Today, a national-scale public institution governs every artificial intelligence system it purchases through one federated operating model: standards and stop authority held at the center, execution and accountability held locally, and a single national register of AI use cases that procurement cannot bypass. Vendor obligations are written into contracts before signature, not negotiated after failure.
It nearly went another way. Dozens of procured AI tools had spread across agencies with no shared inventory. Each agency governed alone, or not at all. Vendors answered to nobody in particular, and no one could say, on any given day, how many AI systems were acting on citizens' data.
The institution builds almost nothing itself. Its entire AI estate is bought, not built, which is the reality of most public administrations. The governance frontier was never the data science team. It was the purchasing process.