AI governance and strategy
How destinations are building trust as infrastructure
How do destinations move governance from a compliance burden to a strategic enabler?
The organisation stands behind what AI produced and what got published. Disclosure carries the most human weight.
AI sits in the loop. The checks happen here and someone signs off before the work ships.
The approved tools and environments, and the data the systems are allowed to touch.
Hover a layer to see what it holds. Each one rests on the layer below.
From whether to how
Governance is heard as compliance
Within most destinations, AI governance is heard as compliance work. The Grant Thornton AI Impact Survey 2026 puts that framing under pressure, with 46% of organisations citing governance and compliance as the leading cause of AI underperformance, ahead of skills and training at 27% and data quality at 18%. The same governance that operates as the tallest barrier in one organisation operates as the biggest enabler in another. The destinations making progress are treating governance as the enabler.
Grant Thornton, AI Impact Survey, 2026
Read as a problem, governance and compliance is the leading cause of AI underperformance. 46% name it as the thing holding AI back.
The shift in the question
Trust remains the fundamental requirement for effective disclosure. Leadership actively build this trust at the base of the organisation, while formal policy provides the top-down rules. Without this essential foundation the entire structure and framework can fail. The most meaningful shift involves changing the core question. Asking "Did you use AI?" merely produces a dead-end answer. Conversely, asking "How did you use AI?" opens the dialogue, driving the exact accountability, transparency and trust that successful governance requires.
A dead end. The answer is yes or no and the conversation stops. Nothing surfaces about where, how or with what.
The conversation opens. Governance has something to work with, and three things surface.
The shadow economy
Enforcing mandates without clear frameworks severely erodes trust. Two statistics highlight this consequence: 35% of professionals have entered proprietary data into public AI tools, while 67% of leaders suspect an internal leak has already occurred. Currently, most usage happens entirely out of sight, bypassing official approval and formal governance. Staff will continue using these tools whether guidelines exist or not. Implementing a proper framework simply determines whether an organisation can actively monitor and safely manage this inevitable activity.
The anxiety underneath the data
Workforce anxiety regarding new technology takes two distinct forms within the same organisation. Deutsche Bank Research found that 24% of Gen Z workers fear direct displacement, viewing the technology as a potential replacement. Conversely, around 10% of Millennials and older professionals fear skill erosion, feeling like these systems are actively undermining their professional value. Standard governance frameworks impact these demographics entirely differently. Policies focused purely on operational risks completely ignore the critical human element, which remains exactly where internal trust is ultimately built or broken.
Governance works on three layers
Governance operates across three distinct layers. The foundational base consists of operational guardrails: the strict boundaries defining approved tools, secure environments and permitted data access. The middle layer focuses on process, detailing exactly how work flows through the team, where quality checks occur and who provides final approval. The top layer demands disclosure, embedding transparency and trust directly into the brand's core values while ensuring full organisational accountability for all published outputs. Ultimately, this commitment to clear disclosure carries the most significant weight.
A culture of trust and transparency, with the organisation accountable for what gets published.
How work moves through the team with AI in the loop, where the checks happen and who signs off.
The boundaries for where and how AI can operate, the approved tools and the data the systems can touch.
From principle to instrument
The governance framework is the instrument that takes the strategy and keeps it on purpose. Strategy decides what AI is for. The framework decides where AI may and may not go, how the work moves and gets checked and what gets recorded and shared. The result is AI work that stays on purpose and stays audit-ready.
DTTT has formalised this in the AI Transparency Framework, structured in two tiers. Tier 1 covers the models: Transparency, Productivity, Environmental and Content Integrity. Tier 2 covers the foundations: Maturity Model, Capability Model, Wellbeing Instrument. The framework gives destinations a working language for the governance work without forcing them to invent it from scratch.
Aruba Tourism Authority
Building a governance framework from scratch for a public tourism authority.
Aruba Tourism Authority · governance framework in development
The Aruba Tourism Authority’s governance initiative began when the digital team recognised a stark gap between widespread AI adoption and actual oversight. An internal audit revealed the scale of the issue: 91% of staff were already using the technology in some capacity, operating almost entirely without formal guidelines. Bridging this divide became the central brief for the work that followed.
Why the work matters
A public tourism authority carries responsibility for visitor data, brand reputation and public accountability at the same time, with unmanaged AI use putting all three under pressure at once. The audit showed high everyday use and far lower sanctioned use. A governance framework is what closes that distance, giving the organisation one place where the rules for AI are decided, recorded and owned across legal, IT, data protection and operations.
Five principles guiding the work
The strategy defined five guiding principles. The framework is built against them and any decision about the framework's direction is tested against them.
The underlying conditions for AI come before the experimental edge.
Build the governance discipline inside the organisation before extending it to external work.
The framework gives staff a structure to move inside, with rules supporting use.
Address the actual patterns of AI use across the team and the work the patterns reflect.
Ship the first version of the framework and improve it through application.
From confident to strategic
The work is structured against a five-level AI maturity model. The organisational target sits at level 3, "confident": the team uses AI day-to-day with consistent quality, recorded outputs and clear accountability. The governance committee shaping the framework's evolution sets its sights on level 5, "strategic": AI sits inside the organisation's operating model and the governance structure shapes how the strategic decisions get made. The gap between level 3 and level 5 defines the work the committee has in front of it.
One project that became three
What started as a single governance project became three parallel workstreams. Each has its own timeline and its own ownership, with shared coordination across the top.
The framework that decides where AI can be used, who decides and what gets recorded.
The tools, the data the AI is allowed to touch and the disclosure standards across the organisation.
The protection of visitor and staff data as AI use scales.
Implementation in three phases
The work runs in three phases. The first phase is three months long and focuses on the foundations. This phase sits underneath everything else, covering the audit findings, the maturity baseline, the committee structure and the operating principles the framework is built against. The second and third phases extend the framework across the organisation, with the foundation phase setting the conditions for both.
Audit findings, the maturity baseline, the committee structure and the operating principles the framework is built against.
The framework extends across the organisation.
· · ·The framework continues across the organisation.
· · ·The three-month foundation reflects the "foundation before innovation" principle directly. Without the underlying conditions in place, the later phases struggle to land and the maturity gains stay temporary.
Disclosure as a discipline
Disclosure became one of the load-bearing components of the framework. The system asks what was used, by whom, in what way and for what output, with the answers travelling into how the organisation publishes and represents the work. The discipline supports external reporting and gives the internal team a record of where AI is reliable and where it is producing inconsistent output that needs review.
What the framework is building toward
Building a governance framework across a public-facing tourism authority pulls in legal, IT, leadership and operational teams, with each group wanting different things from the same document. Aruba committed to the work upfront. The committee owns the framework's evolution. As the framework takes shape, the three workstreams give the organisation a working language for AI that holds trust, disclosure and audit alongside the experimentation.
Visit Skåne's approach to in-house guidelines
Starting with experimentation, building structure as use grows.
Visit Skåne · guidelines built in-house
Visit Skåne's governance journey started from a different position than Aruba's. The team built guidelines in-house, leaning on permission and trust at the start, then tightening the structure as use spread across the organisation.
The initial guideline was deliberately light. Staff could experiment with AI on the condition that no sensitive information went in and the human controlled every output. The framing gave the team room to explore, with the safety net of explicit limits on what the AI was allowed to see and what it was allowed to publish.
Where the structure tightened
As more people started using AI, the guidelines specialised. Pictures and text needed separate rules, because the trust questions for each are different.
Questions about authenticity, where AI augmentation of a real photograph sits relative to a fully generated image.
Questions about voice, brand consistency and whether the AI produces the destination's character or a generic version of it.
Training ran in tandem with the guidelines. The team focused on helping staff understand the core reasoning behind the rules, ensuring the policies remained effective even in unexpected scenarios. Ultimately, guidelines that exist purely on paper tend to fail the moment a situation becomes complex.
Vendor disclosure and the trust chain
Visit Skåne now writes into every public procurement document that suppliers must be transparent about how they have used AI. The value of that became clear when two suppliers responded to the same brief. One had pasted the procurement into an AI tool and returned the output. The other set out which parts of its work would use AI, how it would handle the information and how it would transform it. This detailed and structured response gave confidence and established trust, setting a strong basis for a working relationship.
The next direction
The team has started building personalised, vibe-coded applications for specific industry partners, extending this governance work directly into active production. Every new tool triggers the same fundamental questions: what data does it access, who controls the output and what is disclosed when the result reaches a visitor or stakeholder? What began as simple content guidelines is rapidly becoming the foundation for everything the destination delivers, balancing experimentation with clear trust, disclosure and oversight.
Key Questions and Practical Answers
This section captures the primary concerns raised by DMOs throughout the afternoon alongside the strategic solutions agreed upon by the group, leading directly into six core recommendations.
How do we move governance from compliance to enabler?
Start with the strategic question before drafting policy. Successful destinations begin by defining the technology’s exact role within their organisation, then build guidelines to uphold that vision. With trust as the foundation, the three core layers (guardrails, process and disclosure) provide the necessary operational structure. Guidelines work best when written alongside the staff who must follow them. That shared ownership ensures the framework holds firm when things get complicated.
Re-enter the zones from XDW 2026
Each zone approached the governance question from a distinct angle. The summaries below capture the key points from each session and their final agreed outcomes. The portal links open the immersive zone experiences built during the event.
The Lab
The Lab tried something harder than the morning session. Governance and strategy are difficult to make hands-on because the work happens through documents and conversations more than through tools. The session designed a stress-testing exercise around the DTTT AI Transparency Framework, with participants working through how policies hold up when applied to AI use cases the destinations had been navigating in their own work.