AI Transformation Is A Problem Of Governance: Is It True?

In today’s world of constant change, where new technologies emerge constantly, we must continue to adapt what we know to succeed.

The rise of artificial intelligence (AI) has created an unprecedented opportunity for transformation but has also introduced enormous amounts of risk into organizations.

While the hype around AI is real – more than ever before, there is an abundance of AI solutions that can be accessed by anyone at any time – organizations are also facing many challenges that come with leveraging AI as part of a digital transformation of their businesses.

When using AI as a core component of an organization's digital transformation, governance (i.e., defining policies, processes, and practices associated with AI) will be critical in determining the viability of any proposed use case.

In this article, we take a look back at the development of AI, highlight some of the problems associated with developing AI projects, and discuss ways in which organizations can begin developing the necessary governance infrastructure for AIs.

Recent research from MIT's Project NANDA, published in July 2025, revealed that about 95% of generative AI pilots do not produce verifiable returns on investment.

This means that many companies are losing substantial amounts of money on AI projects due to a lack of governance for their businesses, not because they do not have enough parameters in their machine learning algorithms.

Although technology is not the bottleneck when trying to scale AI, organizations must build the necessary governance around their AI projects in order to scale successfully.

Key problems caused by the lack of governance

A square matrix infographic visualizing 4 key AI governance problems: Shadow AI, Accountability, Regulatory Walls, and Model Drift.

When it comes to scaling AI, organizations are often challenged by the following four broad issues of governance:

  1. Shadow AI - Many employees are using unvetted autonomous agents and unregulated LLMs and submitting expenses for these tools.
  2. Holding People Accountable - Organizations often use AI to produce legal documents and do not have a clear accountability model for determining which employee will bear the cost associated with a model producing faulty results or outputs.
  3. Regulatory Walls - Organizations that develop and/or use high-risk AI applications, such as ChatGPT or LLMs for enterprise, should be particularly concerned about compliance with the European Union AI Act. Starting August 2026, companies that fail to comply with the EU AI Regs will face significant fines.
  4. Drift - When a model begins to drift (i.e., the algorithm no longer produces "correct" output), the organization is unaware or is unable to detect when a drift occurs.

Until organizations build a governance infrastructure that enables them to develop, validate, and scale their AI projects, they will continue to fail to fully capitalize on the opportunities and potential benefits AI presents.

Why AI will fail in 2026

You are inundated with competing advice in the form of syndicated articles about how AI transformation is simply an extension of how you govern your business.

This is true.

The problem is that nearly all of the suggested solutions are written in a completely abstract way.

Most organizations approach AI in the same manner as they do traditional SaaS (Software as a Service). They purchase licenses, assign seats, and expect productivity to magically improve exponentially.

However, this is an incorrect assumption of how AI works as a probabilistic system.

Traditional software operates on a deterministic model; once you program it, it will perform the same way every time. AI is the opposite; it is probabilistic and unpredictable; it learns, evolves, drifts, and ultimately produces unexpected errors.

Managing an AI system is fundamentally different from managing traditional software.

You must monitor it at all times, test for bias on an ongoing basis, keep a current record of where the AI is being used within your organization, and maintain some type of control over how you use this technology.

Without these tools, the transformation initiatives start failing under their own weight; all of the friction shifts from the engineering teams to the legal and compliance teams, at which point they put on the brakes because they fully understand that the company is now at enormous risk of exposure.

Shadow AI and how we think we control it

Most Executive Leadership still thinks that they are in the early phases of evaluating the potential benefits and risks associated with AI integration into their organization; meanwhile, their employees have been doing just that for the last two years.

Undocumented tools

Shadow AI is created when company employees use generative tools, automated workflows, and agentic (or assistive) systems without official authorization from their organization.

Employees may use a summarizing tool to summarize sensitive client data, or a junior developer may inadvertently use a publicly accessible chatbot to troubleshoot or debug their proprietary code.

While it may be easy to dismiss these occurrences, they happen every day within your organization. The security perimeter of the enterprise has effectively been breached by all of the individual employee browsers.

This year alone, 47% of companies have been impacted by a Shadow AI Security Breach.

That means it is impossible to manage an item you do not know exists.

Real-world post-mortem on a $2.3M shadow IT breach

It seems like every month I hear of another story involving an unauthorized application in the workplace.

A logistics company recently found that their Dispatch team was using an API (an Application Programming Interface) to link to their internal routing database. This API allowed drivers to efficiently plan their routes and schedules.

After three months of using it, everything was working well until the vendor changed his policy regarding data retention.

The vendor's training data now had access to every piece of customer information on the logistics company. As a result, the cost of fixing this breach, notifying clients, and paying regulatory fines was $2.3 million.

There are options like creating an internal agent registry and implementing a $15K automated monitoring tool for APIs that would have been effective in preventing this breach.

The EU AI act reality check

For those companies who do business in Europe, the discussion about AI oversight is already over.

The deadline to comply with the European Union AI Act is August 2026 for high-risk systems, and today is June 2026. The time to prepare is gone and many mid-sized companies still do not have an accurate inventory of their working models.

For example, if a business is located in Hungary, the National Authority for Data Protection and Freedom of Information (NAIH) requires documentation on any system used to classify individuals or store any type of sensitive data.

If a company cannot provide this documentation, it will launch an investigation into the company that could result in them being unable to continue operations.

Building a phased roadmap for resource-constrained teams

Developing a compliance framework does not have to involve spending $50,000 on an enterprise-grade platform.

A 6-month portrait infographic showing a phased AI compliance roadmap: Inventory, Risk, Vendors, Policies, Telemetry, and Audit.

To pass regulatory audits and reduce regulatory scrutiny on AI, SME's will need to develop and implement a pragmatic, phased approach as follows:

  1. Month 1 - Inventory Audit: All new deployment of Artificial Intelligence (AI) must be stopped immediately and all departments must create an inventory of every AI they are using, and create a single centralized spreadsheet for all AI tools used within the organization.
  2. Month 2 - Risk Classification: The inventory must be categorized according to the following risk categories defined by the EU AI Act: Prohibited; High-Risk; Limited Risk; and Minimal Risk. All AI tools in the high-risk categories should be stopped immediately, except where it can be shown that they are needed.
  3. Month 3 - Vendor Assessment: The terms of service for the AI tools that remain should be reviewed to ensure that none of the data collected by the AI tools is being used to train models outside of the organization.
  4. Month 4 - Internal Policies: Clear internal policies regarding acceptable employee use of AI should be developed and distributed to all employees. Any violations of these internal policies should result in standard IT security disciplinary actions.
  5. Month 5 - Telemetry Implementation: Basic telemetry monitoring should be established to track usage, costs of tokens used, and basic output anomalies.
  6. Month 6 - Audit Drill: An audit drill should be conducted, simulating how quickly an external regulatory authority may request the documentation related to the HR screening AI tool, and how quickly the team can produce the results of the bias testing.

The issue of AI governance can be addressed through five real case studies

Hypothetical scenarios do not address business problems. Failure to govern AI has unique and observable impacts, which vary based on company size and industry.

Below are examples of the various ways organizations fail when governing AI, the associated costs, and the governance structure necessary to remediate the damage done by the failure to properly govern AI.

Case study 1 - Manufacturing: Hungarian automotive parts manufacturer (Estimated Cost: €50 Million)

A mid-sized Hungarian automotive parts manufacturer located in Esztergom (Annual Revenue - Estimated at €50 million), deployed twelve AI tools across the supply chain and operation teams.

Deployment was driven by enthusiasm of the department heads rather than a systematic or coordinated approach.

The CEO of the company was concerned that their company did not have a central repository for all of its models and with that the CEO was concerned about the approach that their company was going to take to ensure compliance with the forthcoming European Union AI Act through the compliance audit.

The production forecasting model was classified as a high-risk model under the forthcoming supply chain requirements, yet no one really knew which version of the model they were currently using.

The fix for this involved two weeks of stopping all the automated forecasting of the company.

The company created a central model registry using the internal database tools that were already available to the company.

While the software cost for this was essentially zero, the company did have to spend approximately eighty hours of labor across the various departments to complete the mapping of the architecture for creation of the model registry.

Healthcare: Misuse of an AI patient triage system

A regional private healthcare provider had implemented an AI-based triage system to assist the clinic in sorting through the requests received from patients.

The AI system had been extremely effective in being able to provide the medical staff with a method to triage the patient requests. However, the medical staff became aware that the system was consistently ranking lower the requests from elderly patients for urgent pain.

The AI system was provided to the clinic as a "black box" solution from the vendor who supplied the system, so the clinic did not have any documented human oversight protocols in place.

The exposure of liability risk caused the clinic to remove the system from service, resulting in approximately $120,000 being wasted in the implementation of the AI system.

The solution for governance of the triage system was to implement a "human-in-the-loop" protocol.

This would require that every high-risk triage classification would have to be reviewed by a registered nurse and documented in the patient's electronic medical record prior to the automated routing of the triage to the medical staff.

Finance: Unnoticed model drift

The accounting firm automated its invoice processing through a custom computer-vision model.

The vendor of the invoice processing model silently updated the core model with a new version of the model, which was theoretically superior to the old version.

This new version of the model allowed invoices to be processed quicker, but it also had a different method of determining the threshold for identification of decimal placement for some European invoice formats.

The company was processing payments for a period of three weeks before discovering that there were systematic errors with how these payments were being processed.

The issue was not with an update to the vendor. The issue was with a lack of automated drift monitoring.

The company had no way of knowing that the model's confidence scores had dropped significantly lower than when they were started. As a part of its governance model, a company is required to continuously test their models against a static golden dataset for any silent changes.

HR - The bias trap

A technology company with 800 employees purchased an AI-based resume screening tool that could help New HR process the expected influx of applicants into their recruitment process.

A few months later, an internal audit conducted by a hesitant engineering manager found the tool to be systematically filtering out candidates from specific state universities.

The company did not keep a record of any initial bias testing. The HR team assumed that the vendor had conducted the necessary testing. The vendor assumed that the client would have taken the appropriate steps to set up the necessary safety parameters.

This disconnect led to significant internal strife and almost resulted in a lawsuit.

Governance requires that there be a clearly defined boundary of liability associated with the tools.

In this case, a best practice has been established to require all HR technology to have a pre-deployment bias audit conducted using an open-source fairness toolkit and conducted by an internal independent committee.

200-Person startup that scaled too quickly

This rapidly growing fintech startup was heavily promoting AI adoption across its operations at a furious pace to keep pace with rapid growth.

Employees were using over 30 unauthorized generative tools that posed a severe security risk.

The CEO recognized this risk and mandated the implementation of strict governance with respect to the company's AI use.

The engineering team resisted this mandate on the grounds that implementing governance structures would ruin their velocity and competitive advantage.

The solution was to establish a "sandbox" environment for AI deployment that would be monitored and managed with an established governance structure.

The business bought three vetted AI platforms to create enterprise licenses (limited access) around data privacy via walled gardens.

In doing so, they prevented data leakage while maintaining speed.

Structure of accountability for AI initiatives

Typical post-failure analysis of an AI initiative looks like a circular firing squad: IT blames the business unit for poor requirements, business units blame IT for poor execution, and legal blames everyone for not calling them.

Detailed portrait infographic breaking down an AI Governance RACI Matrix, mapping specific processes and roles (BU Leader, CIO, CTO, Legal, QA, etc.).

Transformations stop because there's diffuse accountability; you need to be able to associate precise responsibilities to specific roles.

Creating an AI governance RACI matrix

Creating a RACI (Responsible, Accountable, Consulted, Informed) matrix can eliminate ambiguity during AI implementation.

Vendor Selection and Procurement of AI Models

  • Responsible: Business Unit Leader (identifies need, evaluates tool).
  • Accountable: Chief Information Officer (signs off on technical integration).
  • Consulted: Legal and Compliance (verifies data rights and privacy).
  • Informed: Executive Board (receives quarterly vendor updates).

Ongoing Runtime Monitoring

  • Responsible: MLOps or Data Engineering Team (develops and maintains telemetry).
  • Accountable: Chief Technology Officer (owns operational uptime and accuracy).
  • Consulted: Quality Assurance (reviews drift alert thresholds).
  • Informed: Business Unit Leader (notified if the model deteriorates).

Audit and Compliance with Regulatory Requirements

  • Responsible: Compliance Officer (performs audit, prepares documentation).
  • Accountable: Chief Legal Officer (holds ultimate regulatory risk).
  • Consulted: CTO and CIO (supply technical data for audit).
  • Informed: Entire Company (receives updated usage policies).

The Chief Executive Officer (CEO) is generally not responsible for the day-to-day activities of an organization, whereas the Information Technology (IT) division does not hold the organization accountable for the selection of vendors by the business unit.

By establishing specified accounts of ownership for the AI rollout process, responsibility is maintained throughout, preventing the paralysis that has accompanied other organizations’ AI deployment.

Comparing and highlighting AI governance costs against the costs of chaos

The perception of the costs associated with AI Management and Governance creates substantial resistance from many middle-sized businesses to implement Governance Structures for AI.

Middle-sized businesses tend to look at the costs of solutions such as Vaults AI, OneTrust, and Modulos as excessive.

However, while the cost of oversight needs to be factored in, it is essential that companies understand that this cost should be compared against the costs they would ultimately incur by paying for outside advisory services during a crisis; incurring regulatory fines; and suffering the economic loss associated with the time, effort, and resources wasted through failed AI deployments.

Research indicates that any business that implements strict AI Governance will incur roughly 30% less in advisory costs for AI than a competitor without Governance due to the internal clarity present in a business with the right level of AI Governance.

Calculating AI governance

To accurately budget for AI Governance, companies must first understand the financial requirements associated with establishing AI Governance.

By calculating the cost of AI Governance, companies may avoid "sticker-shock" and therefore can budget realistically on an annual basis.

For a 50 Person Company (Minimum Budget):

  • Tools: $0 – $5,000 Annually.
  • Methods: Use of available resources (spreadsheets for model registry, Microsoft and/or Google Workspace controls for preventing unapproved API access, open-source monitoring products (such as Evidently AI).
  • Workforce: Shared time of a current IT Manager and a current legal counsel (fractionally).

For a 200 Person Company (Mid-Market Budget):

  • Tools: $15,000 – $40,000 Annually.
  • Methods: Mid-tier Governance products, tools for discovering "Shadow" AI by tracking API connections, dashboards dedicated to Model Monitoring on Production Systems.
  • Workforce: One full-time AI Compliance Analyst or at least one very substantial fraction of the budgeted Data Governance Officer time.

Annual budget for an enterprise with 1000+ workforce (Entire enterprise)

Annual Business Tools Cost: $100,000+

Enterprise Business Model Approach: Use of Comprehensive incumbent AI systems/platforms/tools, including Automated Artificial Intelligence Bias Testing, Continuous Detection of Artificial Intelligence Model Drift, Integrated Legal Workflows for the Full Suite of Artificial Intelligence Applications, Automated Compliance Reporting to European Union's Artificial Intelligence Act (AI Act).

GAAS: Requires a Team of Personnel, including: AI Governance Committee Members, MLOps Engineers, Remote Independent Legal Advisors (Lawyers).

While Governance has its costs associated with providing adequate services to businesses; neglecting to have an effective and proactive Governance will lead to tremendous financial losses.

Compliance/regulatory differences across multiple industries

Heed my warning: implementing AI without considering the Industry in question is a recipe for failure.

A flat-design comparison infographic comparing AI governance in Finance (Explainability, Proof of Math) and Healthcare (Patient Safety, Human Oversight).

The Compliance/Regulatory requirements & Governance for a Retail Recommendation Systems Provider vs. an Algorithmic Trading System Providers will differ significantly.

Financial industry governance vs. health care governance

In the Financial Industry, Governance tends to focus mainly on Explainability and Proof of Mathematics.

If a Financial Institution denies an individual credit based on the AI model, the Governance of the AI model must allow the Financial Institution to export the exact criteria, the exact variables, and reasoning why the Credit was denied in a manner that can be comprehended by an individual (auditor) and confirm mathematically to be valid and not an indication of Redlining.

Therefore; Financial institutions focus heavily on maintaining Audit Trails, Immutable Audit Logs, and Maintaining Strict Version Control of their AI Model Weights.

In the HealthCare Industry, Governance focuses almost entirely on Patient Safety, Data Anonymization, and Human Oversight.

Therefore, the Governance of a Diagnostic Imaging Artificial Intelligence System must prevent the Artificial Intelligence from making an independent decision without the Physical Signature of a Physician (using Digital Document Signature technology).

In addition, the telemetry must continuously assess how representative the demographic composition of the training data is to make sure that the model is not underperforming on a particular minority patient population.

A hospital will not protect its patients effectively without a financial governance framework, and a bank will not meet the regulatory requirements of financial regulators without a health care governance framework. Control mechanisms are determined by context.

Final ruling: Transitioning from friction to speed

The teams worry that strict rules on control mechanisms will slow down deployment cycles; they see governance as a roadblock created by legal departments that do not have an understanding of technology.

This is incorrect thinking.

Governance is the brake of a race car; it is installed to drive the car extremely fast without crashing.

Engineers will no longer have to wait weeks for ad hoc legal reviews if a company has a complete inventory of items, defined responsibility for all items, automated mechanisms for monitoring all items, and pre-approved environments for deploying all items.

They will know where they are allowed to operate and will be able to deploy at maximum speeds within those constraints.

Companies fail to adapt AI transformation when they try to purchase innovation rather than build the operational structures necessary to achieve probabilistic outcomes. Fix governance before expecting technology to deliver the promised results.

Questions asked frequently

Where do we begin with an AI Inventory?

Start by analysing network traffic and expense reports; do not rely on employee surveys because many employees do not realise that there are integrated autonomous agents with the SaaS tools they are using daily.

Cross-reference corporate credit card charges against AI vendors that are known (e.g. OpenAI, Anthropic, Midjourney, etc.) to identify any shadow deployments and identify the actual use case for each.

Does governance kill deployment speed?

Governance kills the speed of the reckless, initial deployments, but speeds up the rate at which organisations can scale safely.

Without governance, a pilot project will linger in “proof of concept purgatory” for as long as risk officers refuse to permit the pilot to touch live customer data, and the governance framework provides the checklist necessary for a project to move seamlessly from a sandbox into production.

What is the most critical component of the EU AI Act for medium-sized companies?

The classification phase is the most pressing issue; mid-sized companies must immediately determine whether any of their existing or upcoming systems fall into the "high-risk" annex.

The requirements for compliance with document and risk management systems for the high-risk annex are onerous and the financial penalties for failure to comply with the Act are substantial.

At what frequency should models be monitored for drift?

Models must be continuously and automatically monitored; therefore, telemetry must provide real-time tracking of incoming data distributions and output confidence levels.

If the statistical properties of the incoming data differ from the baseline training data by a predefined threshold, telemetry must automatically raise an alert with the MLOps team.

Manual, periodic checking of probabilistic parts of a model is insufficient.

About the author, Peter Keszegh

Peter K. is a digital marketing veteran who helps businesses grow. With over ten years of experience, he's an expert in SEO, PPC, social media, and content – and he knows how to use them to get real results. Peter's data-driven approach ensures that every strategy is tailored to your unique goals, and his insights are sought after by industry professionals. Let Peter's expertise take your brand to the next level.

We have 10+ years of experience in the field

  • Get a decade's worth of digital marketing expertise on your side.
  • Leverage our 10+ years of experience to achieve your marketing goals faster.
  • We bring battle-tested strategies honed over 10 years to your business.