The AI Didn’t Embarrass You. Your Governance Did.
David Moskowitz – Founder Member and Chief Content Architect, at the DVMS Institute
For decades, I’ve maintained that every technology problem is, at its core, a people problem. A recent incident made the case better than I could have argued it myself.[1]
A polished map appeared on a conference screen, showing where an organization planned to direct funding and build partnerships. Every country highlighted was in the wrong place. The slide carried all the visual markers of authority: borders, labels, numbers, and a professional layout. It was also fiction. Labels didn’t match borders. Regions had shifted. At first glance, the visual meant to signal competence read like carelessness.
Within hours, people were sharing pictures of the screen. The explanation arrived quickly: the image had been generated using AI.
That explanation is comfortable. It’s also the same incomplete explanation I suggested in another post, namely that the commentators misidentified the real issue regarding the OpenAI test agent “went rogue” after it broke out of a sandbox and accessed systems at Hugging Face.[2] Calling either incident an AI failure describes what produced the result. It says nothing about what let the result reach an audience before anyone checked it.
The two incidents look nothing alike. One is a security boundary. The other is a slide deck. But they share the discipline that failed. An automated system did what it was instructed to do. Nobody had decided, in advance, who was accountable for stopping it before it acted, or was shown in public.
Strategy and risk usually live in different rooms. Strategy focuses on outcomes and speed: the slide has to be ready by morning, the prototype has to be demoed next week, and the memo has to go out by the close of business. Risk sits elsewhere, treating verification as a downstream check. As long as nothing visibly breaks, the separation stays out of sight and out of mind.
Generative and agentic AI erase that separation, whether an organization is ready or not. Once an AI tool can produce something that shapes perception, or act on a live system, every use of it is a concurrent strategy and risk decision. Treating those decisions as separate is how a slide reaches a global stage unverified. It’s also how a test agent finds a sandbox boundary that nobody had modeled as something it might attack.[3]
The DVMS Institute frames the discipline that closes that separation as a single governing construct: strategy-risk. Every decision to use AI commits an organization to an outcome and to weighing the risks, both plus and minus, that come with its pursuit. Under strategy-risk, verification isn’t a step that follows creation. It’s part of the decision process, meaning that every decision becomes strategy-risk informed.
I’ve argued before that nearly every AI-shaped action needs to remain a proposal until an accountable human disposes of it.[4] The map is a clean example of what happens when that discipline isn’t followed. The generated image should have been treated as a proposal. It became an organizational statement the moment it reached the public screen. Nobody in between was responsible for checking it against a real map before anyone treated it as final.
That’s not a claim about intent. Nobody who built that slide wanted it wrong. The failure lies earlier in the process: no one owned the task of preventing an unverified proposal from becoming an act. This is exactly what Deming[5] and Crosby[6] argue in their respective books: quality comes from prevention, not detection, which is the responsibility of management.
Why does that job go unowned so often? I’ve argued elsewhere that the answer is cultural before it’s technical: disclosure feels riskier than the workaround, so people quietly skip verification rather than decline it on the record.[7] Detection tools can find an AI-generated file after the fact. They can’t tell you whether anyone felt safe enough to say “I’m not sure this is right” before it went live.
The map was wrong before it reached the screen. At that point, it was only an error. What made it official, in front of a global audience, wasn’t the model. It was the absence of anyone whose job it was to stop it.
Technology didn’t embarrass anyone. The missing decision did.
[1] The idea for this piece is based on Reuters reporting on a 2026 incident in which an AI-generated map presented at a global conference mislabeled every country it highlighted. Reuters reported that the image carried a watermark associated with OpenAI tools. https://www.reuters.com/world/africa/us-government-map-africa-mislabels-every-country-global-conference-2026-07-30/
[2] David Moskowitz, “The Agent Didn’t Go Rogue. The Governance Around It Did.,” DVMS Institute, 2026.
[5] Deming, W. Edwards, Out of the Crisis, MIT, Center for Advanced Educational Services, Cambridge, MA, 1986
[6] Crosby, Philip B., Quailty is Free: The art of making quality certain. New York, NY, McGraw-Hill, 1979
[7] David Moskowitz, “Shadow AI Is a Cultural Debt, Not a Technical Vulnerability,” DVMS Institute, 2026.
About the Author

David Moskowitz – Founding Member and Chief Content Architect, at the DVMS Institute
David is a Founding Member and Executive Director of the DVMS Institute LLC. He is the lead author of the “Digital Value Management System®” publication series which include the *Fundamentals of Adopting the NIST Cybersecurity Framework* and *A Practitioner’s Guide to Adapting the NIST Cybersecurity Framework*, and Thriving on the Edge of Chaos published by TSO
Digital Value Management System® is a registered trademark of the DVMS Institute LLC.
® DVMS Institute 2026 All Rights Reserved


