In Earl Nightingale’s Lead the Field, there’s a story about an American general captured during the Korean War. Subjected to weeks of interrogation and told he would be executed in the morning, he wrote one final letter home. The instruction he left for his son was six words long: “Tell Johnny the word is integrity.”
Nightingale called integrity the seed for achievement — and he was precise about what it is not. It is not expediency. It is not “everybody’s doing it, so it won’t hurt if I do it too.” His argument was that every act of expediency is a boomerang: you throw it, it travels a circle you cannot see, and it comes back. The only variable is when.
Forty years later, that boomerang has a regulatory schedule attached to it.
Expediency has a look, and auditors know it
In AI governance, expediency is recognizable on sight. It’s the Acceptable Use Policy copied from a generic template, unadapted for the industry, the jurisdictions, or the tools employees actually use. It’s the “we don’t allow ChatGPT” declaration in an organization where 59% of employees admit hiding their AI usage from IT (Cybernews, 2025). It’s the training requirement satisfied by a forwarded PDF nobody read. It’s a governance program that exists as a claim rather than as a record.
Security professionals have older, sharper words for the alternative — the same words a CISSP recites and a court applies. Due care is doing what a reasonable organization in your position would do: having the policy, assigning the accountability, training the people. Due diligence is the ongoing verification that the program actually operates: reviewing it, refreshing it, producing the evidence. Expediency is the absence of both — and it fails not when things go well, but at exactly the moment the organization needs its governance to hold: the audit, the insurance renewal, the incident post-mortem, the regulator’s letter.
Nightingale’s test for integrity was three questions asked before every act: Is this true? Is this honest? Is this the best I can do? An organization’s governance program should survive the same three questions — asked by someone outside the organization, with the evidence in front of them.
“To thine own self be true” is a declared-vs-observed problem
Nightingale built his integrity session on Polonius’s line from Hamlet — be true to yourself first, and you cannot be false to anyone else. The organizational translation is uncomfortable: your policy must be true to what your organization actually does. A pristine AUP describing an organization that doesn’t exist is not governance; it’s fiction with a letterhead.
This is why declared inventory has to meet observed reality. Shadow AI has two faces — the human face (employees using and hiding tools, AI embedded in already-approved SaaS) and the agentic face (agents, keys, and tokens holding authorizations that were never written down, reviewed, or revoked, now outnumbering human identities by an order of magnitude or more, per Astrix Security via the CIS Controls v8.1 MCP Companion Guide, 2026). Both faces share one blind spot: everything is authorized, and nothing is governed. Integrity, at the organizational level, means closing the gap between what you say you run and what you can prove you run.
Reasonableness: adjust the belief to the evidence
Nightingale’s session leans on the philosopher Brand Blanshard, who spent a lifetime arguing that the master virtue is reasonableness: “Adjust your belief or decision to the evidence.” That is arguably the shortest definition of governance ever written. Not adjust the evidence to the belief — which is what a backfilled compliance narrative does — but hold beliefs, policies, and risk decisions that move when the evidence moves.
The regulatory landscape now demands exactly this posture, on the record. Regulators cannot legislate character — so they legislate its observable traces: documented evidence, accountable ownership, verifiable training, records that survive outside scrutiny. Read that way, the converging frameworks aren’t twelve separate burdens. They are one shared attempt to make integrity measurable:
- AI literacy is already law. EU AI Act Article 4 has been in force since February 2, 2025. An organization of integrity doesn’t treat literacy as a checkbox; it treats it as the human layer of the program, with verifiable training and acknowledgment records to show for it.
- Transparency is already law. Article 50 obligations took effect August 2, 2026.
- The frameworks converge on evidence. Twelve frameworks inform the methodology; seven render clause-by-clause in generated policy text today, with five more on the active roadmap. HIPAA § 164.308(a)(1), NIST AI RMF GOVERN, ISO/IEC 42001 Clause 6, EU AI Act Article 17, Colorado SB 26-189 — different jurisdictions, one shared demand: documented evidence of an active program. Telemetry is not evidence. Runtime blocks are not policy. A verbal assurance is neither.
Notice what travels and what doesn’t. The deadlines are jurisdictional — Brussels, Denver, wherever comes next. The three questions are not. An organization in Singapore, São Paulo, or St. Louis that can answer is this true, is this honest, is this the best we can do with evidence in hand is governed everywhere, under every framework, before and after every individual deadline shifts.
Evidence is what integrity looks like from the outside
Emerson — another of Nightingale’s touchstones — wrote that everything in nature “goes by law and not by luck.” Governance outcomes are not luck either. They are cause and effect, and the cause you control is the record: the regulation-anchored AUP, the severity-ranked Executive Risk Report, the one-page Board Memo, and the Verification URL — dated, third-party-verifiable, queryable by an auditor or underwriter for five years. That artifact layer sits above your observability and enforcement stack, complementary to both. Your SIEM sees; your DLP blocks; the governance record is what an outside party can actually verify.
And integrity cuts both ways — it constrains the vendor too. An AI governance tool of integrity refuses to flatter you. Our Coach will never tell you “you’re compliant.” That refusal is the point: a compliance verdict isn’t the tool’s to give, and any product that hands one out is selling expediency in a nicer suit.
The word is still integrity
Nightingale ended his session with a promise: walk with integrity every day, and the harvest follows — not because the universe is sentimental, but because cause precedes effect. The organizational version is just as unsentimental. Due care and due diligence, practiced continuously and recorded verifiably, are what integrity looks like when an organization does it. Expediency is a boomerang. Governance is the decision not to throw it.
Start where the evidence starts: run the free Shadow AI Risk Calculator (12 questions, no account, no email), read the full methodology at /under-the-hood, or take the printable governance templates to your next leadership meeting.
Sources & further reading
- Earl Nightingale, Lead the Field, Session 6, “Seed for Achievement” (Nightingale-Conant)
- William Shakespeare, Hamlet, Act I, Scene 3
- Brand Blanshard, Four Reasonable Men (1984)
- Ralph Waldo Emerson, “Compensation,” Essays: First Series (1841)
- EU AI Act, Articles 4, 17, and 50 (Regulation (EU) 2024/1689, as amended by the Digital Omnibus)
- Colorado SB 26-189 (effective January 1, 2027)
- NIST AI Risk Management Framework, GOVERN function
- ISO/IEC 42001:2023, Clause 6
- Cybernews 2025 AI Workplace Survey; Astrix Security via CIS Controls v8.1 MCP Companion Guide (2026)