Thursday 30 July 2026 8:00 am
| Updated:
Wednesday 29 July 2026 4:52 pm
Effective AI use has become a competitive advantage, and organisations are deploying tools and agents across every part of the business. But with great innovation comes great accountability.Today’s AI isn’t just chatbots – agents are querying databases, calling tools and moving data. And this often happens without oversight over what they can access, or how their risk changes over time. Those blind spots, coupled with the AI skills crisis and lagging governance mean adoption is now outpacing governance.The risk only grows as agents become more capable and autonomous. But businesses don’t need to choose between speed and control. Instead, it’s about changing our mindset to recognise that governance is core to innovation.The problem is governance, not AIAI is only as good as the governance around it, and right now governance is falling short. That’s because traditional IT infrastructure was never built for the speed or scale of AI. Organisations have historically relied on traditional point-in-time governance and annual reviews, but these simply can’t keep pace with the continuous change AI brings. In short, in the AI era what was true yesterday may not be true tomorrow. And the same goes for risk.Major regulations, such as the EU AI Act, are beginning to catch up, by classifying AI systems into risk tiers, from minimal to unacceptable. In tandem, regulators have already converged on risk-proportionate governance.But organisations need to move beyond the checkbox. They should apply the same logic to their own AI state – regardless of legislation – and pinpoint how they can truly safeguard their own customers and assets.Visibility is the foundation of AI governanceOne of the biggest emerging governance challenges is that organisations often don’t know the full extent of the AI operating across their business. These unmanaged, unapproved AI tools operate inside company environments without oversight – what we call shadow AI.Ultimately you can’t govern what you can’t see, and organisations have a difficult task even identifying their visibility gaps, let alone closing them. AI has now been so widely adopted across enterprises that it sits across almost all approved enterprise platforms, employee devices and browsers. And, increasingly, autonomous agents are embedded into everyday workflows. This means you can’t govern the technology in isolation. You need to ascertain the data your AI tools can access, the vendors behind it and the wider business context, not simply the model itself.So what’s the solution? The answer starts with triage. Visibility alone isn’t enough. An inventory is a starting point but organisations need to treat all AI tools as risk hotspots, and assess each AI system’s impact and assign its criticality. For instance, a customer-facing agent with database access, and an internal summarisation tool do not warrant the same controls.Govern AI as fast as you adopt itBut where do you begin? Organisations struggling to govern their own AI tools should follow seven key steps:











