Assumption

The expansion’s credibility turns on one unanswered question: whether the Federal Tort Claims Act, designed to govern negligent acts by human federal employees, applies without amendment to decisions made by AI agents running inside federal systems. The same May 2026 survey found only 44% of agencies include vendor liability clauses in AI contracts, and only 29% have documented kill-switch procedures. The legal architecture governing accountability in federal government was designed for humans acting on behalf of the state. No court has ruled on whether it extends to the agents they built.

 

The Sequence

In 2024, federal agencies reported 1,757 AI use cases. By 2025, that figure had grown to 3,611. In March 2026, the Department of Veterans Affairs expanded AI use in claims processing, with 215 of its 367 AI systems classified as high-impact, covering benefit eligibility, healthcare access, and fraud detection. In May 2026, the majority of agencies were planning agentic pilots, with only 20% having defined pre-deployment testing policies. The AI reached citizens before the accountability reached the AI.

 

The Pager

Russell Vought, Director of the Office of Management and Budget, carries the M-25-21 mandate at the centre of the federal AI expansion. Every covered agency has designated a Chief AI Officer responsible for inventory, risk management, and AI governance at agency level. The VA alone runs 215 high-impact AI systems. No single published document names what relief is available to a veteran whose claim was influenced by one of those systems, which official carries accountability for that decision, or whether the Federal Tort Claims Act applies when the acting party is software, not a civil servant.

 

The Proof

The measure that would settle this is a published legal standard: a named accountability chain clarifying who carries liability when a federal AI agent makes a consequential wrong decision, whether government, vendor, or joint, and whether the Federal Tort Claims Act applies or new legislation is required. No such standard has been published. OMB M-25-21 requires risk management proportional to impact. It does not name the relief available to a citizen when that risk management fails, nor the date by which that question must be answered.

 

Verdict

If OMB publishes, before the September 2026 training compliance deadline, a named accountability standard for AI-driven decisions in high-impact federal systems, covering who carries liability when the AI is wrong and what legal remedy a citizen holds, the expansion will stand as the most deliberate attempt the US federal government has made to govern AI before it reaches citizens at scale. Without that, the US government has put AI into 3,611 workflows and left the question of who carries the call when the AI gets it wrong to be answered in court, by accident, or not at all.