In March 2026, the Bank of Ghana revised its Cyber and Information Security Directive (CISD) and built artificial intelligence and machine learning (AI/ML) governance obligations into at least six distinct locations across the document, rather than concentrating them in a single AIspecific clause: board-level AI literacy, contractual due diligence for AI and algorithmic service providers, a dedicated Digital Innovations part, a standalone part on cyber and information security requirements for AI systems, AI/ML-specific technical testing, and a dedicated annexure of AI/ML governance and control guidelines. This exceeds what the directive gives its other major cross-cutting priorities, including third-party risk, cloud computing, and access control. One month later, the United States' banking agencies revised their own foundational model risk guidance and explicitly excluded generative and agentic AI from its scope, deferring the question to future rulemaking (Board of Governors of the Federal Reserve System et al., 2026). This paper uses that contrast, and the wider literature on AI governance's uneasy inheritance from model risk management (Kurshan et al., 2020; Vukovic et al., 2025), to argue that CISD 2026's distributed design has a specific, underexamined consequence for Ghana's digital product organisations: a single AI governance owner or a late compliance sign-off cannot satisfy a framework built this way. The argument has sharpened further since the directive's release: in March 2026, MTN Ghana's mobile money business was structurally separated into a distinct, separately licensed entity, meaning product teams building on top of it must now coordinate across a genuine corporate boundary. A composite illustrative case shows what those costs when discovered late. The paper closes with a practical checklist and an agenda for empirical research.