The AI Skills Got Democratized. The Duties Did Not.

Paul Drennan explains why almost anyone can now build with AI, why almost nobody was handed the duty to check it, and what that imbalance is already costing.

Executive brief

Unsupervised AI drifts every day, and without monitoring and repair it will eventually betray you

Renaming governance as safe enablement moves risk, legal, and audit from post hoc inspectors to co-authors at the start

Once the safety boundary is published, most use cases can clear approval automatically and scarce specialists get to work on genuine novelty

The hardest part of AI is convincing a person to rewrite their job description around a tool they cannot see inside

Subject matter expert validation is a scarce resource that has to be protected in workforce planning before it disappears

Episode conversation

Paul Drennan spent forty years turning data, analytics, and AI into real enterprise capability, most recently as a Chief AI and Analytics Officer. He sat down with Jeff Carson to explain why almost anyone can now build with AI, why almost nobody was handed the duty to check it, and what that imbalance is already costing.

Guest credentials

Paul Drennan — Most recently Chief AI and Analytics Officer. Four decades turning data, analytics, and AI into working enterprise capability across insurance, healthcare, and financial services. LinkedIn: https://www.linkedin.com/in/pauldrennan/

Jeff Carson — Founder, TheAIAudit. Two decades building and governing AI systems inside financial services, hospitality, and retail, including leading global data science teams. LinkedIn: https://www.linkedin.com/in/jeffery-carson/

Watch the episode

Almost anyone can build with AI now. The duties never spread with the skills.

A few years ago, building an AI system took a master’s degree in applied math or data science. The work sat with a small group of practitioners, and so did everything that travelled with it. Checking that the output was actually right. Watching it over time to make sure it still worked. Naming a human who owns it when something goes wrong.

Those barriers are gone. Someone in your finance team can write a prompt, stand up a chatbot, and launch a use case in an afternoon. Most people read that as pure progress.

Paul Drennan reads it differently. He spent forty years turning data, analytics, and AI into enterprise capability, most recently as a Chief AI and Analytics Officer, and before any of that he was a Navy officer running engineering aboard a destroyer, where nobody separates what you are capable of from what you owe.

His argument is that the skills got democratized and the duties stayed where they were. The obligations that used to come bundled with the experts never made the trip. That imbalance is already producing consequences, and most of the leaders living with it have not named it yet.

Why he stopped calling it AI governance and started calling it safe enablement

Drennan is careful to say governance itself is not the problem. It is critical, in this domain more than most. What went wrong is the reputation. Over time, governance acquired a negative sentiment. It became the thing that shows up late in the process and interrupts progress. So he changed the words, and then changed the sequence underneath them.

Governance makes people anxious, as he puts it. Everybody wants safe enablement. The substance behind the relabel is a shift left: the people whose duty is to protect the firm from legal consequence, reputational harm, and security breaches get brought in at the beginning and asked to co-author the system. If the system is followed, safety is a property of the build rather than a verdict delivered afterward.

His tagline for it: safety through design, not supervision.

Team Yes: turning risk, legal, and audit into co-authors instead of blockers

Drennan calls that group the guardians: audit, risk, legal, compliance, and often procurement, security, and architecture. Every one of them has a real obligation to protect the enterprise, and every one of them has learned, over years, that the safe answer is no.

When he formed his governing committee, he told them so directly. He knew they were all born on Team No. He was asking them to join him on Team Yes. The question simply changes direction. Instead of asking the guardians for approval, the builders ask them what they need in order to be able to say yes.

How publishing the safety boundary gets governance off the critical path

In the early days, every use case went in front of every guardian, because everything was novel and everything was first of its kind. That does not scale. The team watched for repetition: retrieval solutions, technical platforms, standard work, and requirements for trust maintenance, observability, monitoring, and repair began looking like patterns rather than one-off judgments.

They defined formally what safety looks like, named the things that would trigger anxiety, and published the boundary set for everyone to see. Most use cases turned out to sit inside the safe perimeter, and builders who could see the boundary started building to it deliberately. Once enough of the portfolio was flowing through the safe box, approval inside that box could be automated.

The AI literacy gap, and why humans are hallucinating too

Everyone worries about models hallucinating. Drennan’s more uncomfortable observation is that the humans deploying them are doing something similar. Pressure to get on board creates two responses: near paralysis, or a jump into the deep end without checking whether there is water in the pool.

His analogy is deliberately uncomfortable. We travelled up the river, found people hunting with bows and arrows, handed out machine guns, and told everyone that refusing to use one meant a bleak future. What we did not do was teach anyone how the machine gun works.

The hardest part of this work is not building the system. It is asking a person to rewrite their job description around a tool they cannot fully see inside while retaining full accountability for what happens next.

The asset owner: the AI role most companies do not have

Once Drennan accepted that the hardest part of the job was recruiting belief rather than building models, he created a role and called it the asset owner. Their entire mission is to close the gap between the people who build the system and the people who have to stake their work on it.

The instruction was to convert a leap of faith into a hop of faith: educate, expose, and make as much of the system transparent as it can be made. He sought a blend of sales engineer, strategy consultant, and product owner. The result became the fastest growing job family in his department.

Why AI pilots really fail

The failure explanation Drennan does not accept is that the technology was not ready. Some pilots fail because the context the system was built for evolved and nobody safeguarded that evolution. But most fail somewhere less technical: the user was asked to rewrite their job description around the tool, their anxiety was never addressed, and adoption quietly never happened.

AI drift is microscopic damage, and safe to own is the repair

Unsupervised AI will betray you, and it is only a question of when. The enemy is drift. Tomorrow will not look like the examples the model learned from. Climate, geopolitics, the price of oil, a new product launch, a changed route to market, and fresh sales incentives all move the world away from those examples.

Drennan thinks of it as microscopic damage, which means the response is repair. Performance monitoring alone will not find it. Millisecond response times can be perfect while answers quietly change. You have to watch what the same inputs produce over time and notice when the output is no longer what it used to be.

The phrase his teams used for the answer was safe to own. It does not just work on day one; it will be working for you three years from now because someone is vigilant on your behalf and does the work to keep it accurate.

What a Chief AI Officer is actually for

The role must navigate between two failure modes: a thousand points of light, where everyone does their own thing, and strict centralization, where one team builds and controls everything. The word Drennan uses is federated. Build a system that supports a distributed builder community while holding on to safe enablement, scalability, extensibility, and affordability.

The method he trusts is the first wrong answer. Deploy something workable, invite critique, expect revision, gain operational experience, and reapply what you learn. What does not work is sitting in a room, defining the answer, and arriving to promulgate it.

How do you audit generative and agentic AI

The deterministic methods of traditional machine learning operations do not transfer, because the same inputs no longer produce the same outputs. Drennan expects more deliberate context engineering, including ontologies and world models that narrow the space the system can operate in. That approach requires professional curation of the underlying knowledge base and protected subject matter expert capacity to validate output.

SME validation is a protected duty

Today’s workforce includes subject matter experts who learned their jobs without an AI in their pocket. They can look at an output and know it is wrong. Ten years out, many of those people will have retired or moved on, and their replacements may not be able to catch the same errors.

Subject matter expert validation has to be treated as a protected duty and planned for explicitly in workforce planning, staff development, job descriptions, and onboarding. You cannot hire your way out of it after the fact.

Proud ownership, and what boards should be asking for

Proud ownership is the summary result of designing safety in, building user confidence, and maintaining observability, monitoring, repair, and validation. The final exam is whether users adopted it and whether they are still using it a year later, and three years after that.

For boards, the starting position is acknowledgment: nobody has fully solved this, every organization sits somewhere different on the maturity curve, and the honest move is to keep it on the agenda as a standing priority rather than an incident response.

Carson closed on the line the hour was building toward. The skills got easy. The duties and responsibilities did not. And until every leader owns that gap, the losses keep coming.

About Paul Drennan

Paul Drennan spent four decades turning data, analytics, and AI into working enterprise capability, most recently as a Chief AI and Analytics Officer, with earlier work across insurance, healthcare, financial services, and consulting. He built the governance model he calls safe enablement, formed the cross-functional group he named Team Yes, and created the asset owner role to close the trust gap between AI builders and the people whose work depends on them.

He is a United States Naval Academy graduate who served as a Navy officer running engineering aboard a destroyer, holds a master’s degree from the Naval Postgraduate School, and is a named inventor on multiple issued patents. He now advises insurtech startups and internal enterprise teams on leadership, AI safety at scale, and practical solution building. Outside work, he is a blacksmith and leatherworker who builds the tools he uses.

About TheAIAudit

TheAIAudit is a patent-filed AI governance platform built on a time-tested financial framework, rebuilt to reflect the rapid adoption of AI by companies. It measures an organization’s AI Investments across Governance, Impact, and Risk Flow and returns an AI Health Score, a 0 to 100 number built on over a thousand source metrics. It answers the three questions a board asks: Is it under control? Is it paying off? And what could it cost us?

Know what your AI Investments return.

TheAIAudit measures your organization’s AI Investments across Governance, Impact, and Risk Flow, and returns a single score executives and boards can act on.

Questions answered in this episode

What is safe enablement in AI governance?

Safe enablement is Paul Drennan’s reframing of AI governance as a design property rather than a late-stage inspection. Instead of reviewing a system after it is built, the risk, legal, audit, compliance, and security functions are brought in at the start and asked to co-author the standards. His summary is safety through design, not supervision.

What is AI drift and why does it matter?

AI drift is the widening gap between the examples a model learned from and the world it now operates in. As the gap widens, the odds of a safe inference fall. Drennan describes it as microscopic damage that requires an ongoing monitoring and repair mechanism.

What is an AI asset owner?

The asset owner is a role Drennan created to close the gap between the people who build AI systems and the people who have to use them. The job is to educate, expose how the system works, and build enough transparency that a user will stake their work on it.

Why do AI pilots fail?

Rarely because the technology was not ready. Most fail because the user was asked to rewrite their job description around a tool they did not understand, nobody owned the job of addressing that anxiety, and adoption never happened.

What does a Chief AI Officer actually do?

The core duty is navigating between a fully distributed model where everyone builds their own thing and a strictly centralized model that protects quality by preventing participation. Drennan calls the middle path federated.

How do you audit generative and agentic AI?

Traditional deterministic methods do not transfer because the same inputs no longer produce the same outputs. Drennan expects deliberate context engineering, knowledge-base curation, and protected subject matter expert capacity to validate output.

Sources