AI governance should be proportionate to risk, using a streamlined assurance process and a Test and Learn approach so teams can focus on safe, effective delivery rather than unnecessary process.