Organizational design · July 21, 2026 · 5 min read

Don't Default AI to IT

Ask most biotechs who owns AI and the answer is IT, a function trained to say no. Traditionally IT in a regulated company is a risk-management shop. Today it has to be a foundational enabler of AI, and that shift is a culture change at its core.

Ask most biotechs who owns AI, and where its guardrails live, and the answer is IT. It is the default, and it is usually a mistake. Not because IT is not capable, but because of what the function has been built to be. In a regulated industry, IT was handed the job of control: validated systems, access management, data integrity, and audit trails, the real and unglamorous obligations of 21 CFR Part 11 and GxP. Do that job for two decades and you get very good at one reflex: protecting the company by slowing the new thing down. Point your AI ambition at a function trained to say no, and you get exactly that.

The default, and the better instinct

The regulated reality that made IT a control function has shifted under it. AI is not one more system to validate and lock down; it is the capability the whole company now runs on. That flips what its guardian is for. Traditionally, IT in a regulated company is a risk-management function. Today it has to be a foundational enabler of the AI transformation, or it is the thing quietly blocking it. There is no neutral.

So AI is a capability to be led, not a risk to be managed down. It should report to the most forward-thinking, respected senior leader you have, high in the company, not buried where new things go to be assessed. Do not default it to IT.

Governance as a brake versus a shaping cone The drive to build with AI forks two ways. Defaulted to IT as a risk gate that reports low and says no, it stalls. Reframed as Innovation Technology that reports high and asks how, it becomes responsible speed. The same function, opposite mandates. THE DRIVE TO BUILD INNOVATION TECHNOLOGY reports high, asks how Responsible speed an accelerator IT AS A RISK GATE reports low, says no Stalled the department of no
The same function, opposite mandates. Governance is the brake, or the shaping cone that turns a blast into flight.

The move

At a company where I now lead the AI and innovation strategy, I made an unusual case, the kind that raises eyebrows in most orgs: IT should report up through me. Then we did the part that mattered more than the org chart. We rebranded the culture of the function itself, from Information Technology to Innovation Technology. Same acronym. Opposite mandate.

The reframe was explicit, and I said it in a picture. This team is the shaping cone on a rocket engine. A shaping cone does not stop the blast. It takes all that raw energy and turns it into directed flight. Their job is not to block the new. It is to ask, of everything new, “how do we do this responsibly?” That is the Permission pillar made real: good governance is not a brake, it is the cone that turns a blast into flight. The function is a group of earlier-career people, and the rebrand lit them up. Being told you are a risk-management cost center is a very different thing from being told you are the foundational champions of the company’s responsible-innovation engine. IT stopped being the last stop that kills momentum and became a foundational component of the AI strategy itself.

Why it works, and where it is easy to get wrong

Two moves, and you need both. The reporting line put the function close to the ambition, under a leader whose job is to build and not only to protect. The culture rebrand gave the people a mandate they were proud to carry. A reporting change without a mandate change is a new box on an org chart. A rebrand without a reporting change is a poster on a wall.

But do not mistake the mechanics for the change. Moving a box on the org chart is the easy, visible half. The real shift, the one that actually turns a risk function into an enabler, is a culture and ways-of-working change at its core: the same people, doing recognizably the same governance, but starting from “how do we make this work, responsibly” instead of “what could go wrong.” You cannot restructure your way to that posture. You lead people to it, which is why this is a people-first change wearing an org-chart costume.

What does not transfer

Take the pattern, not the parts. You do not need to literally rename your IT department, and you may not be the right person for it to report to. What transfers is the principle: put AI and its governance high, under your most forward-thinking leader, and reframe the guardrail function from “prevent the bad” to “enable the responsible.” And it only holds if the mandate is real. If “Innovation Technology” is still measured on tickets closed and incidents avoided, you have renamed the department of no and changed nothing. Change what the function is rewarded for, or the rebrand is theater. The full record of the engagement is here.

Monday morning

Ask one question, and answer it honestly: where does AI report in your company, and what is that function actually rewarded for? If the answer is a risk silo rewarded for saying no, you have found the bottleneck. Move it up, to the leader most eager to build. Then change the function’s mandate, out loud, from preventing the bad to enabling the responsible. Governance is not the brake. It is the shaping cone, and it is where responsible speed is either made or lost.

Cheers,
-Titus

The next one

Get it in your inbox.

New Issues, FAQs, and Case Studies as they go out. Each one names something, explains something, or hands you something you can use on Monday. Subscribe, and I will send each as it goes out.

Prefer the tool you already think in? Here is how to read it in your chatbot.