Blog

AI Governance Is the Job: Ten Things to Get Right as Adoption Scales

Subscribe now to join the Risk Register community:

Adopting AI is easy. Governing it is the job. That sentence is for the people driving AI adoption, not the people slowing it down, and the hardest seat in the room right now belongs to the leaders doing it while the business scales: ramping production, standing up new sites and the hiring waves that come with them, and rolling AI into operations, finance, and the talent lifecycle all at once.

2026 is the year the rules caught up. The AI use cases you champion will be judged on governance, not just results, and done right, governance is what protects your roadmap. We run an internal audit and risk advisory firm, and we spend a meaningful part of our year with senior audit and risk leaders at some of the largest technology companies in the world talking about exactly this. The ten gaps below are the ones we see most often, paired up by the decision they share, with the question we'd put to your team on each.

AI governance starts with an inventory, and your vendor's AI belongs on it

1. You can't govern AI you can't see

Every organization we assess has more AI in production than leadership thinks it does: embedded features in SaaS tools, team-level pilots, vendor models running quietly inside core processes, from the plant floor to the talent stack. Shadow AI isn't a rogue-employee problem. It's what happens when the tools are easier to switch on than the approval process is to get through, and that one analyst who got tired of waiting for procurement isn't the exception. Until someone owns a living inventory of where AI touches a business decision, every other control is built on sand.

The question to ask: who owns the complete list of where AI influences a decision in your business today, and when was it last updated?

2. Your vendor's AI is legally your AI

A SOC 2 report tells you about a vendor's security posture. It tells you almost nothing about how their model behaves, what it learned from, or what happens when it's wrong. Accountability for an AI-driven outcome never transfers to the vendor, and in employment use cases the law now says so explicitly. It stays with you. That's why the inventory has to include the AI you didn't choose, the kind that arrives inside a tool you already trust, switched on by a vendor update.

The question to ask: for each AI vendor, can you articulate what the model does, its known failure modes, and your recourse when it errs?

Once you know where AI lives, the next problem is how it got there, because most of it never went through a gate at all.

Pilots become production without a decision, and rubber-stamp review doesn't count

3. Pilots become production without anyone deciding

The most common path to unmanaged AI risk isn't a bad decision. It's no decision. A pilot works, people rely on it, and six months later a critical process depends on a tool that never went through a formal gate. By design or by drift: one of those is a strategy. Only one of them is defensible.

The question to ask: what's the explicit approval gate between experimenting with a new AI use case and depending on it?

4. "Human in the loop" is usually a human in the way

We've reviewed plenty of processes where a person technically approves every AI output, and approves 99.8% of them in under four seconds. That isn't oversight. That's a rubber stamp with a login, and regulators increasingly treat AI that materially influences a human decision as covered anyway. Real review has rejection rates, sampling logic, and escalation paths you can evidence.

The question to ask: if a regulator asked you to prove your human review is substantive, what would you show them?

Nowhere does that proof matter more than when the decision is about a person, which is where the bar moved furthest this year.

AI decisions about people now carry the highest legal bar

5. Decisions about people now carry the highest bar, by law

Anywhere AI touches hiring, promotion, scheduling, or compensation, 2026 changed the stakes. Illinois now treats discriminatory AI outcomes in employment as a civil rights violation, and intent doesn't matter. California's automated decision rules took effect in late 2025. New York City already mandates independent bias audits for automated hiring tools. For a multi-state employer, this isn't one rule. It's a patchwork you have to evidence state by state.

The question to ask: has anyone run outcome analysis on your AI-assisted people decisions across protected classes, in each state where you hire?

6. If nobody can explain the output, nobody can defend it

The moment an AI-influenced decision is challenged, by a customer, an employee, a regulator, or a court, the question isn't whether the model was accurate. It's whether you can reconstruct and evidence how the decision was made. California now expects automated decision records retained for four years. Explainability is a documentation discipline, not a data science feature, and we've written before about what happens to the audit trail when AI does the reasoning.

The question to ask: pick your highest-stakes AI use case. Could you reconstruct and explain a specific decision from six months ago?

Explaining a decision from six months ago assumes the model is still the one you tested. Often it isn't, which is the next section.

Model drift and data rights are AI governance questions, not technical ones

7. Model drift is a when, not an if, especially while you scale

Models degrade. Data shifts as the business grows, populations change as you stand up new sites and new roles, and vendors push silent updates. A model that tested clean at deployment can be quietly wrong a year later, and the business keeps trusting it because it used to work. Monitoring thresholds and retesting triggers are the difference between catching drift and reading about it in a complaint.

The question to ask: what metric would tell you an AI tool has stopped performing, and who's watching it?

8. Your data rights question comes before your use case question

What data is flowing into prompts, training, and assessments? Whose is it, and what did your policies, contracts, and vendor agreements actually permit? Candidate and employee data carries its own rulebook, video interviews and biometrics especially. We've seen more AI initiatives stall on data rights than on technology, and employees are already pasting things into tools nobody sanctioned.

The question to ask: do your data governance rules address AI specifically, and does anyone monitor against them?

None of this requires inventing a program from scratch. The scaffolding is already written, which brings us to the two gaps that decide whether everything above holds up.

The AI governance frameworks already exist, and independent assurance is the whole game

9. The frameworks exist. Most companies use none of them

NIST's AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, and COSO's guidance on generative AI: the scaffolding for credible AI governance is already written, and regulators increasingly treat framework alignment as evidence of good faith. You don't need to invent a program. You need to pick a framework, scale it to your risk, and operationalize it. Directionally right beats theoretically perfect.

The question to ask: which framework anchors your AI governance, and could you show your mapping to it?

10. "We think it works" and "we know it works" are different sentences

This is the whole game. Internal confidence isn't assurance, and the direction of travel is clear: independent bias audits are already mandatory in some jurisdictions, and legal teams, enterprise customers, and regulators are learning to ask everywhere else. The organizations getting this right bring in an independent set of eyes on their own timeline and their own terms, before a regulator, a plaintiff, or a headline sets the timeline for them. Full stop.

The question to ask: when someone asks tomorrow for independent comfort over the AI you've championed, what will you hand them?

That's the point where a governance program stops being a brake and starts being the case for speed, which is where we come in.

AI governance is the case for going faster, not the brake

For the leaders pushing AI forward, governance isn't the brake. It's the argument for going faster, because a use case you can evidence is a use case nobody can stall. Standards say what good looks like. The TRUST AI Method is how we get there: 40 structured procedures across five workstreams (Truth, Rules, Usage, Skills, and Tracking), mapped to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and COSO's generative AI guidance. Our AI governance assessment and configuration review runs on it. You walk away with a maturity score across eight domains, a configuration review of your live AI tools against baselines, and the artifacts that keep use cases moving: policies, registers, and the evidence legal, compliance, customers, and regulators ask for. And because we use AI-assisted techniques across our own audit delivery, we're not advising on something we don't operate.

The next disruption is already scheduled. Agentic AI that acts rather than advises is moving into production faster than most governance programs anticipated, and the ten gaps above are the foundation you'll be standing on when it arrives. If your audit committee is the one asking, our companion piece on what audit committees should be asking about AI right now gives them the questions in their language. And if you'd rather start with a conversation than an assessment, a 30-minute working session on where AI touches your highest-stakes decisions is the easiest first step.  Reach out to Cherry Hill Advisory and we'll bring the questions.

Until next time.

Subscribe now to join the Risk Register community: