Abstract workspace with floating panels

Enterprise AI Governance Has a Big ‘People Problem’

Most organisations have AI governance policies that don't match how employees actually use AI. Here's what the gap looks like and how to close it.

Table of contents

The governance gap

Two-thirds of organisations have deployed AI. Most can’t govern it.

Enterprise AI projects are running across departments with unclear ownership, policies employees routinely ignore, and no verifiable audit trail. The gap between policy and practice is the primary governance risk in 2026.

2 in 3
organisations lack a mature AI governance framework
2.3/4
average AI trust maturity score across enterprises (McKinsey 2026)
Shadow AI

Banning unapproved AI doesn’t reduce usage. It removes visibility.

Employees using unauthorised tools aren’t acting against company interests. They’re filling the gap between approved tools and useful ones. Closing that gap is a governance decision, not a technical one.

1 in 5
data breaches involve shadow AI, adding $670K per incident (IBM 2025)
47%
of enterprise generative AI usage flows through unmanaged personal accounts (Netskope 2026)
The accountability gap

Agentic AI acts autonomously. Governance frameworks haven’t kept up.

AI risk management used to focus on outputs: biased text, hallucinations, inaccurate scores. That model is now insufficient. Agentic AI systems make decisions that carry direct accountability.

1
Scheduling agents
Commit organisational resources without human sign-off at each step.
2
Financial agents
Initiate transactions autonomously, with limited mid-action oversight.
3
Clinical agents
Prioritise patient care pathways in ways that carry direct ethical and legal consequence.

Human oversight mechanisms need embedding before deployment, not after an incident.

Regulatory landscape

Regulators want verifiable technical evidence, not verbal commitments.

The EU AI Act requires model cards, data lineage tracking, and risk classification — all now in audit scope. US organisations face a patchwork of state laws with no federal equivalent yet.

1
EU AI Act
Risk classification, model cards, data lineage. Fines up to €35M or 7% of global turnover.
2
US federal — NIST AI RMF
Voluntary framework covering risk documentation and transparency. No binding enforcement.
3
US state laws
Colorado SB 205, California’s AI Transparency Act, and Texas’s RAIGA each require disclosures and impact assessments — with varying enforcement.
What to build

Four things robust AI governance actually requires.

1
Inventory first
Catalogue every AI application, agent, and data pipeline before writing a single policy.
2
Policy built on actual behaviour
Map how AI is already being used, then write governance around that — not around aspirational behaviour.
3
Real executive authority
An AI ethics board with advisory status only isn’t a governance structure. It needs direct authority and defined escalation paths.
4
Tie governance to business outcomes
Attach AI compliance metrics to breach reduction, faster audit cycles, and lower remediation time. Governance that can’t show value loses internal support.
1 / 5
Sources: IBM Cost of Data Breach 2025 · Netskope Cloud and Threat Report 2026 · McKinsey 2026 AI Trust Maturity Survey · EU AI Act · NIST AI RMF · mohammedshehu.com

AI governance is important for organisations deploying AI at scale. But two-thirds of organisations have no mature enterprise AI governance framework. 

They’ve deployed AI systems across departments, launched AI projects with unclear ownership, and written governance policies that employees ignore.

There’s a structural gap between those policies and actual AI usage, which is risky for organisations deploying AI at scale.

The shadow AI problem

Data from Gartner, IBM, Wolters Kluwer, and other sources confirms that employees widely use unapproved tools; and that they sometimes do so because the approved AI application doesn’t deliver the AI capabilities they need.

IBM’s 2025 Cost of a Data Breach Report found that shadow AI contributed to 1 in 5 data breaches, adding $670,000 per incident.

Netskope’s 2026 Cloud and Threat Report found that 47% of generative AI usage occurs through unmanaged personal accounts, bypassing enterprise data governance controls entirely.

A ban without an approved alternative doesn’t reduce AI use; it merely removes visibility. AI security fails not because employees resist effective AI governance policies, but because the gap between approved and useful tools is too wide.

Closing that gap is a governance decision, not a technical one.

Agentic AI and the accountability gap

AI risk management used to focus on outputs: biased text, hallucinations, inaccurate scores. That model is now insufficient.

Agentic AI systems and AI agents act autonomously. A scheduling AI agent commits resources, a financial agent initiates transactions, and a clinical agent prioritises patient care pathways. 

Each AI-driven decision carries accountability that existing AI governance frameworks haven’t addressed enough. Human oversight mechanisms need embedding before AI deployment, not after an incident. 

AI behavior in autonomous contexts raises ethical considerations most AI governance policies haven’t caught up to yet.

What the regulatory landscape now requires

The EU AI Act requires organisations to maintain model cards documenting each AI system’s architecture, intended use, performance metrics, and risks. Technical controls around data lineage move firmly into audit scope this year. 

In the United States, there’s no comprehensive federal AI regulation yet, leaving organisations to navigate state AI regulations like Colorado’s SB 205, California’s AI Transparency Act, and Texas’s Responsible AI Governance Act alongside voluntary AI governance frameworks like the NIST AI RMF and OECD AI Principles

Regulatory compliance requirements vary significantly by jurisdiction, making cross-border AI operations burdensome.

JurisdictionFrameworkCore requirementEnforcement
EUAI ActRisk classification, model cards, data lineageFines up to €35M / 7% global turnover
US federalNIST AI RMF (voluntary)Risk documentation, transparencyNo binding enforcement
US stateColorado SB 205, CA Transparency Act, TX RAIGADisclosures, impact assessmentsVaries by state
InternationalOECD AI PrinciplesEthical standards, accountabilityVoluntary

Regulators expect verifiable technical evidence, not verbal claims about ethical AI use or responsible AI practices.

What robust AI governance looks like

Inventory first

A centralised AI management system that catalogues every AI application, AI project, and agentic AI deployment is the foundation of any credible AI governance implementation. 

Treat data governance as part of this inventory: tracking data lineage, access controls, and training data provenance now meets regulatory requirements in most jurisdictions.

Build effective AI governance policies around actual behaviour

Map AI usage patterns before writing policy. Address actual AI-driven decisions, not hypothetical ones. 

Any AI initiative built on aspirational behaviour will drift, and responsible AI governance work is the first casualty.

Give AI governance teams real authority

Strong governance requires structural ownership. An AI governance committee or AI ethics board needs direct executive authority, not advisory status. 

Establish clear AI oversight mechanisms before deploying AI agents: 

  • Pre-deployment review of every autonomous action
  • Defined escalation paths for uncertain AI decision-making; and
  • Hard limits on autonomous authority.

Choose an AI governance platform aligned to your compliance exposure

AI ethics should inform every AI project from scoping through deployment. Frameworks like ISO 42001, the NIST AI RMF, and the OECD AI Principles embed ethical standards and ethical principles into AI development and deployment cycles. 

An AI governance platform that maps to these frameworks makes responsible AI governance auditable.

Tie AI governance to business value. 

Governance that can’t demonstrate business value may lose internal support. Attach AI compliance metrics to outcomes like reduced breach costs, faster audit cycles, and lower remediation time. 

AI innovation and strong governance aren’t opposing forces. Organisations that handle them together end up building AI capabilities that scale without accumulating regulatory and reputational risk.

Abstract organisational network diagram

The final analysis

Robust AI governance requires treating AI oversight and accountability as infrastructure.

McKinsey’s 2026 AI Trust Maturity Survey puts the average responsible AI maturity score at 2.3 out of 4.

In other words, most organisations govern enterprise AI systems they don’t fully understand, using governance policies that don’t reflect actual AI usage. 

Build AI systems with auditable ethical standards from the start, or spend considerably more fixing the damage later.

Get a free audit

Book a 30-minute call to see where AI could help your business.

Virtual personal assistant from Los Angeles supports companies with administrative tasks and handling of office organizational issues.