
AI governance is struggling to keep pace with the rapid expansion of artificial intelligence across enterprises, and the fallout is already evident in business operations.
Incidents and Gaps Reveal Weak Controls
Recent research from the Cloud Security Alliance shows that 65% of organizations have faced at least one AI agent‑related incident in the past year. Almost half of those cases involve data leaks tied to unauthorized generative AI use, according to EY’s Technology Pulse Poll.
Experts say the issue is no longer the absence of policies but the lack of effective controls. Sara Jodka, an attorney at Dickinson Wright, notes, “Many companies have AI activity, some have AI principles, fewer have enforceable AI controls, and fewer still have evidence that those controls work.”
Related: Beats win over former Apple user
Gartner analyst Lauren Kornutick warns that retrofitting governance after deployment is far tougher than designing it from the start. “If an organization was previously very relaxed in their AI use and an incident occurs, it’s much more challenging to decommission tools or models that early adopters were accustomed to using,” she says.
Visibility Problems and Shadow AI
Organizations often overestimate their visibility into AI portfolios. While 68% of CSA respondents claim confidence in seeing their AI agents, a striking 82% admit they discovered shadow AI agents in the previous year. Hillary Baron, AVP of research at CSA, describes this as a “blind spot masquerading as self‑assurance.”
EY reports that 78% of technology leaders believe AI adoption outpaces their ability to audit or monitor systems, and 52% say department‑level AI projects proceed without formal approval. Shadow AI now includes browser extensions, embedded SaaS features, code assistants, meeting transcription tools, copilots, and agentic workflows.
Shadow AI poses a real risk.
Related: Apple squeezes suppliers to cut iPhone costs
At payments and data firm Deluxe, CTDO Yogaraj Jayaprakasam took a proactive stance: “Shadow AI isn’t a technology failure; it’s a governance vacuum. So, we deployed broadly on purpose, to open a sanctioned lane before the unsanctioned ones hardened.”
The situation is complicated by unclear ownership. Roughly a quarter of CISOs fully own AI governance, while more than half share responsibility with another function. Kornutick explains that CISOs have the technical expertise for runtime inspection but often lack the contextual judgment to set appropriate guardrails.
Jodka argues that legal‑only ownership can set standards but cannot enforce code‑level controls, and IT‑only ownership misses privacy, discrimination, IP, and regulatory risks. She proposes a three‑line model: builders own deployed systems; legal, security, and compliance set standards and review high‑risk uses; internal audit tests the program’s effectiveness.
Related: Galaxy Z Fold 8 Ultra Crease Finally Improved
Partner Aslam Rawoof of Benesch Law adds, “AI cuts across all facets of the organization. It can’t be owned by tech or legal alone. You literally need a committee that meets regularly—legal, tech, finance—and reports up to the CEO if not the board.”
In practice, organizations that adopt a clear, layered responsibility framework tend to see fewer surprises. By assigning builders, compliance officers, and auditors distinct roles, they can monitor both the deployment and retirement phases, reducing hidden exposure.
Ultimately, the evidence suggests that effective AI governance requires more than documentation; it demands enforceable controls, realistic visibility, and a coordinated ownership structure that can act quickly as AI agents evolve.
