The central problem with AI governance is not that organizations have failed to implement enough policies, controls, committees, or risk assessments. The deeper problem is that absolute AI governance is structurally impossible. Governance requires sufficient visibility into what is being governed, sufficient authority to control it, and sufficient evidence to establish accountability. Modern AI systems break all three conditions. They are distributed across model providers, cloud platforms, third-party applications, enterprise data, departments, APIs, agents, human users, and downstream systems. No single organization can fully see, control, or reconstruct every material element of that environment. What the industry commonly calls “AI governance” is therefore not governance in the absolute sense. It is bounded governance over the portions of an AI ecosystem that an actor can actually observe and influence. NIST itself exposes this contradiction. The AI Risk Management Framework makes GOVERN a cross-cutting function intended to operate throughout the AI lifecycle and organizational hierarchy, including third-party software, hardware, and data. MAP goes further by calling for risks and benefits to be mapped across all components of an AI system, including third-party components. Yet NIST also explicitly recognizes that an AI lifecycle contains many interdependent actors who often do not have full visibility or control over other parts of that lifecycle, making impacts difficult to anticipate reliably. Those two realities cannot be reconciled into absolute governance. An organization can be responsible for managing risks that originate beyond the limits of its own knowledge and authority. That is risk management. It is not governance closure. The problem becomes obvious inside a real enterprise. A company may use GPT and Claude in the same workflow, Microsoft infrastructure underneath them, Salesforce or Workday downstream, proprietary data in retrieval, and an agent deciding which service to call. OpenAI can govern the portions of GPT that OpenAI controls. Anthropic can govern Claude. The enterprise can govern how its employees, applications, data, permissions, and workflows use those models. None of them governs the entire resulting system. The problem becomes even more fragmented across departments. HR, finance, legal, engineering, security, and marketing may use the same underlying model under completely different permissions, data classifications, laws, consequences, and risk tolerances. Saying that the enterprise has “governed GPT” therefore says very little. A governed component does not produce a governed system, and even several individually governed components do not automatically produce a governed composition.