top of page

AI Governance: Common Questions Answered

Sep 4
11 min read

Most mid-market organizations already have AI in daily use, whether or not leadership has formally sanctioned it. That kind of ungoverned use already has a name, shadow AI.


What's far less common is a clear framework governing how it gets used: who's accountable for it, what data it can touch, and what happens when something goes wrong. That gap, between using AI and governing it, is where most of the real risk sits right now. An AI governance framework is how an organization closes it. Here's what most leaders want to know before they build one.


"AI governance is about making sure the adoption that’s already happening doesn’t outrun the organization’s ability to manage it."


What Is an AI Governance Framework?


An AI governance framework is the structure an organization puts around its AI use: a policy defining what’s acceptable, a named owner or committee accountable for decisions, an approved set of tools, and a process for handling new requests and responding when something goes wrong.


It’s different from an AI strategy. Strategy answers where AI creates value and what to invest in next. Governance answers who’s accountable for how AI actually gets used once it’s in employees’ hands. Most organizations need both, but they tend to build strategy first and governance later, often only after a gap has already created a real problem.



Is AI Governance the Same Thing as AI Risk Management or AI Compliance?


They overlap heavily, and mixing them up is one of the more common points of confusion in this space.


Risk management is the ongoing process of identifying and reducing AI-related risk: it’s the Map, Measure, and Manage work inside the NIST framework covered later in this piece.3


Compliance is the narrower job of meeting a specific external requirement, a state law, an industry regulation, a client contract.


Governance is the umbrella structure, policy, ownership, and process, that makes the other two possible in a durable way, rather than as a one-time scramble.


A useful way to hold the distinction: compliance asks whether you’re meeting the requirement someone else set, risk management asks how exposed you actually are right now, and governance is what makes sure both questions get asked on a schedule instead of only after something’s already gone wrong.



Why Does This Matter Right Now?


AI adoption inside most organizations has outpaced almost everyone’s ability to oversee it. AI adoption inside most organizations has outpaced almost everyone's ability to oversee it. Industry research puts real numbers behind what most leadership teams already sense intuitively: the large majority of organizations are already using AI somewhere in the business, while only a small fraction have anything resembling a comprehensive governance framework in place.¹ That gap doesn't close on its own, and it tends to widen the more useful AI becomes to the people using it.


Most of that gap shows up as shadow AI: employees and teams adopting tools on their own because the sanctioned option is slower, weaker, or doesn't exist yet. The cost shows up in real breach data. IBM's 2025 Cost of a Data Breach Report found that organizations with high levels of shadow AI incurred breach costs roughly $670,000 higher on average than organizations with low or no shadow AI use.¹⁰


Regulation is also moving, in pieces rather than all at once, and there's more to it than most organizations realize, more on that below. For most mid-market organizations, the immediate pressure is still the everyday one: AI is already woven into how people work, and nobody has clearly said what's in bounds.



What US Regulations Apply to AI Right Now?


There's still no single federal AI law, but the absence of one doesn't mean the absence of legal exposure. Several states have already turned proposals into enforceable statutes.


Texas's Responsible AI Governance Act took effect January 1, 2026 and applies broadly to any business doing business with Texas residents, no revenue or company-size threshold required, backed by real civil penalties.⁶ One detail worth knowing: Texas grants a measure of protection from enforcement to organizations that can demonstrate substantial alignment with the NIST AI Risk Management Framework, covered in more detail later in this piece, which makes that framework a genuinely practical starting point rather than an academic exercise.


California, Colorado, Illinois, and New York have each passed their own laws covering narrower ground, frontier-model transparency, automated decision-making, and AI used in employment screening, and more states are actively drafting versions of their own.



Does the EU AI Act Apply to US Companies?


Often, yes, and the trigger is what the AI touches rather than where the company is headquartered. The EU AI Act applies to any organization that places an AI system on the EU market, or whose AI system’s output is used by people in the EU, regardless of physical presence or EU offices.7 In practice, that reaches a purely US-based company with EU customers, EU job applicants, or a product accessible from Europe.


A company with genuinely zero EU touchpoints falls outside it, though that’s a smaller group than most assume, and it’s worth checking rather than guessing. For the parts of the Act that do apply, the timeline shifted this year: transparency obligations took effect on schedule in August 2026, while the toughest high-risk system obligations were deferred to December 2027 under a regulatory amendment known as the Digital Omnibus.2



Are Some Industries Held to a Higher AI Compliance Bar?


Yes, and healthcare and manufacturing are two of the clearest examples.


In healthcare, any AI system touching protected health information inherits the same HIPAA obligations that already govern human staff: access controls, audit trails, and a signed business associate agreement with any AI vendor in the data path. An AI tool that crosses the line from assisting a clinician's judgment to replacing it can also trigger FDA medical device oversight.⁸


In manufacturing, the pressure looks different but lands just as hard: defense manufacturers layer CMMC and ITAR requirements on top of whatever AI governance they already run, and AI-driven equipment or worker-monitoring tools can draw OSHA scrutiny under the same general duty clause that already governs machine safety, alongside a growing list of state laws covering AI in employment decisions.⁹


A mid-market organization in either industry doesn't need a dedicated compliance department to meet this bar. The governance layers covered in more detail below, policy, ownership, an approved tool list, documented incident response, are also the practical answer to nearly every one of these frameworks, since they all converge on the same three questions: who's accountable, what's the audit trail, and how does a human stay in the loop.



Where Does Fairness and Bias Fit Into AI Governance?


This is the piece a purely risk-and-compliance view of governance tends to miss, and it deserves its own line item rather than getting folded into "policy." An AI system can follow every data-handling rule in a policy and still produce outputs that treat people differently based on protected characteristics, and a real share of the state laws already covered above exist for exactly that reason: Illinois’s employment AI law and the automated-decision-making rules in states like Colorado are aimed specifically at algorithmic fairness.6


The practical fix means building a fairness check into how new AI use cases get approved in the first place, particularly anything touching hiring, lending, or other decisions about people, and revisiting that check periodically rather than treating a single pre-launch review as sufficient. No data science team required, just a defined question in the approval process that someone is responsible for asking.



What Does an AI Governance Program Include?


A working governance program is built in layers, and each layer makes the next one easier to run:


Policy:

A written document defining what’s approved, what’s discouraged, and why, in language people will actually read and follow.


Ownership:

A named individual or steering committee accountable for decisions, tool evaluation, and policy updates.


Approved tools:

A living list of vetted AI tools with a clear procurement path, so the sanctioned option is also the easy option.


Data handling rules:

Clear guidance on what information, especially client or employee data, can and can’t go into an AI tool.


Incident response:

A defined process for what happens when something goes wrong, from a data exposure to a bad output making it into a client deliverable.


Most organizations don't need to build this from scratch. Two reference frameworks show up in the majority of enterprise governance programs today.


  1. The NIST AI Risk Management Framework, voluntary in the US, organizes the work into four functions:

    • Govern: the ownership and policy layer already described above

    • Map: identifying where AI is actually in use and what could go wrong with it

    • Measure: testing and monitoring those risks with real evidence instead of assumptions

    • Manage: acting on what that monitoring turns up, up to and including shutting a system down

  2. ISO/IEC 42001 covers similar ground as a certifiable international standard, increasingly showing up in vendor and procurement conversations as proof a governance program is more than a document.³


Neither is legally required for most mid-market organizations, but both give a program a recognizable structure instead of a custom-built one, which matters the first time a client or auditor asks how AI is actually being governed.



Does Governance Look Different for AI Agents Than for Tools Like ChatGPT or Copilot?


It does, and the distinction is becoming more important by the month. Governing a tool like ChatGPT or Copilot is mostly about acceptable use: what data can go in, what the output gets used for, who’s accountable if something’s wrong. An AI agent is a different category of risk, because it can take action on its own, executing workflows, accessing systems, calling other tools, without a human reviewing each step along the way. The risk is an action the system already took, with no one reviewing the step in real time.


Agentic AI is also where a lot of AI investment is quietly going to waste. Gartner has forecast that over 40% of agentic AI projects will be canceled by the end of 2027, and the reasons cited are organizational: escalating costs, unclear business value, and inadequate risk controls, the exact gaps a governance program is designed to close.4 


Organizations that get ahead of agent governance now, defining access controls, audit trails, and a review process before agents go into production, are positioning themselves on the right side of that statistic instead of becoming part of it.



Does More Mature Governance Mean Fewer AI Failures?


The relationship is more complicated than most people assume, and it’s worth sitting with, because it reframes what a governance program is supposed to do. A major 2026 industry study on enterprise AI agents found that nearly three-quarters of organizations running agents in production had already rolled back or shut down one after deployment. Counterintuitively, the rollback rate was even higher among organizations with the most mature, well-monitored governance programs.5


That points to how governance really works in practice. Organizations with monitoring in place can see failures that less-governed organizations simply miss, and catch them before a customer does instead of after.


The honest goal of an AI governance program is building the visibility to catch problems while they’re still a policy conversation.



What’s the Difference Between an AI Policy and an AI Governance Program?


A policy is a document. A governance program is the structure that keeps that document current and enforced. A policy alone tells people what’s allowed. Without an owner reviewing it, a committee evaluating new tools, and a process for handling exceptions, a policy quietly goes stale within a few months and gets routed around. The program is what makes the policy durable.



Who Should Own AI Governance in a Mid-Market Organization?


Ownership works best with someone who has both technical fluency and a genuine seat at the leadership table, an executive-level responsibility rather than a function tucked inside IT. Many mid-market organizations without a full-time CIO or CAIO route this through a fractional executive who can build the policy, chair a steering committee, and stay accountable for it over time, rather than deliver a one-time document and move on.



Comparing Governance Maturity Levels


Organizations tend to fall into one of four stages.

Here’s how they compare:


No Governance

Policy Only

Governed Adoption

Enterprise Framework

Written AI policy?

No

Yes

Yes

Yes

Named owner or committee?

No

No

Yes

Yes

Approved tool list?

No

Sometimes

Yes

Yes

Incident response plan?

No

No

Yes

Yes

Board or exec visibility?

No

No

Sometimes

Yes

Best suited for

Any org still in early experimentation

Organizations that need something in writing quickly

Mid-market organizations with real AI use across teams

Large enterprises with regulatory exposure


Most mid-market organizations don’t need to jump straight to an enterprise framework. Governed adoption, a policy with real ownership and an approved tool set behind it, closes most of the practical risk without the overhead built for much larger organizations.



What’s the Difference Between AI Governance and a Fractional CAIO Engagement?


A Fractional CAIO’s work includes AI governance, but governance is one piece of a broader mandate that also covers AI readiness, education, and strategy. An organization that only needs the policy and oversight structure can build a governance program on its own or with narrower support. An organization also trying to figure out where AI creates value and how to build internal capability typically needs the fuller Fractional CAIO scope. See our Fractional CAIO FAQ for how that engagement works.



How Long Does It Take to Build an AI Governance Framework?


A minimum viable policy, ownership structure, and approved tool list can be built in weeks, not months, when the organization starts with an honest inventory of what’s already in use. The stakeholder work is the harder part: getting department heads, franchise owners, or distributed teams to buy into a policy framed around enabling their work rather than restricting it.



Is Your Organization Ready to Build an AI Governance Framework?


An AI governance framework is worth prioritizing now if any of the following describes your organization:


•     Employees are already using AI tools without a formal policy in place

•     Leadership can’t say with confidence which AI tools are in use across the organization

•     You operate in a regulated industry or handle sensitive client or employee data

•     You’re planning to deploy AI more broadly and want the guardrails in place first

•     No one is clearly accountable for AI decisions today



Building Governance That Moves With You


AI is a moving target. The tools, the risks, and the regulatory landscape underneath it are all still shifting, which means a governance framework built to be perfect on day one and never revisited is already the wrong kind of framework. The organizations getting this right treat governance the same way they’d treat any strategic capability: informed by what’s really happening on the ground, built to flex as adoption grows, and revisited on a real cadence instead of set once and forgotten.


That’s the approach we bring to every AI governance engagement. We start with an honest read of where an organization is today, and we stay involved as priorities shift, new tools emerge, and AI use matures, so the governance in place keeps pace with how the organization is actually using AI rather than describing how it used AI six months ago.




Rob Niles standing in front of a bookshelf


Fractional Chief AI Officer


Rob Niles helps organizations cut through AI complexity as Odyssey Partners Consulting's Fractional Chief AI Officer. He brings 25+ years of enterprise IT experience to every engagement.








Sources
  1. Aon, AI Risk 2026; Economist Impact / Kyocera Future of Work Study, late 2025.

  2. EU AI Act, official legislative text (EUR-Lex); Digital Omnibus on AI (Regulation (EU) 2026/1744), entered into force July 27, 2026, deferring Annex III high-risk obligations to December 2, 2027.

  3. NIST AI Risk Management Framework (AI RMF 1.0), January 2023; ISO/IEC 42001:2023.

  4. Gartner, "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027," press release, June 25, 2025.

  5. Sinch, The AI Production Paradox, 2026 (survey of 2,527 enterprise decision-makers across 10 countries and 6 industries, conducted January–February 2026).

  6. Texas Responsible AI Governance Act (HB 149 / TRAIGA), effective January 1, 2026; GLACIS, "US State AI Laws Tracker," 2026; Compyl, "US State AI Laws: The 2026 Compliance Guide," 2026 (NIST AI RMF alignment as enforcement safe harbor).

  7. EU AI Act, Article 2 (territorial scope); Techné AI, "The EU AI Act for US Boards: A Reference Guide," 2026; JAGGAER, "EU AI Act 2026: The Complete Compliance Guide," 2026.

  8. Kiteworks, "AI Compliance Requirements for Healthcare Organizations," 2026 (HIPAA, FDA clinical decision support guidance, 21 CFR Part 11).

  9. Kiteworks, "AI Compliance Requirements for Manufacturers," 2026; Ogletree, "AI on the Factory Floor: A Primer for Manufacturers," June 25, 2026 (CMMC, ITAR, OSHA General Duty Clause).

  10. IBM, Cost of a Data Breach Report 2025, with the Ponemon Institute, released July 30, 2025 (shadow AI breach cost impact).

Comments


bottom of page