Between 40 and 65 percent of enterprise employees use AI tools their IT department never approved, according to IBM's 2025 Cost of a Data Breach Report and Netskope's 2026 Cloud and Threat Report.1 Somebody in marketing is already using ChatGPT to draft client-facing risk summaries. Nobody approved it. Nobody reviewed it. It just happened, the way most AI adoption happens, because the tool was faster than asking permission.
That's not a hypothetical. It's the default state of most mid-size organizations right now. A policy exists somewhere, usually a PDF drafted eighteen months ago that mentions “responsible AI use” in three vague paragraphs. Almost nobody has read it. Fewer could tell you who's supposed to enforce it.
The Gap Auditors Actually Find
Here's the part that should worry an auditor more than the policy gap itself: even where a policy exists, it rarely has an owner with actual authority. Legal drafted it. IT hosts it on the intranet. The AI use cases live in six different departments, unsupervised, because nobody's job description says “stop this.”
The Framework Asks the Right Question First
The NIST AI Risk Management Framework asks a deceptively simple question first: who governs, maps, measures, and manages AI risk in your organization? Most companies can answer “governs” with a name. They usually can't answer the other three. A framework without an owner is a document. It's not a control.
It's Not a Technology Problem
I'd push back on the popular assumption that this is primarily a technology problem. It isn't. It's an accountability problem wearing a technology costume. The tools change every quarter. The question of who's on the hook when a model produces a biased hiring recommendation or a hallucinated compliance answer doesn't change at all, and right now the honest answer at most companies is “we're not sure.”
What a Real Owner Actually Does
- Keeps an active inventory of every AI use case in the business, including the ones procurement never saw because someone expensed a $20/month subscription.
- Runs a lightweight risk review before a new use case goes live, not a six-week committee process.
- Has the standing to say no to a business unit, which means they report high enough in the org to make that no stick.
Without that person, you don't have an AI governance gap. You have an AI governance fiction, and auditors are going to start treating it that way.
Frequently asked questions
Who should own AI governance if we don't have a CAIO?
Someone with cross-functional authority, not necessarily a C-suite title. What matters is the standing to pause a deployment, not the badge on the door.
Does a written AI policy count as governance?
Only if someone is accountable for enforcing it and an inventory exists to enforce it against. A policy with no inventory has nothing to check itself against.
How do we find shadow AI we don't already know about?
Start with expense reports and SSO logs for AI-adjacent domains, then interview department heads directly. Most shadow AI shows up in a $20 line item long before it shows up in a security alert.
Know What's Actually Running Before an Auditor Asks
Devensa AI's vCAIO vOfficer keeps an active inventory of AI use cases across the business and runs risk review before deployment, not after an incident forces the question.
If someone asked you right now how many AI tools are touching customer data, could you answer with confidence?
Schedule a demo with our team at info@devensa.ai, or request early access to the Governance Readiness Assessment, coming to devensa.ai.
Sources
- IBM, Cost of a Data Breach Report 2025; Netskope, Cloud and Threat Report 2026, cited via MarkTechPost. https://www.marktechpost.com



