Lynqra Blog
AI Governance & Safety

Govern the AI you already use. Then keep it current.

Gartner published a piece on how large organisations should build a responsible AI programme. Ethics, governance, and compliance sitting together, not in three different folders.

We read it as operators, not as people collecting frameworks. The useful line is Sicular's: govern the AI you currently use. Not every hypothetical risk. The tool already in the tab.

We agree with that. We also think it is incomplete on its own.

Governance without growth is a policy PDF nobody opens. Growth without governance is staff pasting client files into ChatGPT because it is faster. Lynqra exists in the uncomfortable middle. Proper governance, and growth with AI. Not irresponsible adoption dressed up as transformation.

What we took from Gartner

Sicular wrote that fewer than a quarter of IT leaders are very confident their organisations can manage governance when they roll out GenAI. Most Singapore SMEs I talk to do not have an IT leader. They have an ops person, a shared Drive, and a browser tab.

Her practical steps still travel. Govern current use cases, not a catalogue of imaginary failures. Extend the controls you already have (who can see a file, who can approve a payment) instead of inventing a parallel "AI department". Get someone legal-minded in before private data leaves the tenancy. Watch the live system, not only the demo.

She also argues for adaptive ethics: handle cases as they come, because AI answers vary and can behave randomly. That is not consultant-speak once you have seen the same prompt extract an invoice cleanly on Monday and invent a total on Tuesday.

Where we part with the large-company version is the machinery. You do not need an agentic-AI working group or a hexagon of decision rights. You need named owners and a partner who will still be there when the model changes.

Our stance

We would rather be a tech partner than a vendor.

A vendor sells a build. The project closes. Six months later a better model ships, or a new approach makes the old stack look slow, and you are stuck running what you bought. That is irresponsible in a different direction: you locked the company to a moment in time.

A partner stays with the company. We keep iterating on the live workflow. If a new model is released, we ascertain whether it is actually better for that process, then we upgrade. If a new method makes our old work deficient, we overhaul it. We do not protect last year's build because it was already invoiced.

That is also how governance stays real. Rules written at go-live rot the moment the tool underneath them changes. If we are still in the room, the rules can move with the stack. If we have left, you have a PDF and a login nobody trusts.

The human gate does not move. A person still signs off payments, hiring, and customer commitments. The tool does the copying and checking. The judgement stays with the person who already owns the pile.

What this looks like in a smaller firm

The failure I keep seeing is not a biased model in a lab. Someone on ops pastes a supplier invoice or a candidate CV into ChatGPT because retyping is painful. Nobody wrote down whether that is allowed. The week they are out, the work stops, or the next person does the same thing with even less context.

If that output then pays a supplier or rejects a candidate, and nobody can name who was supposed to check it, you do not have a "responsible AI" gap. You have an ownership gap with a chatbot in the middle.

PDPA does not care that it was "just a draft". If client or staff personal data left your tenancy into a public model, that is your problem.

So before you buy anything, including from us, name two things in a meeting you already run.

Who can put company data into an AI tool, and what counts as company data. Invoices and CVs are. A public brochure is not.

Who signs off when the output moves money or a person. If the answer is "the model", that is not an answer.

Write it in a Google Doc if that is where the other rules live. Then pick a partner who will still be around to change it when the stack changes.

What we will not do

We will not drop a chatbot on a live process and call it adoption.

We will not write you a 40-page ethics charter so the real decisions can stay unnamed.

We will not treat a finished build as finished forever. The work is the workflow, and the workflow has to keep up.

Gartner can keep its 2027 and 2030 predictions. A ten-person trading firm needs to know, this Friday, what staff may paste into a tool, who signs the exception, and who will upgrade the thing when a better option shows up.

That last part is us, if you want it to be.

Bring one live workflow. Invoices, CVs, claims, approvals. We will say what is safe to automate, where a human stays, and how we will keep the build current after it is live.

Book a free consult

Source: Svetlana Sicular, How to Build a Responsible AI Program in a Large Organization, Gartner, 30 June 2026.