
The rapid adoption of artificial intelligence has outpaced the development of effective AI governance, resulting in significant consequences for businesses. According to the Cloud Security Alliance research, 65% of organizations have experienced at least one AI agent-related incident in the past year, with nearly half attributing confirmed or suspected data leaks to unauthorized gen AI use.
This issue is not due to a lack of policies, but rather a lack of controls that work. The fix is not more documentation, but rather minimum viable governance focused on what actually matters.
Gap in AI Governance
Sara Jodka, an attorney at Dickinson Wright, notes that many companies have AI activity, but few have enforceable AI controls, and even fewer have evidence that those controls work. Gartner analyst Lauren Kornutick warns that retrofitting governance is harder than building it in, and that it is really hard to walk back previous decisions once an incident occurs.
Organizations often do not have visibility into their AI portfolio. More than two-thirds of CSA survey respondents expressed high confidence in their visibility into AI agents, but 82% also reported discovering shadow AI agents in the previous year.
Shadow AI
Hillary Baron, AVP of research at CSA, calls this a blind spot masquerading as self-assurance. Organizations have strong visibility into the agents they know about, but it’s easy to mistake that for seeing everything. Meanwhile, 78% of technology leaders say AI adoption is outpacing their ability to audit or monitor systems.
At payments and data company Deluxe, CTDO Yogaraj Jayaprakasam took a different approach by flooding the zone with sanctioned tools before shadow AI could take root. He notes that shadow AI isn’t a technology failure, but rather a governance vacuum.
One potential solution to the governance challenge is to prioritize minimum viable governance focused on what actually matters.
Whose AI is it Anyway?
Even when AI is visible, it’s often unclear who’s responsible for governing it. Roughly a quarter of CISOs fully own AI governance, while more than half co-lead with another function. Kornutick notes that CISOs have the technology and technical expertise to address the runtime inspection and policy enforcement requirements for AI governance, but they frequently lack the expertise to apply guardrails with context or make decisions about what AI should be used and for what purpose.
A possible approach to addressing this challenge is to adopt a three-line model, where builders own the systems they deploy, legal, security, and compliance set standards and review high-risk uses, and internal audit tests whether the program actually works. This approach recognizes that AI governance spans multiple facets of the organization, including privacy, discrimination, IP, cybersecurity, and regulatory risk.
The Back-end Blind Spot
Governance tends to focus on the front end, approving tools and writing acceptable-use policies, but the back end — knowing when to turn something off — gets far less attention. In fact, per CSA, only 21% of organizations have formal decommissioning processes for AI agents.
As AI continues to evolve, the stakes will only increase. Agentic AI raises the stakes further, as AI becomes an agent taking actions inside systems, and accountability becomes a major concern. Most governance models were designed for a slower velocity, and it’s unclear whether they will be able to keep up with the rapid pace of tech trade-offs.
By prioritizing minimum viable governance and focusing on what actually matters, organizations can begin to address the challenges of AI governance.
Organizations must also consider the potential risks associated with DNS changes and how they can impact AI systems.
Furthermore, the development of new AI technologies, such as those included in the Golden Gate public beta, will continue to raise new governance challenges.
It is essential for organizations to stay ahead of these challenges and develop effective governance strategies to ensure the responsible use of AI.
