Skip to main content

Is Your AI Governance Tool Actually Governance?

Alyssa O'Brien8 min read

Title card: Is your AI governance tool actually governance? Governance sits above controls.

AI governance is the set of decisions about who is accountable for AI, which uses are acceptable, and how much risk an organization is prepared to carry. AI controls are the technical mechanisms that enforce those decisions. The gap between the two is real: 63% of breached organizations in IBM’s 2025 research had no AI governance policies in place.1

I raise this because of what I keep seeing in the market.

What the Market Is Calling “Governance”

Every few weeks, another product launches under the AI governance label. That momentum reflects real demand. Gartner projects spending on AI governance platforms to reach $492 million in 2026 and pass $1 billion by 2030.2 Organizations are taking AI risk seriously, and builders are responding.

When I look closely at many of these products, a pattern shows up. You describe what you want the controls to do. Some tools let you upload your existing AI policy so it can be translated into rules. The tool then monitors, flags, blocks, or logs activity against those rules.

That capability is useful, and I want to be clear about that. This is not a critique of any vendor or product. It is an observation about language. What many of these tools deliver is AI controls, and controls are not the same thing as governance.

Two Different Jobs, Two Different Owners

Governance sets strategic direction, defines policy, and assigns accountability. Controls enforce and operationalize those decisions inside systems.7 One answers who, why, and what. The other answers how.

GovernanceControls
Core questionWho decides, why, and what is acceptableHow those decisions are enforced
Primary goalAlign AI risk with business objectivesProtect systems and data, and prevent misuse
Owned byBoard, executives, and cross-functional leadersIT, security, and technical teams
NatureStrategic, directional, evolvingOperational, technical, responsive
Typical outputsRisk appetite, use-case approvals, roles, exception decisionsAccess restrictions, data loss prevention, logging, monitoring

Neither column replaces the other. Governance without controls is a document on a shelf. Controls without governance run without business context, which tends to produce either access so restrictive that people work around it, or a growing pile of exceptions nobody can explain later.7

The Assumption Built Into Every Policy Upload

This is the part I think buyers should understand. When a tool asks you to write in what you want the controls to do, or to upload your AI policy, it assumes the governance work has already happened. It assumes:

  • Your AI policy reflects real decisions, not a borrowed template.
  • A named person owns that policy and keeps it current.
  • Leadership has defined and agreed on a risk appetite for AI.
  • Accountability is assigned across legal, security, privacy, data, and the business.
  • There is a clear process for deciding when a flagged issue is acceptable and when it is not.

If those foundations exist, a controls tool can accelerate a program in a meaningful way. If they do not, the tool enforces whatever it is given. A controls tool can faithfully enforce the wrong decisions.

The analysts tracking this category make a similar point. Gartner advises organizations adopting AI governance platforms to reassess their governance and compliance processes, identify gaps, and clarify roles and responsibilities along the way.2

Why the Distinction Matters Now

The breach data shows two separate gaps

IBM’s 2025 Cost of a Data Breach research found that 97% of organizations reporting an AI-related breach lacked proper AI access controls, and 63% of breached organizations had no AI governance policies.1 Those are two different findings. One is a controls gap. The other is a governance gap. Closing one does not close the other.

High levels of shadow AI added an estimated $670,000 to the average breach cost in the same study.1 Shadow AI is, at its root, a governance question: which tools are permitted, who approves them, and what happens when someone goes around the process.

Two gaps from IBM's 2025 Cost of a Data Breach Report: 97 percent lacked AI access controls, and 63 percent had no AI governance policies.

Boards are still getting oriented

Deloitte’s 2025 global survey of board members and executives found that 31% say AI is not on the board agenda, and 66% say their boards have limited to no knowledge or experience with AI.3 A controls dashboard does not answer the questions a board needs answered: what the organization is trying to achieve with AI, what it is prepared to risk, and who is accountable.

Regulation expects decisions, not only tooling

The EU AI Act timeline shifted this year. The Digital Omnibus, enacted as Regulation (EU) 2026/1744, moved obligations for stand-alone high-risk systems to December 2027.4 The obligations were deferred, not removed. The Act’s high-risk requirements include classifying systems by risk and assigning human oversight to people with the competence and authority to act. Those are governance decisions before they are technical ones.

NIST Put “Govern” at the Center for a Reason

The NIST AI Risk Management Framework organizes AI risk work into four functions: Govern, Map, Measure, and Manage.5 Govern is the cross-cutting function. It establishes the policies, accountability structures, and culture the other three depend on. A few of its categories make the difference from controls concrete:

  • GOVERN 1: policies, processes, and practices for AI risk are in place, documented, and embedded in the organization.
  • GOVERN 2: accountability structures exist, and teams are trained and empowered to carry out AI risk responsibilities.
  • GOVERN 6: risks from third parties, including AI supply chains, are addressed by organizational policy.

Many AI controls tools do strong work in Measure and Manage: monitoring, testing, tracking, and responding. That work matters. It also depends on Govern being done first, by people.

ISO/IEC 42001 takes a similar view. It sets requirements for an AI management system that begins with leadership commitment, defined roles, and objectives before it reaches operational controls.6

Where Governance Ends and Controls Begin

Questions governance answers

  • Which AI use cases are permitted, restricted, or prohibited?
  • Who is accountable when an AI system produces a harmful or incorrect outcome?
  • How are use cases tiered by risk, and does oversight scale with the tier?
  • Who reviews and approves exceptions?
  • When should a model or use case be reviewed, changed, or retired?

What controls do

  • Log prompts and outputs for audit.
  • Block sensitive data from leaving the organization.
  • Restrict access to approved models and tools.
  • Filter or flag outputs that break defined rules, and monitor models for drift.

The bridge between them

Classification connects the two. When governance defines how data and AI use cases are tiered by sensitivity and risk, controls can map directly to those tiers.7 A high-risk use case gets tighter oversight. A low-risk one moves faster. The strategic decision flows cleanly into a technical action.

Governance decides who, why and what is acceptable. Controls enforce those decisions through access, logging and monitoring.

Five Questions to Ask Before You Buy

These are not a test a vendor has to pass. They are a way to know which job you are hiring the tool to do.

  1. Does it help us make governance decisions, or enforce decisions we have already made? Both are legitimate. Know which one it is.
  2. Where do the rules come from, and who owns them? If the answer is “whoever configures the tool,” governance has not happened yet.
  3. What happens after something is flagged? Look for a defined decision path, a named owner, and a record of the outcome.
  4. Does it connect AI risk to our broader risk, privacy, compliance, and data programs? AI risk rarely stays in one lane.
  5. How does its output reach leadership and the board? A dashboard for analysts is not the same as a reporting line for directors.

Frequently asked questions

What is the difference between AI governance and AI controls?

AI governance is the set of decisions about accountability, acceptable use, and risk appetite for AI. AI controls are the technical mechanisms that enforce those decisions, such as access restrictions, data loss prevention, logging, and monitoring. Governance decides. Controls enforce.

Can an AI governance platform replace an AI governance program?

No. A platform can inventory AI systems, automate policy enforcement, and collect evidence. It cannot set your risk appetite or hold accountability. Those decisions belong to people with the authority to make them.

Who should own AI governance in an organization?

Ownership typically sits with executive leadership, with oversight from the board and participation from legal, security, privacy, compliance, data, and business leaders. The NIST AI RMF treats accountability structures as a core part of its Govern function.5

Is uploading our AI policy into a tool enough?

Only if the policy reflects real, current decisions and has a named owner. A tool enforces what it is given. If the policy is outdated or incomplete, enforcement carries those gaps forward.

Where should an organization start?

Start with decisions, not tooling. Inventory where AI is in use, define acceptable and prohibited uses, set a risk appetite, and assign owners. Then choose controls built to enforce those decisions. So where does your organization stand today: are you governing AI, or controlling it?

Let's Keep This Conversation Going

I'm sharing these observations to bring some clarity to a noisy market, not to take sides. The tools are getting better, and that is good for everyone. But no tool can own accountability for you. That part is ours.

When you hear “AI governance” in your next vendor conversation, which job is really on the table: governance, or controls?

Share your perspective in the comments. I'd like to hear what you're seeing.

Sources

  1. IBM and Ponemon Institute, “2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security.” https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
  2. Gartner, “Global AI Regulations Fuel Billion-Dollar Market for AI Governance Platforms,” February 17, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-17-gartner-global-ai-regulations-fuel-billion-dollar-market-for-ai-governance-platforms
  3. Deloitte Global Boardroom Program, “Governance of AI: A critical imperative for today’s boards,” 2nd edition, 2025. https://www.deloitte.com/ca/en/services/audit-assurance/research/governance-of-ai-2.html
  4. Cloud Security Alliance, “EU AI Act’s High-Risk Deadline: Deferred, Not Cancelled,” August 2026 (Regulation (EU) 2026/1744). https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-high-risk-deadline-omnibus-20260/
  5. National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
  6. International Organization for Standardization, “ISO/IEC 42001:2023, Artificial intelligence: Management system.” https://www.iso.org/standard/42001
  7. OvalEdge, “Data Governance vs. Data Security.” https://www.ovaledge.com/blog/data-governance-vs-data-security