by Emanuela Giangregorio
Artificial intelligence is already being used extensively in project environments. Project teams are using generative AI tools to create documents, analyse information, develop plans, summarise meetings and support decision-making. AI assistance is also increasingly embedded within the project management software organisations already use.
The governance of that AI use, however, is lagging behind.
The first Pulse of AI Governance in Projects report, published in Spring 2026, found a median AI governance maturity score of 2.43 on a five-level scale. More significantly, 77% of respondents had not yet reached a standardised approach to governing AI in projects.
That creates an important question for Project Management Offices:
Who should make sure AI is being used appropriately across the project portfolio?
The answer is increasingly likely to be the PMO.
Not because the PMO should own AI policy, AI regulation or enterprise AI strategy. Those remain organisational responsibilities.
The case for the PMO is different. AI governance in projects is fundamentally about applying organisational expectations consistently within project delivery.
And that is territory the PMO already understands.
The AI governance gap in projects
AI has entered project delivery through several routes.
Project teams are using tools such as ChatGPT, Claude, Copilot, Gemini and AI-powered project management software tools.
The consequential questions and AI in projects are:
- Was its use planned?
- What data was provided to the AI tool?
- Was that data appropriate and approved for use?
- Who is accountable for the output?
- Was the output reviewed by a suitably qualified person?
- What risks arose from using AI?
- Was there evidence of human oversight?
- Can the organisation demonstrate how AI was used?
The findings from the Spring 2026 Pulse report suggest that many organisations are not yet able to answer these questions consistently.
Across 146 self-assessments covering twelve sectors, the median maturity score was 2.43, placing the sample in the Initialised band of the AIPG-CMM. No respondent reached Level 4 or Level 5, while 77% had not reached the Standardised level.
The problem is therefore less about the absence of AI than the absence of consistent governance around its use.
Why should the PMO lead AI governance in projects?
There are several legitimate candidates for AI governance at organisational level.
A Chief AI Officer or equivalent function may own enterprise AI policy. Data governance may own requirements concerning data. Risk, compliance or legal functions may own aspects of regulatory and reputational exposure.
Those responsibilities do not disappear because the PMO becomes involved.
The distinction is between setting organisational direction and applying that direction within projects.
A project needs to know how to plan AI assistance, assess data readiness, manage AI-related risks, maintain human oversight, monitor performance and capture lessons. Those are project-level governance activities. They need to operate consistently across the project and programme portfolio.
This is where the PMO has a natural role.
A PMO already has many of the mechanisms required:
- a project governance framework
- standard templates and artefacts
- project assurance processes
- governance reviews and stage gates
- portfolio-level reporting
- lessons learned
- continuous improvement mechanisms
The conclusion is straightforward:
The PMO does not need to build a separate AI governance machine. It needs to extend the governance machinery it already operates.
Three responsibilities for PMO AI governance
The August 2026 AIPGF white paper proposes three responsibilities for PMOs:
1. Embed
AI governance should be incorporated into the existing project governance framework.
Projects should not have to design their own AI governance arrangements from scratch. The PMO can update standard project artefacts, controls and reporting requirements so that AI assistance is planned, risk-assessed and governed as part of normal project delivery.
This could include introducing an:
- AI Assistance Plan
- Data Readiness Assessment
- AI Assistance Risk Register
- AI Usage Report
- AI Lessons Learned
These become part of the governance architecture rather than additional paperwork sitting alongside it.
2. Assure
Embedding controls is only the beginning.
The PMO also needs to provide assurance that those controls are actually working.
This does not necessarily require a new assurance process. The AIPGF proposes using questions within existing gate reviews, stage assessments and project reporting.
For example:
Foundation
- Which AI tools will be used, and for what?
- What data do those tools require?
- What could go wrong, and what will be done about it?
Activation
- Are the tools being used as planned?
- Is there evidence of appropriate human oversight?
- Are AI-related risks and issues being actively managed?
Evaluation
- Was AI used within the agreed boundaries?
- How effectively did humans and AI tools work together?
- What should be continued, stopped or improved?
The value of this approach is consistency. A PMO can apply the same fundamental questions across projects rather than relying on individual project managers to decide what constitutes adequate AI governance.
3. Improve
The third responsibility is perhaps the most important in the longer term.
AI governance should not be a static set of controls. AI tools change. Organisational practices change. Regulation changes. Project teams learn from experience.
The PMO therefore has a role in measuring governance maturity and using what it learns to improve the framework.
The AIPG-CMM provides one mechanism for doing this. It assesses four governance pillars:
- AI Strategy and Governance
- AI Tools and Infrastructure
- Human Capability and Accountability
- Data Readiness and Quality
These are assessed against five maturity levels: Ad hoc, Initialised, Standardised, Enterprised and Optimised.
This gives the PMO something that many AI governance discussions lack: a way to move from broad principles to a measurable improvement trajectory.
What should a PMO do first?
For organisations that have not yet established standardised AI governance in projects, the answer does not need to be a large-scale programme.
The AIPGF white paper proposes a pragmatic starting sequence.
1. Inventory current AI use
Find out which AI tools and data sources are already being used across projects, why they are being used, and what risks or issues are already known. This is important because AI governance should begin with the actual state of AI use, rather than an assumed future state.
2. Establish a baseline
Use the AIPG-CMM self-assessment to understand current maturity across the four governance pillars. The objective is not to achieve a particular score immediately. It is to establish a defensible baseline from which improvement can be measured.
3. Pilot lightweight AI governance
Select one or two relatively short AI-assisted projects. Introduce a lightweight AI Assistance Plan, incorporate AI-related risks into existing risk assessments, and include commentary on AI benefits and issues in project reporting. This creates an opportunity to test the governance approach before making it standard across the portfolio.
4. Add AI assurance questions to existing reviews
Rather than creating another governance meeting, incorporate AI governance questions into existing gate reviews, reporting and assurance activity.
5. Capture AI-specific lessons
Create an AI category within the existing lessons learned process. Over time, this gives the PMO an evidence base from which to refine its governance framework.
AI governance does not have to become another PMO bureaucracy
There is an understandable risk here.
PMOs are already responsible for governance, assurance, reporting, standards and controls. Adding another layer of AI governance could create more bureaucracy without necessarily improving outcomes.
That is precisely why the distinction between adding governance and extending existing governance matters.
The AIPGF is designed to integrate with existing project management approaches, including Agile, PRINCE2, PMBOK guidance and tailored organisational frameworks. Its Foundation, Activation and Evaluation stages can be mapped onto existing project governance processes.
The objective is therefore not to create an AI governance process that operates beside project governance.
It is to make AI use part of governed project delivery.
The question PMOs should be preparing to answer
Eventually, an executive, auditor, regulator or other stakeholder may ask a relatively simple question:
Can you provide assurance that AI is being used ethically, efficiently and effectively across your projects?
A PMO should be able to answer that question with evidence.
It should be able to show:
- where AI is being used
- why it is being used
- what controls apply
- what data is involved
- who remains accountable
- how AI-related risks are managed
- how human oversight is maintained
- what assurance has been undertaken
- what has been learned
That is the real case for AI governance in projects.
The PMO does not need to become the organisation’s AI authority. It needs to become the function that ensures organisational AI governance expectations are translated into practical, consistent and demonstrable project-level governance.
The August 2026 AIPGF white paper sets out the full argument, together with the proposed PMO responsibilities, governance artefacts, assurance questions, maturity model and practical implementation sequence.