Pillar 2 · Governance X. Design Week 2026

AI governance and strategy

How destinations are building trust as infrastructure

How do destinations move governance from a compliance burden to a strategic enabler?

The human top arrow_upwardbuilds up
visibility
03Disclosure
A culture of trust and transparency
Top

The organisation stands behind what AI produced and what got published. Disclosure carries the most human weight.

account_tree
02Process
How work moves and gets checked
Middle

AI sits in the loop. The checks happen here and someone signs off before the work ships.

shield
01Guardrails
Boundaries for where and how AI operates
Base

The approved tools and environments, and the data the systems are allowed to touch.

foundation
Trust
The foundation every layer rests on

Hover a layer to see what it holds. Each one rests on the layer below.

In this report
02The argument
03Aruba Tourism Authority
04Visit Skåne
05Strategic recommendations
06Re-enter the zones
The argument

From whether to how

Governance is heard as compliance

Within most destinations, AI governance is heard as compliance work. The Grant Thornton AI Impact Survey 2026 puts that framing under pressure, with 46% of organisations citing governance and compliance as the leading cause of AI underperformance, ahead of skills and training at 27% and data quality at 18%. The same governance that operates as the tallest barrier in one organisation operates as the biggest enabler in another. The destinations making progress are treating governance as the enabler.

Leading causes of AI underperformance
Governance and compliance 46%
Skills and training 27%
Data quality 18%

Grant Thornton, AI Impact Survey, 2026

The same number, two readings
block

Read as a problem, governance and compliance is the leading cause of AI underperformance. 46% name it as the thing holding AI back.

The shift in the question

Trust remains the fundamental requirement for effective disclosure. Leadership actively build this trust at the base of the organisation, while formal policy provides the top-down rules. Without this essential foundation the entire structure and framework can fail. The most meaningful shift involves changing the core question. Asking "Did you use AI?" merely produces a dead-end answer. Conversely, asking "How did you use AI?" opens the dialogue, driving the exact accountability, transparency and trust that successful governance requires.

Pick the question a manager asks
do_not_disturb_on

A dead end. The answer is yes or no and the conversation stops. Nothing surfaces about where, how or with what.

The conversation opens. Governance has something to work with, and three things surface.

Accountability Disclosure Trust

The shadow economy

Enforcing mandates without clear frameworks severely erodes trust. Two statistics highlight this consequence: 35% of professionals have entered proprietary data into public AI tools, while 67% of leaders suspect an internal leak has already occurred. Currently, most usage happens entirely out of sight, bypassing official approval and formal governance. Staff will continue using these tools whether guidelines exist or not. Implementing a proper framework simply determines whether an organisation can actively monitor and safely manage this inevitable activity.

The shadow economy

Hover the iceberg.

Above and below the waterline

Sanctioned use is the visible tip. Most AI use sits below it, in the shadow economy.

35%have put proprietary data into public AI tools
67%of leaders believe a leak has already happened

The anxiety underneath the data

Workforce anxiety regarding new technology takes two distinct forms within the same organisation. Deutsche Bank Research found that 24% of Gen Z workers fear direct displacement, viewing the technology as a potential replacement. Conversely, around 10% of Millennials and older professionals fear skill erosion, feeling like these systems are actively undermining their professional value. Standard governance frameworks impact these demographics entirely differently. Policies focused purely on operational risks completely ignore the critical human element, which remains exactly where internal trust is ultimately built or broken.

Governance works on three layers

Governance operates across three distinct layers. The foundational base consists of operational guardrails: the strict boundaries defining approved tools, secure environments and permitted data access. The middle layer focuses on process, detailing exactly how work flows through the team, where quality checks occur and who provides final approval. The top layer demands disclosure, embedding transparency and trust directly into the brand's core values while ensuring full organisational accountability for all published outputs. Ultimately, this commitment to clear disclosure carries the most significant weight.

The three layers
arrow_upwardBase builds to the top
03
DisclosureThe human top

A culture of trust and transparency, with the organisation accountable for what gets published.

02
ProcessThe middle

How work moves through the team with AI in the loop, where the checks happen and who signs off.

01
GuardrailsOperational base

The boundaries for where and how AI can operate, the approved tools and the data the systems can touch.

gavel EU AI Act · August 2026 · high-risk obligations

From principle to instrument

The governance framework is the instrument that takes the strategy and keeps it on purpose. Strategy decides what AI is for. The framework decides where AI may and may not go, how the work moves and gets checked and what gets recorded and shared. The result is AI work that stays on purpose and stays audit-ready.

DTTT has formalised this in the AI Transparency Framework, structured in two tiers. Tier 1 covers the models: Transparency, Productivity, Environmental and Content Integrity. Tier 2 covers the foundations: Maturity Model, Capability Model, Wellbeing Instrument. The framework gives destinations a working language for the governance work without forcing them to invent it from scratch.

AI Transparency Framework
DTTT · the models and the instruments beneath them
Tier 1 · Models
Transparency model
TM
Transparency
Productivity model
PM
Productivity
Environmental model
EM
Environmental
Content integrity model
CI
Content integrity
south Rests on
Tier 2 · Instruments
Maturity model
MM
Maturity Model
Capability model
CM
Capability Model
Wellbeing instrument
WI
Wellbeing Instrument
The foundation
Case study

Aruba Tourism Authority

Building a governance framework from scratch for a public tourism authority.

91%
of staff already using AI
3
parallel workstreams
Whole org
one framework across legal, IT, data protection and operations

Aruba Tourism Authority · governance framework in development

The Aruba Tourism Authority’s governance initiative began when the digital team recognised a stark gap between widespread AI adoption and actual oversight. An internal audit revealed the scale of the issue: 91% of staff were already using the technology in some capacity, operating almost entirely without formal guidelines. Bridging this divide became the central brief for the work that followed.

Why the work matters

A public tourism authority carries responsibility for visitor data, brand reputation and public accountability at the same time, with unmanaged AI use putting all three under pressure at once. The audit showed high everyday use and far lower sanctioned use. A governance framework is what closes that distance, giving the organisation one place where the rules for AI are decided, recorded and owned across legal, IT, data protection and operations.

Five principles guiding the work

The strategy defined five guiding principles. The framework is built against them and any decision about the framework's direction is tested against them.

01
Foundation before innovation

The underlying conditions for AI come before the experimental edge.

02
Internal first, external second

Build the governance discipline inside the organisation before extending it to external work.

03
Enable, do not restrict

The framework gives staff a structure to move inside, with rules supporting use.

04
Meet people where they are

Address the actual patterns of AI use across the team and the work the patterns reflect.

05
Progress over perfection

Ship the first version of the framework and improve it through application.

From confident to strategic

The work is structured against a five-level AI maturity model. The organisational target sits at level 3, "confident": the team uses AI day-to-day with consistent quality, recorded outputs and clear accountability. The governance committee shaping the framework's evolution sets its sights on level 5, "strategic": AI sits inside the organisation's operating model and the governance structure shapes how the strategic decisions get made. The gap between level 3 and level 5 defines the work the committee has in front of it.

AI maturity model · five levels
1
2
3
Confident
Organisational target
4
5
Strategic
Committee target

One project that became three

What started as a single governance project became three parallel workstreams. Each has its own timeline and its own ownership, with shared coordination across the top.

Workstream 01
Governance

The framework that decides where AI can be used, who decides and what gets recorded.

Workstream 02
AI governance

The tools, the data the AI is allowed to touch and the disclosure standards across the organisation.

Workstream 03
Data privacy

The protection of visitor and staff data as AI use scales.

Implementation in three phases

The work runs in three phases. The first phase is three months long and focuses on the foundations. This phase sits underneath everything else, covering the audit findings, the maturity baseline, the committee structure and the operating principles the framework is built against. The second and third phases extend the framework across the organisation, with the foundation phase setting the conditions for both.

Phase 1 · 3 months
Foundation

Audit findings, the maturity baseline, the committee structure and the operating principles the framework is built against.

Phase 2

The framework extends across the organisation.

· · ·
Phase 3

The framework continues across the organisation.

· · ·

The three-month foundation reflects the "foundation before innovation" principle directly. Without the underlying conditions in place, the later phases struggle to land and the maturity gains stay temporary.

Disclosure as a discipline

Disclosure became one of the load-bearing components of the framework. The system asks what was used, by whom, in what way and for what output, with the answers travelling into how the organisation publishes and represents the work. The discipline supports external reporting and gives the internal team a record of where AI is reliable and where it is producing inconsistent output that needs review.

What the framework is building toward

Building a governance framework across a public-facing tourism authority pulls in legal, IT, leadership and operational teams, with each group wanting different things from the same document. Aruba committed to the work upfront. The committee owns the framework's evolution. As the framework takes shape, the three workstreams give the organisation a working language for AI that holds trust, disclosure and audit alongside the experimentation.

Case study

Visit Skåne's approach to in-house guidelines

Starting with experimentation, building structure as use grows.

How the guideline grew
explore
Permission and trust
chevron_right
rule
Specialised rules
chevron_right
handshake
Vendor disclosure
chevron_right
terminal
Production tooling

Visit Skåne · guidelines built in-house

Visit Skåne's governance journey started from a different position than Aruba's. The team built guidelines in-house, leaning on permission and trust at the start, then tightening the structure as use spread across the organisation.

The initial guideline was deliberately light. Staff could experiment with AI on the condition that no sensitive information went in and the human controlled every output. The framing gave the team room to explore, with the safety net of explicit limits on what the AI was allowed to see and what it was allowed to publish.

Where the structure tightened

As more people started using AI, the guidelines specialised. Pictures and text needed separate rules, because the trust questions for each are different.

imagePictures

Questions about authenticity, where AI augmentation of a real photograph sits relative to a fully generated image.

edit_noteText

Questions about voice, brand consistency and whether the AI produces the destination's character or a generic version of it.

Training ran in tandem with the guidelines. The team focused on helping staff understand the core reasoning behind the rules, ensuring the policies remained effective even in unexpected scenarios. Ultimately, guidelines that exist purely on paper tend to fail the moment a situation becomes complex.

Vendor disclosure and the trust chain

Visit Skåne now writes into every public procurement document that suppliers must be transparent about how they have used AI. The value of that became clear when two suppliers responded to the same brief. One had pasted the procurement into an AI tool and returned the output. The other set out which parts of its work would use AI, how it would handle the information and how it would transform it. This detailed and structured response gave confidence and established trust, setting a strong basis for a working relationship.

The next direction

The team has started building personalised, vibe-coded applications for specific industry partners, extending this governance work directly into active production. Every new tool triggers the same fundamental questions: what data does it access, who controls the output and what is disclosed when the result reaches a visitor or stakeholder? What began as simple content guidelines is rapidly becoming the foundation for everything the destination delivers, balancing experimentation with clear trust, disclosure and oversight.

Strategic recommendations

Key Questions and Practical Answers

This section captures the primary concerns raised by DMOs throughout the afternoon alongside the strategic solutions agreed upon by the group, leading directly into six core recommendations.

01

How do we move governance from compliance to enabler?

Start with the strategic question before drafting policy. Successful destinations begin by defining the technology’s exact role within their organisation, then build guidelines to uphold that vision. With trust as the foundation, the three core layers (guardrails, process and disclosure) provide the necessary operational structure. Guidelines work best when written alongside the staff who must follow them. That shared ownership ensures the framework holds firm when things get complicated.

02

What does a working governance framework actually include?

expand_more

A working framework rests on guardrails at the operational base. These cover the approved tools, environments and data sources along with the boundaries for where and how AI can operate inside the team. The middle layer is process, covering how work moves with AI in the loop, where the checks happen, who signs off and what gets reviewed. The top layer is disclosure, covering what gets recorded when AI is involved, what gets shared internally and externally and what the brand stands behind. The three layers depend on each other for the framework to work. Guardrails on their own produce inconsistency in output. Adding process brings consistency without transparency. Adding disclosure completes the system by giving the work the visibility it needs to be trusted.

03

How do we deal with the shadow economy of AI use that already exists?

expand_more

Audit before policy. The 35% of professionals inputting proprietary data into public tools will keep doing so until approved alternatives are easier to access. Effective destinations audit first to map this activity, designing official workflows around how their teams actually work. Unofficial tool use drops the moment secure options offer the same speed and flexibility. Mandates without proper support simply push the behaviour out of sight.

04

How do we work with the EU AI Act?

expand_more

Treat August 2026 as the deadline the framework is built backwards from. The high-risk obligations apply from that date. The destinations who complete the three-layer work before then arrive ready, with a framework that already meets the requirements. The destinations who treat the act as compliance to handle after the deadline arrive without the time to build properly. The framework also has to address disclosure obligations across content, marketing and AI-driven interfaces, with documentation good enough to support an audit if one comes.

05

How do we hold vendors and partners to the same standard?

expand_more

Make disclosure a procurement requirement. The trust chain extends beyond the DMO's own staff to vendors and agencies producing content for the destination, with both expected to disclose AI use and document the work involved. The cleanest way to enforce this is to write it into the contracts and the tender process. A vendor who finds the disclosure intolerable is signalling something about their own AI use that the destination should know.

Recommendations to take into the second half of the year
01

Lead with the strategic question

Define what AI is for in your destination before writing the rules around it. A policy without a strategic frame produces compliance paperwork that does not change the work.

02

Audit before policy

Find out where AI is already being used in the team. Design the framework around what is happening, not around what the policy author wishes was happening.

03

Build the framework as a three-layer stack

Guardrails sit at the operational base, process sits in the middle and disclosure sits on top. Each layer depends on the one below it to work.

04

Treat disclosure as a discipline

Disclosure is what makes governance operate. A framework without disclosure carries no force. Build the recording habits into the workflow so disclosure becomes a byproduct of the work.

05

Make vendors part of the framework

The trust chain extends to anyone producing content for the destination. Disclosure should be a procurement standard, supported by a shared framework like the DTTT AI Transparency Framework.

06

Build backwards from August 2026

The EU AI Act's high-risk obligations apply from that date. The framework should be in place before, with the documentation good enough to support an audit.

lock

Log in to continue reading.

From the room lockMembers

Re-enter the zones from XDW 2026

Each zone approached the governance question from a distinct angle. The summaries below capture the key points from each session and their final agreed outcomes. The portal links open the immersive zone experiences built during the event.

science

The Lab

What happened

The Lab tried something harder than the morning session. Governance and strategy are difficult to make hands-on because the work happens through documents and conversations more than through tools. The session designed a stress-testing exercise around the DTTT AI Transparency Framework, with participants working through how policies hold up when applied to AI use cases the destinations had been navigating in their own work.

The discussion extended beyond the planned exercise. The "we are our own agency" debate surfaced around whether a destination producing its own AI-assisted content should be held to the same standards as a vendor producing AI-assisted content for it. The position reached was that the same disclosure obligations apply internally and externally, with the destination as accountable for its own AI-assisted work as it expects its partners to be for theirs.

Takeaway

Governance is difficult to make hands-on because the work lives in writing and signing off. The value of stress-testing a framework against operational cases is in exposing where the framework's gaps sit. The route forward is to take a handful of operational cases, apply the framework against them and document where the framework holds and where it breaks.

Explore The Labnorth_east
hub

The Strategy Room

What happened

The Strategy Room opened by assessing how far different organisations had progressed with their governance. Every destination present had some form of policy in place, though the actual depth varied significantly. Almost universally, the starting point was content. Rules governing written and visual output were consistently far more developed than broader internal frameworks.

The discussion then questioned whether formal governance is even necessary at this stage. The room agreed that the answer depends entirely on scale. Smaller destinations can operate safely with loose guidelines because informal accountability still works within a close team. Larger organisations require strict frameworks because that informal oversight naturally breaks down once staff numbers cross a certain threshold.

The second half of the session focused on disclosure. The group concluded that transparency must be a built-in process rather than an optional courtesy. Relying on staff to voluntarily declare their usage rarely works. The destinations succeeding at disclosure are the ones wiring it directly into their standard operations through supplier contracts, staff onboarding and daily workflows.

Takeaway

Most destinations have some form of AI policy in place, though the actual depth varies. Content guidelines consistently dominate the starting point. The leap from a static document to a working framework is what separates the destinations gaining real traction from those still in the early stages of adoption. Transparency follows the exact same rule. Disclosure that depends on personal discipline tends to slip, but the one embedded in process holds.

Explore The Strategy Roomnorth_east
forum

The Debating Room

What happened

The Debating Room quickly found that the topic resists a black-and-white debate, repeatedly shifting the conversation toward balance and compromise. The most valuable breakthrough centred on the role of the internal sceptic. The group agreed that sceptics belong in the room, though 'constructive challenger' is a more helpful title. This person exists to test the assumptions about AI before anything goes live. They point out missing guardrails, advocate for human oversight and catch the blind spots that enthusiasts naturally miss.

A second major discussion focused on the pace of adoption. The room concluded that moving too slowly carries its own significant risk. If leadership drags its feet, staff will simply test out new tools on their own, meaning the work happens entirely without protection. Ultimately, the group found consensus in 'measured adoption'. The safest route is moving forward steadily, but doing so within a defined structure.

Takeaway

The most productive governance requires finding the middle ground. It balances speed with structure and official policy with everyday practice. A working framework is simply the one that holds firm under those competing pressures.

Explore The Debating Roomnorth_east
support_agent

The Advisory Clinic

What happened

The Advisory Clinic worked through the EU AI Act and what it asks destinations to do. The position reached was that the act concerns disclosure structure, with the operative question being how the organisation discloses its AI use. Compliance starts with understanding the requirements clearly, then mapping them onto what each team actually does in its daily work.

Two patterns surfaced. The first was that a main framework needs to flex around how individual departments operate. Marketing, digital and operational teams produce different kinds of output with different risk profiles, with a single policy document tending to fail when the granular work does not match what the document anticipated. The working answer was to keep the framework as the strategic spine and develop a use case library or exceptions catalogue alongside it, giving the team something to reach for when the situation lies outside the main document.

The second pattern was about policy depth. Detailed policies work for new employees as part of onboarding. The same level of detail loses traction with existing employees who already carry working habits. The destinations who get traction develop a detailed policy for onboarding and a shorter operational summary for the existing team, with the longer document available as a reference for the cases that need it.

Takeaway

The EU AI Act asks for disclosure structure. The destinations who do this well treat the act as a deadline to build the disclosure architecture against, with a main framework that flexes around how each team actually works.

Explore The Advisory Clinicnorth_east
arrow_backBack to overview Continue to Discoverabilityarrow_forward
lock

Log in to continue reading.

chevron_right
01 · Overview
keyboard_arrow_leftArrow keys · swipe · tap a dotkeyboard_arrow_right
01 / 06