Who decides what the council sees?
On 28 July 2026 FIFA announced a plan to sell minority stakes in a new subsidiary holding its commercial rights, including the World Cup. Three days later the organisation said the proposal would not proceed. Most of the coverage since has been about whether the plan was a good one. The sentence worth a governance reader’s time is a different one, and it is in FIFA’s own release.
“While FIFA regularly creates subsidiaries for specific ventures unilaterally, FIFA is now engaging the MAs and the FIFA Council in this instance given its strategic importance.”
Read that as a control statement rather than as sports news. By FIFA’s own account, creating a subsidiary did not require consultation. This one got it because management judged the matter important enough. Consultation was the exception, and the exception was granted by the people proposing the thing to be consulted on.
The three confederation presidents who objected, Aleksander Čeferin of UEFA, Salman bin Ibrahim Al Khalifa of the AFC and Victor Montagliani of Concacaf, wrote on 10 August that “attempting to sell an interest in the FIFA World Cup was a profound failure of judgement” and “not just a procedural misstep, but a fundamental breach of trust with the very institutions FIFA exists to serve.” That last phrase is the one to carry across. Procedure is the mechanism; trust is what the mechanism protects, and the institutions FIFA exists to serve are, in the reader’s own building, the board, the control functions, the members or clients, and the examiner.
Gianni Infantino’s answer, in a letter to the FIFA Council and the national associations reported by the BBC and Reuters on 21 September, is that the proposal became public before it could be presented in full, which “created the impression that decisions had already been taken. They had not.” He has proposed an external review. The Council meets on 15 October.
Whether it was a decision or a proposal is his argument to make. The question for a regulated firm comes before it: who decided the Council needed to see this at all?
The same question, inside your firm
Ask what your AI governance council has actually reviewed. In most programmes the list is the things the business considered significant. The rest are pilots, features, tools, a setting a vendor turned on in a product you already own.
Nobody decided to keep those from the council. Someone decided they were not worth bringing, and that someone had a stake in the answer. That is the business setting the perimeter of its own oversight, and it happens whether what sits inside the perimeter is a commercial subsidiary or a chatbot answering clients from their account data.
A council that only reviews what it was given cannot know what it was not given. Its minutes will record a clean record of everything it saw.
None of this needs bad faith, and framing it as bad faith is the fastest way to lose the room. A sponsor who honestly judges a system minor has still made the oversight decision on the council’s behalf. The failure is structural: the person who makes the commitment is almost never the person who answers for it, so accountability ends up separated from authority.
Three things to check
1. What triggers review: declared facts, or someone’s view of importance
A materiality threshold that runs on judgement puts the sponsor in charge of whether the sponsor is reviewed. A threshold that runs on facts declared at intake does not.
The facts are the ones a requester can answer in a sentence each, before anything is built, and that can later be checked against what is running:
What data does it read? Customer or member records, employee records, confidential firm information, or none of those. Does it act outside the firm? Sending, transacting, filing, writing to a system of record, or calling another party’s system. Does its output reach a client? Directly, or after a person reviews it, or never.
Any one of those answers landing on the wrong side should route the system to review regardless of how important anyone thinks it is. Importance can still raise the level of review. It should not be what decides whether review happens.
Test it this way: pick three systems your council has never seen and answer the three questions for each. If any of them would have triggered review on the facts, your threshold is not doing the work you think it is.
2. Whether a label can route around the control
Most programmes carry an exemption for pilots, trials, proofs of concept and features. Some of those exemptions are sensible. The question is what stops an unreviewed system from being relabelled into one and running anyway.
If the label changes the route, the label is the control, and a label is easy to change. The usable version has a boundary the label cannot cross: a pilot has an end date, a named owner, a capped population, no client-facing output, and a review that is triggered by the end date rather than by someone remembering. A pilot that has been running for eleven months with real clients on it is a production system with a forgiving name.
3. Whether the council has a list of what it did not review
This is the check almost nobody runs, and it is the only one that tests the other two.
Reconcile what is actually running against what was registered. The sources are ordinary: the vendor and subscription list from accounts payable, the single sign-on application list, the browser extension inventory, the AI features switched on inside products already in the estate, and the model or API keys issued. Set that against the council’s own register.
The gap is the finding. Not as an accusation, but as the measurement of how well intake is working, and as the list the council reviews next. Repeat it at a set interval so the number is a trend rather than an event.
A council that has never produced a list of what it did not review has no evidence that its perimeter is where it believes it is.
The question to put to your own council
What decides which models reach the council: the facts a system declares at intake, or a view of how much it matters?
If it is the second, that view is a judgement the sponsor makes alone, and the council’s record will show only what it was shown.
- FIFA media release, 28 July 2026 (the “unilaterally” sentence and the approval conditions): inside.fifa.com
- Statement attributable to the FIFA President, 31 July 2026 (“this proposal will not proceed”): inside.fifa.com
- Open letter to the football family, AFC, Concacaf and UEFA, 10 August 2026, published in full by UEFA: uefa.com
- Infantino’s 21 September 2026 letter, as reported by the BBC (Dan Roan) and by Reuters; the letter itself is not published: bbc.com
- The principle that review should follow what a system does rather than what it is called is the one Bidun Group put to the Colorado Attorney General in August 2026: the filed comment (PDF)
- And to the Financial Stability Board in July 2026 on agentic AI: 15 July (PDF) and 19 July supplemental (PDF)
Scope note. This piece is about decision rights and intake, not about the merits of the FIFA proposal or about any individual’s conduct. Every statement about FIFA above is either a sentence FIFA published on its own site or a quotation attributed to the person who said it. No motive is asserted. “Judgement” is UEFA’s spelling in the open letter and is quoted as written. The comments cited are submissions to those bodies, not positions either body has adopted.
Written for compliance and risk readers in regulated financial firms. Informational, not legal advice; Mike Bidun is not a lawyer.
