Governance sounds about as sexy as a three-hour agenda item with a procedural motion attached. Until it is missing. Or until it technically exists somewhere, but nobody can say where decisions are actually being made.
Estimated reading time: 4 min

After print, media production, content systems, and TYPO3, you might have expected the next big question to be technical again. Better systems. Cleaner processes. Fewer mistakes ending up stacked on pallets in a warehouse. More control over information before it causes damage.
At some point, though, you realize that technology is only the visible surface. Underneath sits the real question. Who gets to decide? Who gets access? Who can block things? Who carries responsibility? Who appears in the official org chart, and who actually has influence?
That is governance. Unfortunately, it is much more interesting than the name suggests.
You run into this quickly in open source. Many projects talk about openness, participation, and community. Often that is true. Certainly in their self-image. Sometimes in practice. But between self-image and lived experience there is often a corridor with many doors. Some are open. Some are ajar. Some have no sign. And in front of others stands someone politely explaining that this is simply how people have always gone through.
TYPO3 long saw itself as a bazaar. Open, community-driven, many people, many contributions, lots of movement. To some outsiders, though, it still felt more like a cathedral. Not necessarily out of bad intent. More because of history, responsibility, quality assurance, trust, and networks that had grown over time.
That is exactly why structures like these are so persistent. They rarely look completely absurd. Most of them started out as pragmatic solutions. And at some point later, nobody notices that pragmatism has turned into an access system.
Politics does not look all that different. There are statutes, rules of procedure, motions, votes, and people who can use the word transparency without visibly being in pain.
At the same time, you learn fairly quickly that the official process is only one map. The other map is not posted anywhere. It contains the conversations beforehand, the phone calls afterwards, old loyalties, personal reputation, unspoken conflicts, and the question of who has known whom for years.
The sentence “that’s just how politics works” is not an explanation. It is an admission that the real operating system runs somewhere else. That does not automatically make it dirty. Many informal paths emerge because people want to work pragmatically. They trust people they know. They avoid loops. They sort things out in advance. That can actually work quite well.
Until new people arrive.
Then pragmatism turns into an access barrier. Trust turns into a closed circle. Experience turns into authority over interpretation. Participation turns into scenery. And that is where governance becomes serious.
Good governance does not mean everyone gets a say on everything until the last productive person resigns internally. Good governance makes visible how decisions are made, who is responsible for what, where people can enter the process, and how dissent is possible. It defines how conflicts are resolved without leaving only those who know the unofficial city map by heart.
That sounds dry, but it is not. It determines whether a system can absorb new energy or merely administer its own past.
Still, another attitude is part of my story.
Do not ask for permission forever. Do not wait until someone has built the perfect process. Do not keep circling an idea until it collapses from boredom.
That attitude worked in open source. In politics too, at least up to the point where responsibility became greater than the personal urge to push something through. Being underestimated sometimes has advantages. You can try things before others notice that you are already on your way.
And when someone thinks something cannot be done, that often describes their limits first. Not necessarily the limits of the thing itself. But that attitude has a downside.
People can play “just do it” because they can carry responsibility. They can face objections, fail, improve things, explain themselves, or deal with the consequences. With AI systems, the same attitude becomes dangerous.
A system working with organizational knowledge must not simply run because it sounds convincing at the moment. If an agent reads documents, interprets roles, prepares decisions, drafts emails, or triggers processes, “looks smart” is no longer enough as quality control.
Then it has to be clear: what information may the system use? In what context? For which role? With what level of traceability, and under whose responsibility? These are not peripheral technical questions. This is governance.
AI rarely encounters neatly organized ideal worlds inside companies. It encounters inherited permissions, old file stores, implicit knowledge, political sensitivities, forgotten Excel files, and people who use “we’ve always done it this way” as an explanation, a warning, or a threat depending on the day.
Anyone who wants to use AI meaningfully in that environment has to understand more than models, prompts, and APIs. They have to understand how organizations actually work. Where formal rules end. Where informal power begins. Where trust carries weight. And where it is merely claimed.
That is why governance is not a topic for petty committee bureaucrats. It determines whether people can be effective within a system, and increasingly it will also determine whether machines are allowed to act within that system at all.
Good systems need both: people with enough room to make things happen, and machines with clear boundaries when they access knowledge, roles, and commitments. Everything else is either paralysis with rules of procedure or reckless action with admin rights.
We have had both before.
Governance does not only determine who is officially responsible. It determines who actually has access, influence, and responsibility. In open source and politics, informal paths always emerge alongside formal structures. They can be pragmatic, but they can quickly turn into invisible barriers to entry. With AI, this becomes even more important. People need room to act. Machines need clear boundaries once they start accessing knowledge, roles, and decisions.
© Copyright 2026 Cybercraft GmbH