Enterprises are adopting AI faster than they are effectively governing it. Copilots, embedded AI features, generative AI assistants, and agentic AI systems are making their way into critical business processes, while governance remains fragmented across legal, security, privacy, procurement, and risk functions. This situation is familiar. Governance seemingly always trails major technological shifts because the business moves quickly and governance and management functions must catch up. This perspective is backed up by a recent industry survey referenced in CIO Dive: “More than 78% of leaders said adoption [of AI] is surpassing their organization’s ability to manage the associated risks, with governance and oversight falling by the wayside in favor of rapid rollouts.”
Given its non-deterministic nature, AI raises larger than normal governance challenges. The issue is clearly not whether enterprises will use AI. They already are. The real question is whether governance programs will mature fast enough to keep that use safe, auditable, and compliant.
Why the issue is becoming urgent
AI is now being embedded in business workflows that support employee productivity, decision support, customer interactions, content generation, code development, and security operations. In many organizations it is already influencing how work is performed even when it is not formally embedded in key business systems. Employees are doing their own thing with AI. That alone should accelerate the governance conversation.
Improving governance pressure is also coming from several other directions. Boards and executives are, as they should, asking questions about accountability, reliability, and reputational exposure. Regulators, auditors, and customers increasingly expect organizations to demonstrate that AI-enabled processes are subject to proper oversight. Security teams are also confronting a fast-growing set of AI-related risks, from data leakage, model errors, and AI-enabled threat actors. Taken together, these pressures mean enterprises can no longer rely on ad hoc approval processes, isolated policies, narrow security controls, or informal monitoring. AI adoption has become an enterprise-level GRC issue.
Why AI cannot be treated as just another application
Traditional application governance was built around relatively deterministic software with known boundaries, explicit logic, and predictable outputs. AI systems do not fit neatly into this model. Their outputs are probabilistic rather than fully deterministic. Their behavior can vary depending on training data, prompt design, context, retrieved data, model updates, and the surrounding workflow. This does not make AI unmanageable, but it does make simplistic governance assumptions insufficient.
This difference matters in practice. Enterprises now must deal with hallucinations and reliability concerns in systems that may still appear authoritative to users. They must think about prompt and context leakage, explainability challenges, and intellectual property or sensitive data exposure. They must contend with AI embedded in recommendations, prioritization decisions, and automated steps within larger business processes. As I argued in my advisory note on the shift from deterministic to probabilistic security, AI changes the assumptions on which trust, control, and assurance have traditionally rested. The governance problem is not simply that AI is new. It is that AI behaves differently.
One impact of this is that enterprises cannot exclusively govern AI at the level of the embedded model. They must govern the system or process in its entirety: the data it can access, the business purpose it serves, the people responsible for it, the decisions it can influence, and the controls around its operation. The old habit of treating new technology as just another application category will leave important gaps unaddressed.
What GRC for AI means in practice
GRC for AI is the enterprise discipline of making sure AI systems are governed by policy, assessed for risk before deployment, monitored across their lifecycle, and aligned with legal, security, privacy, and business requirements. In principle, this should sound familiar to anyone who has worked in enterprise GRC. The challenge is not that the GRC concept is new. The challenge is that AI systems are moving quickly, changing frequently, and often appearing in places where existing control models were not designed to operate.
In practical terms, AI GRC starts with very basic questions that many organizations still cannot answer consistently. Where is AI being used? Who owns each use case? What business process does it serve? What data does it rely on? What could go wrong if it fails, produces misleading output, or is misused? And what controls are required before it can be trusted in production?
This is why governance cannot be only focused on writing policies or publishing an acceptable-use statement. Effective GRC for AI requires operational processes, evidence, and enforcement. It requires intake and review mechanisms, risk classification, approval paths, logging, testing, documentation, and escalation when something falls outside policy or tolerance. In other words, governance must become something the enterprise can consistently execute.
What enterprises need first
Most organizations do not need a sprawling AI governance bureaucracy. They do, however, need a few foundational capabilities that make governance visible, repeatable, and scalable.
First, they require visibility and accountability. Enterprises should know what AI systems are in use, who owns them, and what business purpose they serve. This includes employee-led adoption, often referred to as unsanctioned use or shadow AI, embedded AI in SaaS applications, and use cases developed by business units.
Second, they must be able to make risk-based control decisions. Not every AI use case requires the same level of scrutiny. A low-impact productivity assistant should not be governed to the same level as an AI system that impacts customer outcomes, security operations, or high-value business decisions. High-impact uses should trigger formal review, defined guardrails, and clear approvals.
Third, they should be implementing ongoing oversight. Governance cannot stop at system launch. AI systems are changing too quickly. AI systems should be monitored for behavior, misuse, drift, incidents, and material changes in how they are configured or connected. Logging, periodic reassessment, and defined response processes are essential if oversight is to remain real after deployment.
GRC Unlocks AI
The most important point is that AI GRC should not be thought of as a brake on adoption, just the opposite. In well-run enterprises, governance is what makes IT adoption durable and scalable. It creates the confidence that enables organizations to move from isolated experimentation to broader deployment with fewer surprises and stronger accountability.
That is especially significant now because AI is becoming more embedded in enterprise operations, not less. Organizations that establish practical governance early will be better positioned to scale AI with resilience and compliance. Those that do not will find themselves reacting to risk, scrutiny, and operational drift after AI is already deeply woven into their processes. In a follow-up post, I will look more closely at why agentic AI in particular raises the stakes further by shifting governance from oversight of outputs to control over actions, permissions, and authority further by shifting governance from oversight of outputs to control over actions, permissions, and authority. Meanwhile, there are many sessions that deal with GRC for AI at the May EIC conference in Berlin. Please come and join us there.