Why AI governance can’t wait: Seven steps every security leader should follow today
Effective AI use has become a competitive advantage, and organisations are deploying tools and agents across every part of the business. But with great innovation comes great accountability.
Today’s AI isn’t just chatbots – agents are querying databases, calling tools and moving data. And this often happens without oversight over what they can access, or how their risk changes over time. Those blind spots, coupled with the AI skills crisis and lagging governance mean adoption is now outpacing governance.
The risk only grows as agents become more capable and autonomous. But businesses don’t need to choose between speed and control. Instead, it’s about changing our mindset to recognise that governance is core to innovation.
The problem is governance, not AI
AI is only as good as the governance around it, and right now governance is falling short. That’s because traditional IT infrastructure was never built for the speed or scale of AI. Organisations have historically relied on traditional point-in-time governance and annual reviews, but these simply can’t keep pace with the continuous change AI brings. In short, in the AI era what was true yesterday may not be true tomorrow. And the same goes for risk.
Major regulations, such as the EU AI Act, are beginning to catch up, by classifying AI systems into risk tiers, from minimal to unacceptable. In tandem, regulators have already converged on risk-proportionate governance.
But organisations need to move beyond the checkbox. They should apply the same logic to their own AI state – regardless of legislation – and pinpoint how they can truly safeguard their own customers and assets.
Visibility is the foundation of AI governance
One of the biggest emerging governance challenges is that organisations often don’t know the full extent of the AI operating across their business. These unmanaged, unapproved AI tools operate inside company environments without oversight – what we call shadow AI.
Ultimately you can’t govern what you can’t see, and organisations have a difficult task even identifying their visibility gaps, let alone closing them. AI has now been so widely adopted across enterprises that it sits across almost all approved enterprise platforms, employee devices and browsers. And, increasingly, autonomous agents are embedded into everyday workflows. This means you can’t govern the technology in isolation. You need to ascertain the data your AI tools can access, the vendors behind it and the wider business context, not simply the model itself.
So what’s the solution? The answer starts with triage. Visibility alone isn’t enough. An inventory is a starting point but organisations need to treat all AI tools as risk hotspots, and assess each AI system’s impact and assign its criticality. For instance, a customer-facing agent with database access, and an internal summarisation tool do not warrant the same controls.

Govern AI as fast as you adopt it
But where do you begin? Organisations struggling to govern their own AI tools should follow seven key steps:
- Assess the impact of each AI system and assign risk level: critical, high, medium or low. This should be based on the sensitivity of the data it touches, its level of autonomy, and who it affects – be it customers or employees.
- Layer controls proportional to that criticality – high-risk agents warrant human-in-the-loop approval, tightly scoped permissions and defined escalation paths when something goes wrong; low-risk tools need lighter-touch guardrails.
- Set clear guardrails around what AI agents are allowed to do, enforcing those boundaries and stopping high-risk actions before they become incidents.
- Extend third-party risk management to AI. Know which suppliers embed agents in their products, what data those agents can access, and build contractual protections such as training restrictions, incident notification or audit rights.
- Continuously monitor how AI environments evolve, rather than relying on periodic reviews. Reassess criticality when systems change – a rating assigned at onboarding goes stale the moment an agent’s scope, model or data access shifts.
- Name an owner to define accountability. This means you can adopt AI with confidence and without unnecessary frictions. In many organisations AI risk falls between security, legal and data teams.
- Build ongoing evidence that demonstrates AI is behaving as intended for customers, regulators and stakeholders
By following these steps, governance can become the trust layer that enables organisations to adopt AI with confidence, rather than a source of unnecessary friction.
Governing AI at the speed of adoption
Governance should aim to bolster innovation, rather than stand in its way. Governance may temporarily slow organisations down to speed them up, but once you get the right foundations in place you can move quickly. The organisations that follow this process will see the greatest gains from AI.
The most innovative organisations will build governance into AI from day one, giving the visibility, context and confidence to innovate responsibly. Governance also fails if it only lives in a policy document. Employees need AI literacy, clear acceptable-use guidance, and safe channels to disclose the tools they’re already using – punitive approaches drive AI underground and destroy the very visibility governance depends on. Organisations should be able to go all in on AI, safely, by governing AI as fast as they adopt it.

