If It Can’t Stop the Purchase, It Doesn’t Govern

AI task forces are multiplying. The real test is whether they can bind the vendor, interrupt procurement and reassign risk.

If It Can’t Stop the Purchase, It Doesn’t Govern
The title puts a body at the wheel. The mandate decides whether it can change course.

When an institution announces an AI task force, the first questions are usually about composition. Who chairs it. Which departments have seats. Whether industry, labour or civil society has been invited.

Those questions describe the committee. They do not describe its power.

The more useful questions are less ceremonial. Can the body stop a purchase? Can it compel a vendor to produce evidence? Can it delay deployment? Can it decide who carries the loss when the system fails?

If the answer is no, the task force may still coordinate, study or advise. But it does not control AI. It comments on decisions made somewhere else.

An AI task force is only as powerful as the decision it can interrupt.

That distinction matters because “task force” has no consistent institutional meaning. The same label can describe a congressional study group, an internal technology programme, a regulatory advisory council or an office with direct enforcement powers. Counting task forces tells us that institutions are paying attention. It tells us almost nothing about who is in control.

The Title Tells You Nothing

On 20 April 2023, Alejandro Mayorkas created the Department of Homeland Security’s Artificial Intelligence Task Force. Its stated purpose was to “advance specific mission applications of AI across DHS”.

That wording matters. The body was positioned close to deployment: border security, supply chains, critical infrastructure and the Department’s own operations. It was not simply asked to produce general principles.

But proximity to operations is not the same as authority over them. The founding memo did not, by itself, transfer control over procurement, vendor disclosure or residual liability to the task force. It created an operating mechanism inside an institution whose existing departments still held those powers.

The bipartisan U.S. House Task Force on Artificial Intelligence was designed for something different. Its December 2024 report contained 66 findings and 85 recommendations across areas including privacy, national security, intellectual property, employment and government use. Its output was a roadmap for Congress.

That is useful work. It is also explicitly advisory. A congressional report becomes binding only when legislators convert it into appropriations, statutes or oversight action.

The phrase “AI task force” becomes more useful once the label is removed and the function is stated plainly.

Five bodies, five kinds of power

Body Function and authority
DHS AI Task Force Operational coordination. Coordinates mission applications inside DHS.
Power: Existing departmental, procurement and executive authorities.
U.S. House AI Task Force Legislative advice. Produces findings and recommendations for Congress.
Power: Congress, if recommendations become law, appropriations or oversight action.
SEC AI Task Force Internal adoption. Accelerates responsible AI use across the agency.
Power: The Commission retains its existing regulatory authority.
Texas AI Council Statutory advice. Issues reports, provides training and advises on the regulatory sandbox.
Limit: Cannot issue binding guidance or override a state agency.
European AI Office Direct enforcement. Can request information, inspect documentation and require corrective action.
Power: Can restrict model availability and impose fines within its mandate.

Same label. Five entirely different relationships to power.

The names are similar. The consequences are not.

A Powerful Host Does Not Make Every Unit Powerful

The institutional centre of gravity around AI is moving. Oversight is no longer confined to innovation ministries, academic committees and digital strategy units. It now sits inside agencies responsible for markets, public administration, security and fundamental rights.

But the host institution cannot be used as a shortcut for reading the mandate.

On 1 August 2025, the U.S. Securities and Exchange Commission announced its Artificial Intelligence Task Force, led by Chief AI Officer Valerie Szczepanik. The SEC is a regulator with obvious enforcement gravity. Its AI task force, however, was announced as an internal adoption body: it centralises AI efforts across the agency, removes barriers to implementation and supports the responsible integration of AI into the SEC’s work.

That could eventually improve surveillance, examinations or enforcement. But the announcement did not create a new regulator for the external use of AI in financial markets. The task force’s immediate object is the SEC itself.

The distinction is important. A task force inside a regulator can still be an implementation office rather than an enforcement body.

The European AI Office sits on the other side of the line. It can evaluate general-purpose AI models, request information and technical documentation, investigate possible infringements, require corrective measures, restrict a model’s availability and issue fines for non-compliance.

Those are not coordination verbs. They are control verbs.

The Office matters because the AI Act gives the European Commission legal authority that can be exercised against another party. Its power does not come from the expertise of its members or the quality of its reports. It comes from the fact that a provider may be required to respond.

Power begins where advice becomes an obligation for someone else.

That is the institutional test. Not whether the body sits inside a respected organisation, but whether its decisions alter the duties of the people outside the room.

Texas Wrote the Limitation Into Law

Texas offers an unusually clean example because the boundary is written directly into the statute.

Comparison of the Texas AI Council’s statutory limits and California’s binding frontier-model obligations.
The useful comparison is not council against council. It is recommendation against enforceable obligation.

The Texas Responsible Artificial Intelligence Governance Act, or TRAIGA, created the Texas Artificial Intelligence Council and gave it a real administrative role. The council can issue reports, train state and local authorities, advise the Department of Information Resources and recommend that a participant be removed from the state’s AI regulatory sandbox.

It also has staff and an executive director. This is not an empty structure.

But Section 554.103 prohibits the council from issuing “guidance that is binding for any entity” or overriding the operation of a state agency.

That sentence tells us more than the rest of the institutional branding combined.

The council can observe, advise and recommend. The Department of Information Resources and relevant agencies approve entry into the regulatory sandbox. The Attorney General brings enforcement actions under the Act. Power is distributed around the council, not concentrated inside it.

California illustrates the next stage of the process.

The Joint California Policy Working Group on AI Frontier Models was also advisory. It produced an evidence base and recommendations; it did not become an AI regulator. The difference is what happened afterwards.

California’s SB 53 expressly cites the working group’s recommendations and converts part of that work into statutory obligations. Covered frontier developers must publish risk frameworks and model information. Large developers must report certain assessments. Critical safety incidents must be reported to the state. The Attorney General can seek civil penalties of up to $1 million per violation for specified failures.

California did not make the working group powerful. It moved selected recommendations from the working group into institutions that already possessed legal authority.

That is the path task-force announcements usually conceal:

Four Levers Decide Whether the Body Governs

For an internal task force, the same logic can be reduced to four levers.

  • Procurement. Can the body approve, reject or condition an AI purchase—or does it review the system after the commercial decision has already been made?
  • Information. Can it require model documentation, evaluation results, data-flow records, deployment logs and evidence about subcontractors?
  • Deployment. Can it delay a release, impose conditions, limit a system’s authority or order a rollback?
  • Residual risk. Can it decide who owns the operational loss, regulatory exposure and remediation cost when the system fails?

Budget matters because each of those powers becomes fictional without resources. A task force that can demand an audit but cannot pay for one has a right on paper. A body responsible for monitoring without staff, tooling or access to logs has been assigned liability without control.

The practical test is therefore not whether the task force has a charter. It is whether procurement, legal, security and business owners must respond to its decisions before deployment.

If those teams can ignore it, the task force is a consultation forum.
If they need its approval, it is part of the control architecture.

Build Around the Workflow, Not the Model

An internal AI task force should not begin with a model shortlist. That reverses the decision.

Start with five to ten workflows. For each one, record the owner, current cycle time, cost, volume, error or rework rate, affected users and consequence of failure. Then decide whether AI belongs in the process at all.

The candidate use cases can be classified by business value, data readiness, repeatability, reversibility, regulatory exposure and the authority the system would receive. A summarisation assistant and a model that changes a customer’s credit limit should not travel through the same approval path.

The first 90 days should create an operating system, not a principles document.

Days 1–30: inventory and authority

Map active tools, informal employee use, planned deployments, vendors and data flows. Assign a business owner and a decision owner to every material use case. Write down which function can approve, condition or stop each one.

Days 31–60: evidence and controls

Select one bounded workflow. Establish a baseline and test set. Define data permissions, human review, evaluation thresholds, logging, escalation and rollback. Review the commercial agreement before the pilot—not after it.

Days 61–90: controlled operation

Run the workflow with limited users and limited authority. Measure accepted outputs, corrections, incidents, operating cost and actual completion of the business process. Then scale, revise or stop it.

Four-step operational playbook showing inventory, authority, evidence and review.
The model is not the unit of governance. The workflow—and the decision it changes—is.

This is also why a generic AI policy is insufficient. Policies describe expected behaviour. Operating controls determine what the system is technically and contractually allowed to do.

Contracts Are Where the Task Force Either Exists or Does Not

The legal perimeter will vary by use case. In Europe it may include prohibited practices, high-risk-system obligations, transparency duties and the separate regime for general-purpose AI. Data protection, employment law, sector rules, competition law or export controls may also apply.

The task force does not create that perimeter. Its role is to make sure the perimeter changes the approval path.

That starts with the contract.

The agreement should distinguish between processing customer data to provide the service and reusing it for training, profiling or product development. It should define access to technical documentation, evaluation results and relevant logs. Material model changes and new subprocessors should trigger notice. Portability and termination assistance should be decided before dependency forms. Security incidents, performance failures and regulatory claims need named owners.

Most importantly, the contract should say what happens when the vendor cannot provide the evidence the buyer needs.

A right to audit is weak if refusal has no consequence. A portability clause is decorative if the data format is unusable. A termination right does not create resilience if every downstream workflow depends on the same proprietary model.

This is the organisational version of the argument I made in Who controls AI?: formal governance is often decided clause by clause, because that is where access, evidence and liability are distributed.

It is also the lesson behind The Off-Switch Isn’t Yours. A rollback plan that depends entirely on the cooperation of the vendor being rolled back is not a rollback plan.

If legal has signed before the task force reviews the agreement, the task force is already downstream of power.

The body does not need to negotiate every contract. It does need an approval gate that prevents material AI dependencies from being purchased without the rights required to govern them.

Labour Is Part of the Control System

The most common omission is not technical. It is distributive.

Task forces discuss model risk while treating workforce change as an implementation detail. But AI governance is also labour governance: who is monitored, whose work is restructured, who absorbs errors and who has enough institutional standing to challenge the system.

Washington State’s Artificial Intelligence Task Force, established in 2024, made labour a formal part of the structure. It operated a dedicated labour subcommittee, surveyed workers and released its final report on 1 July 2026.

The important point is not that every organisation needs a subcommittee with the same name. It is that workforce impact needs an owner, a budget and a measurement system.

Three questions expose the gap quickly:

  • Who owns the transition for workers whose roles change?
  • Is there money for training, access and process redesign?
  • Is anyone measuring which groups receive the productivity gain and which absorb the displacement?

If those questions have no owner, the task force is structurally incomplete. It can assess model performance but not implementation resistance. It can see labour savings in a business case without seeing who must perform the additional checking, correction and exception handling that produced them.

The cost rarely disappears. It moves to someone with less power to record it.

The 90-Day Test

After 90 days, a functioning AI task force should be able to produce five things:

  • A register of active AI systems, vendors and material use cases.
  • A named business owner and risk classification for each one.
  • A control and contract clause library linked to those risk levels.
  • Evidence supporting every approval, exception and deployment condition.
  • A review cadence with incident, rollback and escalation owners.

If it has produced only principles, meeting minutes and an awareness presentation, it may have improved coordination. It has not created control.

For operators, the lesson is to build the body around decisions, evidence and interruption rights. For investors, the existence of a task force means little until it changes procurement discipline, vendor dependency and residual risk. For policymakers, an advisory body should be described as advisory until another institution is legally required to act on what it says.

The logo is irrelevant. The minutes are not governance.

The question is whether somebody in the room can stop the purchase, demand the evidence or change who carries the loss.

If they can, the task force may govern.

If they cannot, it is theatre.


Sources


Fabio Lauria

CEO & Founder, ELECTE

Every week, we explore AI without the hype — using data, analysis and an independent perspective.

If you found this analysis useful, please share it with someone who might be interested. And if you’d like to find out how ELECTE uses AI to automate data analysis and reporting, you can find out more at electe.net.