If your AI risk process lives somewhere separate from the work, it will lose to the work. That is the practical lesson from this week’s OpenAI reporting. The public argument is over whether the company disbanded its preparedness team. The business lesson is simpler: as AI moves into daily operations, risk cannot be a room down the hall. It has to sit inside the workflow where decisions are made, tools are chosen, and people actually use the system.

The Verge reported on August 18 that, according to the Financial Times, OpenAI had disbanded its preparedness team at the end of July. That team assessed whether models posed serious risks and worked on ways to reduce them. OpenAI disputed the report, telling The Verge, “We have not disbanded the Preparedness team,” and said research leaders across cybersecurity, biological and chemical risk, and AI self-improvement now report to its head of safety, Saachi Jain.

Fine. Take OpenAI’s denial seriously. The structure still matters.

The org chart is the control system

Business leaders tend to treat AI risk as a policy question. Write the acceptable-use policy. Create a review group. Ask legal to weigh in. Maybe assign an executive sponsor. Then everyone returns to buying tools, automating tasks, and asking teams to “find efficiencies.”

That structure fails because AI adoption does not wait for governance meetings.

Gallup reported in July that 52% of US employees now use AI at work at least a few times a year, up from 27% two years earlier. It also reported that employees saying their employer has integrated AI tools into daily work rose from 41% in the first quarter of 2026 to 47% in the second quarter. That means the operating reality is moving faster than most companies’ control systems.

The same pattern is visible at the platform level. The Verge reported on August 11 that ChatGPT hit 1 billion weekly users in July, while Google said Gemini reached 1 billion monthly users. These are not lab toys anymore. They are becoming default work surfaces.

When a tool becomes default, a separate risk function becomes too slow by design.

The question is not whether you have AI governance

Most companies can produce an AI governance document if asked. That is not the same as having AI governance that works.

The real test is operational:

When someone adds an AI tool to a workflow, who reviews what changes?

When an employee uses customer data in a prompt, who knows?

When an AI output becomes part of a financial model, sales recommendation, legal summary, customer email, or hiring screen, what catches the failure?

If the answer is “the AI committee,” the answer is probably no one.

Committees are not bad. Policies are not bad. But they are not where work happens. Work happens in the sales process, the support queue, the analyst spreadsheet, the marketing calendar, the claims review, the recruiting screen, the executive assistant’s inbox. That is where AI creates value. That is also where AI creates risk.

Risk work has to follow the work there.

Centralize standards, distribute ownership

The mistake is choosing between a centralized AI risk team and total decentralization. Both break.

A fully centralized team becomes a bottleneck. People route around it because they have targets to hit and customers to serve. A fully decentralized approach becomes shadow AI with nicer language. Every team invents its own rules, and leadership discovers the problem only after something leaks, breaks, or quietly produces bad decisions for three months.

The better pattern is centralized standards with distributed ownership.

One group should define the non-negotiables: what data cannot be used, which tools are approved, what needs a human review, what records must be kept, what use cases are off limits, and what escalation looks like when something feels wrong.

But every operating team needs a named owner for AI use inside its own workflow. Not a mascot. Not “the person who likes ChatGPT.” An accountable person who understands the process, knows where AI touches it, and can explain the risk controls without sending everyone to a PDF.

That person does not need to be an engineer. In most companies, they should not be. They need enough AI literacy to know what can go wrong and enough operational authority to change how the team works.

What to do this week

Pick one workflow where AI is already being used. Not the future roadmap. Not the vendor demo. The real one.

Map it in plain language. Where does information enter? Where does AI touch it? Where does the output go? Who relies on it? What happens if it is wrong? Who checks it before it affects a customer, employee, financial decision, or public claim?

Then assign ownership at the workflow level.

This is not bureaucracy. It is the minimum structure required for AI adoption to keep moving without becoming a mess. The companies that get this right will not be the ones with the thickest governance binders. They will be the ones where risk checks are part of how work moves.

OpenAI can argue about what happened to its preparedness team because OpenAI is operating at the frontier. Most businesses are not. But the organizational lesson transfers cleanly: the faster AI becomes part of normal work, the less useful it is to manage AI risk as a separate function.

AI risk does not fail because no one wrote a policy. It fails because the policy lived outside the workflow.