Why AI governance is failing — and what actually works
Summary
AI adoption has outpaced governance, leading to frequent AI-related incidents and data leaks linked to unauthorized generative AI use. Surveys show most organizations overestimate their visibility into AI agents, with many discovering shadow AI—unapproved tools ranging from browser extensions to agentic workflows—and lacking formal decommissioning processes, creating persistent security risks. Ownership of AI governance is fragmented, with CISOs often sharing responsibility and lacking authority over business decisions, while legal, IT, or committee-only models each have shortcomings.
Experts recommend a three‑line governance model where builders own deployed systems, legal/security/compliance set standards and review high‑risk uses, and internal audit verifies effectiveness. Effective governance prioritizes high‑risk and transformative AI use cases, embeds controls into workflows, uses technical enforcement rather than just policies, measures outcomes with standardized evaluations (evals), and treats governance as a business enabler that delivers Return on Integrity by enabling innovation while managing risk.
(Source:Cio.com Australia)