AI Governance in ITSM – Who Manages the Digital Employee?
Executive Summary
The adoption of artificial intelligence in service management has moved beyond the experimental phase in many companies. While the initial focus was on chatbots, knowledge assistants, and AI-powered automation, another question has now come to the forefront: How do we actually control AI?
Three key findings are emerging:
- AI requires governance just like any other business-critical resource
Companies are increasingly recognizing that AI systems are not just technical tools, but active components of their value creation and must be managed accordingly - The biggest challenge is not the technology, but responsibility
Roles, decision-making authority, control mechanisms, and liability issues remain unresolved in many organizations - ITSM Is Becoming the Natural Governance Framework for AI Services
Existing service management principles provide a solid foundation for ensuring transparency, controllability, and compliance for AI-based services as well
Trend Snapshot
In recent years, many organizations have focused on the question:
"How can we use AI?"
Meanwhile, the discussion is clearly shifting toward:
"How do we ensure that AI operates in a controlled, transparent, and compliant manner?"
Some of the factors driving this trend include:
- Increasing adoption of AI copilots and agentic AI solutions
- increasing regulatory requirements (e.g., the EU AI Act)
- growing reliance on AI-based decisions
- Higher expectations regarding transparency and traceability
- Increasing Risks from Erroneous Decisions Made by Autonomous Systems
Developments surrounding so-called AI agents are particularly exciting. These systems no longer just answer questions; they independently carry out actions, create changes, process service requests, or make operational decisions. As a result, the line between traditional automation and the digital workforce is becoming increasingly blurred.
HUCAISM as a New Framework for Orientation
This is exactly where HUCAISM, Human-Centered AI Service Management, comes into play. The framework combines service management, AI governance, and human responsibility into a practical approach to AI-powered services. While traditional ITSM structures ensure transparency, control, and service quality, HUCAISM expands this perspective to include the central question of how people, AI systems, and digital employees interact responsibly.
This makes HUCAISM particularly relevant for organizations that not only want to implement AI agents, copilots, or AI-based automation, but also want to operate them securely, transparently, and in a business-oriented manner over the long term.
Why is this relevant, and what impact does it have on ITSM and ESM?
IT and enterprise service organizations are facing new challenges that have hardly been addressed by traditional governance models to date:
Who is the service owner of an AI service?
Does responsibility lie with IT, the business unit, Data Science, or an external provider?
How are AI-supported decisions documented in a way that is transparent?
Many existing audit and compliance requirements call for a transparent rationale for decisions.
How is risk and quality management carried out?
While technical services are measured based on availability, performance, or support costs, AI services require additional quality metrics such as:
- Accuracy
- Trustworthiness
- Traceability
- Fairness
- Hallucination rate
- Governance Compliance
How are AI services integrated into existing ITSM practices?
The following practices, in particular, are becoming increasingly important:
- Service Level Management
- Service Catalog Management
- Information Security Management
- Risk Management
- Change Enablement
- Knowledge Management
- Continuous Improvement
The key insight is:
AI does not require an entirely new management discipline. Rather, existing service management principles must be consistently extended to include AI-based services.
The SERVIEW Perspective
From our perspective, many organizations are currently in a situation similar to the one they faced when cloud services first emerged a few years ago.
Initially, the focus was on the technological possibilities. It was only later that it became clear that successful implementation requires clear responsibilities, control mechanisms, and governance structures.
In our current projects, we've identified three challenges in particular:
1. Lack of transparency regarding the AI solutions used
Many companies already have numerous AI applications, but they do not have a central directory of the solutions in use and the responsibilities associated with them.
2. Unclear roles and responsibilities
Often, the following is not defined:
- Who approves AI applications?
- Who monitors their quality?
- Who is responsible for bad decisions?
- Who assesses regulatory risks?
3. Lack of integration into existing service management structures
AI is often viewed as a technology initiative rather than a service.
As a result, the following are missing:
- Service Owner
- Service Descriptions
- Governance Rules
- Quality Metrics
- Life Cycle Management
In the long term, a standalone governance model for AI services will become established, one that is closely integrated with existing ITSM and ESM structures. Service management can assume the role of an organizational operating system to manage AI solutions in a way that is controllable, traceable, and business-oriented.
Takeout
1. Treat AI as a service
Any AI deployed in a production environment should be treated as a service—with a defined service owner, service description, governance rules, and quality objectives.
2. Integrating AI Governance into Existing ITSM Structures
New governance bodies are not always necessary. Existing service management mechanisms can be specifically expanded to effectively manage AI services. HUCAISM can be viewed as a guiding framework that integrates ITSM, AI governance, and “human” responsibility.
3. Define responsibilities early on
The most important question is not which AI is used, but who is responsible for its results. Clear roles and decision-making processes form the foundation for sustainable and scalable AI use.
Conclusion
The discussion surrounding artificial intelligence is shifting from a technological issue to one of governance. Companies that establish governance, transparency, and accountability for AI services today are laying the groundwork for the secure, scalable, and business-oriented use of AI.
HUCAISM can be seen as the next logical step: a human-centered framework that integrates ITSM, AI governance, and accountability. Especially as AI systems increasingly act like digital employees, clear guidelines are needed to define who directs, who monitors, and where human judgment remains indispensable.
The future belongs not to the organizations with the most AI applications, but to those that can effectively manage their AI landscape.
