Skip to content
Thursday 30 July 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
City PM

European business, markets and politics

FTSE 100
10,910.16
+0.02%
DAX
25,327.47
-0.52%
CAC 40
8,454.21
+0.55%
STOXX 50
6,261.80
+0.21%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Thursday 30 July 2026 8:00 am  |  Updated:  Wednesday 29 July 2026 4:52 pm

Why AI governance can’t wait: Seven steps every security leader should follow today

By: Khush Kashyap, Senior Director of Governance, Risk and Compliance at Vanta

Add as a preferred source on Google
Person using a Vanta AI Inventory dashboard on a laptop to manage AI agents and their risk.

Effective AI use has become a competitive advantage, and organisations are deploying tools and agents across every part of the business. But with great innovation comes great accountability.

Today’s AI isn’t just chatbots – agents are querying databases, calling tools and moving data. And this often happens without oversight over what they can access, or how their risk changes over time. Those blind spots, coupled with the AI skills crisis and lagging governance mean adoption is now outpacing governance.

The risk only grows as agents become more capable and autonomous. But businesses don’t need to choose between speed and control. Instead, it’s about changing our mindset to recognise that governance is core to innovation.

The problem is governance, not AI

AI is only as good as the governance around it, and right now governance is falling short. That’s because traditional IT infrastructure was never built for the speed or scale of AI. Organisations have historically relied on traditional point-in-time governance and annual reviews, but these simply can’t keep pace with the continuous change AI brings. In short, in the AI era what was true yesterday may not be true tomorrow. And the same goes for risk.

Major regulations, such as the EU AI Act, are beginning to catch up, by classifying AI systems into risk tiers, from minimal to unacceptable. In tandem, regulators have already converged on risk-proportionate governance.

But organisations need to move beyond the checkbox. They should apply the same logic to their own AI state – regardless of legislation – and pinpoint how they can truly safeguard their own customers and assets.

Visibility is the foundation of AI governance

One of the biggest emerging governance challenges is that organisations often don’t know the full extent of the AI operating across their business. These unmanaged, unapproved AI tools operate inside company environments without oversight – what we call shadow AI.

Read more

New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

Ultimately you can’t govern what you can’t see, and organisations have a difficult task even identifying their visibility gaps, let alone closing them. AI has now been so widely adopted across enterprises that it sits across almost all approved enterprise platforms, employee devices and browsers. And, increasingly, autonomous agents are embedded into everyday workflows. This means you can’t govern the technology in isolation. You need to ascertain the data your AI tools can access, the vendors behind it and the wider business context, not simply the model itself.

So what’s the solution? The answer starts with triage. Visibility alone isn’t enough. An inventory is a starting point but organisations need to treat all AI tools as risk hotspots, and assess each AI system’s impact and assign its criticality. For instance, a customer-facing agent with database access, and an internal summarisation tool do not warrant the same controls.


Vanta AI governance dashboard showing agent inventory, risk severity, employee access, and monitoring details.

Govern AI as fast as you adopt it

But where do you begin? Organisations struggling to govern their own AI tools should follow seven key steps:

  1. Assess the impact of each AI system and assign risk level: critical, high, medium or low. This should be based on the sensitivity of the data it touches, its level of autonomy, and who it affects – be it customers or employees.
  2. Layer controls proportional to that criticality – high-risk agents warrant human-in-the-loop approval, tightly scoped permissions and defined escalation paths when something goes wrong; low-risk tools need lighter-touch guardrails.
  3. Set clear guardrails around what AI agents are allowed to do, enforcing those boundaries and stopping high-risk actions before they become incidents.
  4. Extend third-party risk management to AI. Know which suppliers embed agents in their products, what data those agents can access, and build contractual protections such as training restrictions, incident notification or audit rights.
  5. Continuously monitor how AI environments evolve, rather than relying on periodic reviews. Reassess criticality when systems change – a rating assigned at onboarding goes stale the moment an agent’s scope, model or data access shifts.
  6. Name an owner to define accountability. This means you can adopt AI with confidence and without unnecessary frictions. In many organisations AI risk falls between security, legal and data teams.
  7. Build ongoing evidence that demonstrates AI is behaving as intended for customers, regulators and stakeholders

By following these steps, governance can become the trust layer that enables organisations to adopt AI with confidence, rather than a source of unnecessary friction.

Governing AI at the speed of adoption

Governance should aim to bolster innovation, rather than stand in its way. Governance may temporarily slow organisations down to speed them up, but once you get the right foundations in place you can move quickly. The organisations that follow this process will see the greatest gains from AI.

The most innovative organisations will build governance into AI from day one, giving the visibility, context and confidence to innovate responsibly. Governance also fails if it only lives in a policy document. Employees need AI literacy, clear acceptable-use guidance, and safe channels to disclose the tools they’re already using – punitive approaches drive AI underground and destroy the very visibility governance depends on. Organisations should be able to go all in on AI, safely, by governing AI as fast as they adopt it.


Vanta logo featuring a purple llama head next to the company name Vanta in bold purple text on a white background.
Read more

Orca Security Report: 99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Partner Content

Categories

  • Partner
  • AI

People & Organisations

  • Alondra Nelson
  • Credo AI
  • IAPP
  • Khush Kashyap
  • Vanta

Trending Articles

  • Western Europe’s Fashion E-commerce Market Matures, Representing 20% of Online Consumer Spending as Gen Z Drives momentum

  • Arch Construction Risk Report Reveals Top Challenges Facing Sector Amid Rising Volatility

  • Why AI governance can’t wait: Seven steps every security leader should follow today

  • LSEG boss hails ‘growing momentum’ of Pisces as profit soars

  • Fluidra Delivers a Strong First Half of 2026 and Maintains Positive Momentum in a Dynamic Environment

More from City PM

  • New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

    Business Wire
  • Orca Security Report: 99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production

    Business Wire
  • OpenAI’s rogue agent doesn’t scare me – the millions of others do

    Opinion
    Breaking news concept with digital globe and graphs, symbolizing global financial trends and data analysis on a business w...
  • Experian accelerates AI-first experiences with ServiceNow AI Platform

    Business Wire
  • The FCA has finally woken up to the AI revolution

    Opinion
    FCA reception area highlighting UKs shift to market-led innovation post-Brexit in financial regulations debate
  • Convertr Appoints Greg Jordan as Chief Product Officer to Strengthen Data Governance for Enterprise B2B Programmes

    Business Wire
  • Kore.ai Partners With Atos to Deliver Sovereign Agentic AI for UK Enterprise

    Business Wire
  • The shift from black box to glass box in AI translation

    Partner
    Glass Box AI and THG Fluently collaboration visual depicted in a modern business setting with digital interface elements
CityPM

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About City PM
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 City PM Ltd · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook