
Access full report
Oops! Something went wrong while submitting the form.
Facilitated by The Modern Data Company in collaboration with the Modern Data 101 Community
Latest reads...
TABLE OF CONTENT

Enterprise without an AI policy is a rare find in today’s rapidly evolving AI-globe. Either there is a document stating responsible AI principles, a slide-deck explaining acceptable use, or perhaps a steering committee that meets every few months to discuss how AI should be adopted across the organisation.
But having a policy and being able to enforce it are two very different things.
This is becoming one of the biggest challenges with AI in enterprise today. According to IBM’s Institute for Business Value, 77% of organisations report that AI adoption has already outpaced their governance capabilities. Increasingly autonomous systems such as GenAI, copilots were quickly adopted as experiments by the businesses. However, governance struggled to keep up with the velocity at which these technologies entered into production.
A simple example makes the gap digestible.
The speed limit on a busy road tells every driver what the rule is. It is visible, clearly defined, and technically enforceable. But the sign itself doesn’t stop anyone from speeding. What changes behaviour is the presence of a speed camera. It stays there and just observes the activity, records it, and creates consequences when the rules are broken.
[state-of-data-products]
Enterprise AI governance is in a similar position.
Organisations have already put up the signs. There are written policies that explain how AI should be used, what data can be shared with models, and which systems require human oversight. The harder part is building the mechanisms that can actually observe AI systems in operation and enforce those rules as things happen.
That becomes particularly difficult especially when AI evolves from just generating answers to taking actions.
An employee using an AI assistant to summarise a document is one thing. However, an AI agent that can access internal systems, call APIs, update databases, trigger workflows, and make decisions without a person reviewing every step is an entirely different game.
The governance challenge is no longer simply about defining what is allowed. It is now about knowing what is really happening.
[related-1]

Gone are the days when Governance, in general, was assumed to be a Legal and Compliance responsibility only. Enterprises created policies, established approval processes, reviewed risks periodically, and relied on employees to follow the rules.
That approach made sense when AI systems were relatively contained. A model produced an output, a person reviewed it, and the result was used somewhere downstream.
Today the AI arena has evolved. Modern systems have become deeply embedded in everyday workflows. Models now comes with the capability to interact with the databases, enterprise applications, and APIs. AI agents on its own can perform tasks that previously required several steps by a human.
But there is a flipside to this. The same autonomy that evolves workflows, creates a problem that a policy document cannot solve on its own.
A policy define that sensitive information should not be exposed to an unauthorised system, but on its own, it can’t monitor every prompt sent to an AI application. Automatic determination of an agent’s access to more is absent. Also, it cannot stop an autonomous workflow from taking an action outside its intended scope.
That is why AI governance is increasingly becoming a concern for security leaders and CISOs. The risks associated with shadow AI, data exposure through prompts, excessive permissions, and autonomous agents are increasingly technical in nature. Governance is therefore moving closer to the infrastructure itself. The organisation still needs policies but, those policies now need technical controls behind them.
[playbook]
This challenge becomes even more visible with the rise of agentic AI.
Traditional generative AI usually waits for a person to ask a question and then produces an answer. Agentic systems are different. They can interpret a goal, decide which actions are required, use tools, interact with other systems, and continue working through a task with varying degrees of human involvement.
That creates an entirely new governance surface.
An organisation now needs to understand not just what an AI model can generate, but what an AI agent is actually authorised to do. And perhaps most importantly, where does human oversight still belong?
The risks associated with agentic AI are increasingly becoming a barrier to adoption, with security and risk concerns often taking precedence over questions about model performance or cost.
An agent that can only generate a response has a limited impact. An agent that can access customer records, modify data, send emails, approve transactions, or trigger business workflows has a much larger one.
Organisations are building new AI-powered roads faster than they can put the right governance controls around them. The technology is moving into new environments, but the mechanisms for monitoring and enforcing acceptable behaviour are often still catching up.
This is why AI governance increasingly needs to be designed alongside AI systems rather than added after they have already been deployed. Businesses still think of AI governance has the garnishing layer, but in reality, it is the pillar ingredient.
[related-2]
Shadow AI sits quietly alongside agentic AI. And, it is harder to manage it because many organisations don’t have the complete picture. A lot of employees might already be using public AI assistants, specialised AI applications, browser extensions, coding tools, and other services to complete their tasks. Some of these tools may have been formally approved, but there would be tools adopted by teams or individuals without the knowledge of IT, Security, or Governance teams.
The problem isn’t simply that employees are using unauthorised tools. The real challenge begins when sensitive information enters those workflows.
The policy explains everything clearly but if the governance team don’t know which tools are being used by different teams, what data is being shared, or how those tools are connected to internal systems, they are governing an incomplete version of reality.
Before an organisation can control AI usage, it needs to understand that usage. That means identifying which AI tools are being used, understanding what data flows through them, knowing who has access to them, and determining which applications have become part of everyday workflows without going through formal approval processes. Without this visibility, shadow AI can remain invisible until you reached the mayday.
The AI Regulations are adding another layer of urgency. The EU AI Act is one of the clearest examples. Its provisions are being introduced in stages, with additional requirements taking effect through 2026 and beyond. For organisations operating in or serving the European market, AI governance is becoming a regulatory responsibility as well as a technology and risk management concern.
But the more important point is what the regulation reveals about the broader direction of AI governance. Organisations can no longer rely solely on broad principles and periodic reviews, that is history now. Appropriate controls needs to be demonstrated and that they can operate consistently as AI systems change. This is particularly challenging because AI systems don’t remain static.
With the emergence of AI agents, the actions performed by those systems can change as well. A governance framework that works perfectly on the day it is introduced may become incomplete months later simply because the underlying technology and usage patterns have evolved.

[related-3]
The organisations making the most progress are those that have begun to embed AI governance into the infrastructure.
One sign of this shift is the emergence of dedicated leadership roles in AI governance. Forrester has predicted that 60% of Fortune 100 companies will appoint a dedicated head of AI governance in 2026. Businesses such as Sony, Bank of America, and UBS have already established roles focused on AI governance. The change reflects the fact that AI governance now requires ongoing ownership.
The same shift is now visible at the board level as well. AI oversight is increasingly appearing in corporate disclosures and board discussions, reflecting the fact that AI has moved beyond being an experimental technology owned by IT. Its risks now touch security, compliance, reputation, customer trust, and business operations.
Additionally, organisations are increasingly signing up governance that directly embeds into infrastructure that manages AI, data, identities, and access.
Platform such as Microsoft’s Entra AI Governance is a prime example of this. It focuses on areas such as identity, access, and policy enforcement. ServiceNow’s AI Control Tower takes a broader approach to governing AI agents, including their identities, permissions, and the assets they can interact with.
At the data layer, platforms such as DataOS are taking a similar approach by embedding governance, access policies, and lineage directly into data products. Instead of treating governance as something applied after data is created, the idea is to make governance part of the data product itself. This becomes particularly important when organisations are dealing with sensitive information.
Data that looks harmless in isolation can become sensitive when combined with other attributes. A single field may not reveal much, but combining several seemingly ordinary attributes can create a much clearer picture of an individual or organisation.
Automated sensitive data discovery plays an important role here. The platform proactively identifies and classifies sensitive information as soon as data changes/ updates take place. This not only helps teams detect potential risks earlier on but also reduces heavy dependencies on periodic manual reviews.
The common thread across these approaches is fairly clear. Governance is moving closer to the systems where AI and data actually operate. Policies still matter. Compliance still matters. Human judgement still matters.
But the organisations building mature governance capabilities are increasingly recognising that none of these things can work effectively without technical enforcement underneath them. The camera is finally going up.
AI governance is entering a different phase. Customers and partners are increasingly asking questions about how AI is being used. How are decisions made? What data is involved? Who is accountable when something goes wrong? Can the organisation explain how its AI systems are monitored and controlled?
These questions are increasingly influencing how trust, partnerships, procurement decisions, and customer relationships evolve in a business. The companies pulling ahead in 2026 may not necessarily be the ones with the most powerful AI models. They may be the ones with the accurate context of how exactly AI is being used, what it can access, what it is allowed to do, and how those decisions are being monitored.
AI governance is increasingly becoming a shared responsibility across teams like Legal, Compliance, Security, IT, Data, and business teams. However, organisations are also looking at creating dedicated leadership roles focused specifically on AI governance for better ownership and clarity. Forrester’s prediction of Fortune 100 companies for AI governance in 2026 reflects this pattern.
Agentic AI systems can take actions rather than simply generate information. They may access data, call APIs, interact with applications, trigger workflows, or make decisions with limited human intervention. This creates a larger risk surface because organisations need to govern not only what an AI system produces, but also what it is allowed to access and what actions it can take.
AI compliance focuses on meeting specific legal, regulatory, and organisational requirements. AI governance is broader than this. It includes the policies, processes, ownership structures, technical controls, monitoring, and accountability mechanisms determining how AI is developed and used. Compliance is an important part of governance, but effective governance also helps organisations manage risks that may not yet be covered by regulation.



Find more community resources
Modern Data 101 is a movement redefining how the world thinks about data. A community built by the same team behind the world’s first data operating system, Modern Data 101 sits at the intersection of data, product thinking, and AI. Spread across 150+ countries, the community brings together a global network of practitioners, architects, and leaders who are actively building the next generation of data systems.
At its core, Modern Data 101 exists to simplify the journey from raw data to tangible and observable impact. It advocates high-potential data systems and next-gen architectures to unify and activate insights and automation across analytics, applications, and operational workflows at the edge.
In a world shifting from data stacks to AI ecosystems, Modern Data 101 helps teams not just navigate the change but lead it.

Find all things data products, be it strategy, implementation, or a directory of top data product experts & their insights to learn from.
Connect with the minds shaping the future of data. Modern Data 101 is your gateway to share ideas and build relationships that drive innovation.
Showcase your expertise and stand out in a community of like-minded professionals. Share your journey, insights, and solutions with peers and industry leaders.