Central principles
A small set of non-negotiables: what the organisation will protect, what it will not tolerate, and how decisions are made when the answer is not obvious.
AI Federalism is Tim Brewer’s methodology for making that power workable. It separates what must be held centrally from what belongs with the people closest to the decision — so an organisation can move without losing control.
Most AI governance fails at one of two extremes: a central policy that cannot survive contact with delivery, or local experimentation with no shared line of sight. Federalism is the middle path — a deliberate distribution of authority, accountability and judgement.
Each level has a distinct job. The point is not to add another committee; it is to stop every decision becoming everyone’s problem — while keeping the important connections visible.
A small set of non-negotiables: what the organisation will protect, what it will not tolerate, and how decisions are made when the answer is not obvious.
The people closest to a use case own its purpose, impact and outcome. Governance stays connected to the work instead of becoming a remote approval desk.
Security, access, monitoring and evidence make the principles real. Controls should be proportionate to the exposure and maintained as systems change.
Privacy, contractual, regulatory and audit obligations set the boundaries. Legal judgement is brought in at the right point, not bolted on at the end.
The person doing the work still has to decide. Clear escalation routes help teams act with confidence when a new use or edge case appears.
The model gives teams a common language for deciding when to act, when to ask, and when to stop. Central functions provide the boundary and the route; owners provide the context; front-line teams provide the signal.
AI governance is not a standalone service catalogue. It is one part of the connected operating rhythm GOVERNANCE Ltd. brings to growing organisations carrying more exposure than their structure was built for.
Keep the organisation’s material exposures visible, owned and connected to the decisions that protect continuity.
Give AI use cases a practical home: inventory, accountability, review points and principles that people can follow.
Turn technical safeguards into an operating rhythm with clear control owners and evidence that can stand up to scrutiny.
Bring privacy, data mapping and DPIAs into delivery so legal duties are understood before they become blockers.
AI Federalism is authored by Tim Brewer. It is designed for operators who need governance to keep pace with an organisation’s real systems, obligations and decisions — without a dedicated leader to carry it alone.
The method makes authority explicit, keeps accountability close to the work, and leaves a record leaders can return to.