Governing AI We Can Trust: I Graduated!
CMU’s CDAIO Executive Program gave me a clearer understanding of how leaders can govern data and artificial intelligence responsibly while building systems people can trust.
Seven months and hundreds of hours culminated in my graduation from Carnegie Mellon University’s Chief Data and AI Officer Executive Program. The certificate marks an important professional milestone, but its greater value lies in how the experience changed my understanding of AI and executive leadership.
Artificial intelligence is no longer a specialized capability that organizations can assign to a laboratory, analytics team, or software vendor. It has become an enterprise concern involving governance, risk, strategy, culture, investment, and institutional trust. Leaders must now decide not only what AI can do, but also what it should do, who may authorize its use, and how the organization will remain accountable for its consequences.
Completing the program required sustained work from January through July 2026 alongside my full time responsibilities as Chief Data Officer at St. John’s College. The demanding schedule formed part of the experience’s value. Every assignment, discussion, and team deliverable pushed us beyond abstract enthusiasm for AI and required us to confront the practical responsibilities that accompany adoption.
Elmer Yglesias celebrates his graduation from Carnegie Mellon University’s Chief Data and AI Officer Executive Program at Heinz College, July 2026.
The Emerging Role of a Chief Data and AI Officer
Organizations once treated data management, analytics, cybersecurity, privacy, artificial intelligence, and institutional strategy as related but largely separate disciplines. AI has drawn them into a common operating environment. A model cannot produce reliable value without dependable data, and an automated system cannot earn trust without security, privacy, documentation, oversight, and accountability. Even an impressive technical application will struggle when it lacks a clear institutional purpose.
The Chief Data and AI Officer has emerged from that convergence. The role does not replace the chief information officer, chief technology officer, chief risk officer, general counsel, privacy officer, or cybersecurity leader. Instead, the CDAIO connects their work and helps translate technical possibility into institutional capability. Effective leadership ties innovation to mission, authority, measurable value, and organizational responsibility.
Organizations rarely fail from a complete absence of expertise. More often, they fail because expertise remains divided. Engineers understand how a system operates, legal counsel understands regulatory exposure, risk officers identify potential harms, business leaders define desired outcomes, data leaders understand the underlying information, and senior executives control resources and institutional authority. Successful adoption depends on bringing those perspectives together before deployment, not after a problem appears.
Carnegie Mellon’s program therefore felt less like conventional technical training and more like executive formation. Technical fluency remained essential, but the central questions concerned judgment. Which problems deserve attention? What data should support a decision? Who possesses the authority to approve a system? How should an organization measure value? What evidence must remain available for auditors, regulators, employees, students, customers, and governing boards?
Executive education creates lasting value when participants can translate frameworks into operating practice. The program consistently connected strategy, governance, leadership, organizational change, and technical capability as parts of one executive responsibility.
The capstone practicum brought those elements together. Our multidisciplinary team developed an enterprise governance framework for agentic AI, translating broad principles such as accountability, transparency, safety, and human oversight into controls that an organization could apply to consequential decisions.
Governance principles sound persuasive in a policy statement. They become more difficult when an organization must determine who may approve an action, what evidence supports the approval, which permissions an AI agent may receive, how exceptions should be handled, and who has the authority to interrupt the system. The practicum strengthened my conviction that governance cannot arrive after implementation. Responsible governance must develop alongside innovation and shape the system from its earliest design decisions.
Governing AI That Can Act
Agentic AI changes the governance equation because the system may do more than generate an answer. Traditional analytics informs a decision, while generative AI produces content or recommendations. Agentic AI can plan, select tools, retrieve information, initiate workflows, communicate with other systems, and perform actions in pursuit of a goal.
The distance between recommendation and action represents a significant transfer of operational authority. A system that summarizes information presents one level of risk. A system that initiates a transaction, modifies a record, communicates externally, or transfers information between platforms presents another. Systems capable of action require permission structures, approval checkpoints, escalation paths, limits, provenance records, continuous monitoring, audit trails, and clearly defined human authority.
Meaningful human oversight must involve genuine decision making power. An approval screen that encourages users to accept an action without adequate information does not provide responsible supervision. Effective human control requires understandable evidence, sufficient time, appropriate expertise, and the authority to reject, interrupt, or reverse an action.
Governance therefore becomes an operating discipline rather than a collection of isolated policies. Strong governance does not obstruct innovation. It creates the conditions that allow innovation to scale responsibly. An organization may tolerate informal experimentation when a few employees use a limited tool, but informality becomes dangerous when AI enters financial transactions, student records, personnel decisions, customer communications, regulatory reporting, academic processes, or other consequential activities.
Scale requires consistency, and consistency requires standards, ownership, evidence, and controls. Trust consequently carries direct economic and institutional value. Employees will not embrace systems they regard as unreliable, executives will not authorize expansion when risks remain poorly understood, and governing boards will not approve major investments without evidence of accountability. Customers and students will also resist systems that obscure how their information is used, while regulators will scrutinize organizations that cannot reconstruct decisions or identify responsible parties.
Trust determines whether an organization can move beyond experimentation.
Higher education provides an especially important setting for these questions. Colleges and universities hold sensitive student, employee, financial, academic, research, and donor information. They also operate through established traditions of shared governance, professional judgment, academic freedom, and public responsibility.
Artificial intelligence can help institutions analyze enrollment, identify students who may need support, improve administrative services, strengthen institutional research, support financial planning, accelerate routine work, and make information more accessible. Every opportunity carries a corresponding responsibility.
A student success model may help an adviser intervene earlier, but the institution must understand its data, assumptions, error patterns, and possible effects on different student populations. An admissions assistant may improve communication, but it must not disclose protected information or make unauthorized commitments. An agent that prepares regulatory reports may reduce manual effort, but the institution remains accountable for every submission.
Colleges cannot outsource institutional responsibility to a model or vendor.
Higher education leaders must align AI adoption with mission, values, privacy, security, academic integrity, and public trust. The CDAIO can help create that alignment by connecting enterprise data foundations with AI strategy and bringing together academic leadership, administration, information technology, legal counsel, cybersecurity, institutional research, finance, and governance bodies.
The best AI strategy does not begin with a tool. It begins with a mission, decision, or institutional problem. A tool centered approach asks where an organization can use a model. A mission centered approach asks what outcome must improve, what information supports the decision, and what combination of people, processes, data, and technology can improve it responsibly. That distinction protects organizations from expensive demonstrations that never become durable capabilities.
Our practicum applied a senior leadership sequence built around scalability, value, and investment. Leaders must first determine whether a framework can extend across use cases, departments, platforms, and operating environments. A governance process designed for one demonstration will not support an enterprise.
The next step requires demonstrating value. Strong data and AI leadership should improve decisions, reduce avoidable risk, increase operational capacity, strengthen services, or produce another measurable institutional benefit. Investment should follow once leaders establish a credible path toward scale and value. Funding becomes easier to justify when the organization can explain how it will govern the capability, measure the outcome, and manage the risk.
That sequence offers a corrective to two common extremes. One spends heavily because AI appears inevitable, while the other avoids action because uncertainty appears overwhelming. Responsible leadership creates a disciplined middle course by encouraging organizations to experiment carefully, establish authority, measure results, preserve evidence, and expand what works.
Completing Carnegie Mellon’s Chief Data and AI Officer Executive Program strengthened my conviction that the future of artificial intelligence will depend as much on leadership and governance as on innovation. Models will continue to improve, agents will gain access to more tools and information, and vendors will introduce platforms faster than most organizations can evaluate them. Competitive and institutional pressures will continue to encourage rapid adoption.
Enduring advantage will not come from possessing the newest tool for a few months. It will come from building the leadership, data foundations, operating disciplines, and institutional judgment required to use changing tools well.
The Chief Data and AI Officer occupies an important place in that work by connecting capability with purpose, experimentation with accountability, and investment with value. Technology creates capability, leadership provides direction, and governance creates trust. Organizations that combine all three will be best prepared to realize the promise of artificial intelligence responsibly and at scale.
Further Reading
- Carnegie Mellon University, Chief Data and AI Officer Certificate Program
- EDUCAUSE: The Impact of AI on Work in Higher Education
- IBM: The rise and ROI of the Chief AI Officer
- NIST AI Risk Management Framework