AI Governance Has Grown Up

For the past several years, much of the conversation around enterprise AI governance has centered on policies.

Who can use generative AI? What data can employees enter? Which tools are approved? How should AI-generated content be reviewed?

Those questions still matter.

But they are no longer enough.

The next generation of enterprise AI is increasingly capable of taking action—calling tools, accessing systems, retrieving sensitive information, initiating workflows and making decisions across business processes.

That changes the governance problem.

The central question is no longer simply:

What can our AI say?

It is becoming:

What can our AI do—and who is accountable when it does it?

That distinction should be on the agenda of every technology, risk, security and audit leader.

Agentic AI changes the control environment

A traditional generative AI application primarily produces an output for a human to evaluate.

An AI agent can potentially perform a sequence of actions.

Consider an agent used to support customer operations. It might retrieve a customer record, check an account balance, query another system, invoke a third-party service and prepare—or eventually execute—a transaction.

Every step introduces governance questions.

What systems can the agent access?

What credentials is it using?

Which actions are permitted?

Can it delegate work to another agent?

What happens when it encounters something outside its intended scope?

And perhaps most importantly:

Can the organization reconstruct exactly what happened afterward?

These are no longer theoretical questions. Recent ISACA guidance on production AI agents emphasizes the need to understand delegation chains, approved tools, actual agent activity and minimum governance requirements before agents enter production.[1]

An AI policy is not an AI governance program

Many organizations have made meaningful progress by establishing acceptable-use policies for AI.

That is a useful starting point.

But a policy primarily establishes expectations.

Governance establishes decision rights, accountability, controls, evidence and oversight.

A mature AI governance program should therefore answer at least six questions.

Who owns the AI system?

Every production AI capability should have an accountable business owner—not simply a development team or technology vendor.

What is the system allowed to do?

Organizations need defined boundaries around data, systems, tools and actions.

How risky is the use case?

An internal productivity assistant should not necessarily receive the same governance treatment as an AI system influencing hiring, customer eligibility, financial decisions or regulated processes.

What evidence is required before deployment?

Risk assessments, testing results, approvals, security reviews and other evidence should be proportionate to the risk of the use case.

How is the system monitored after deployment?

Approval cannot be the end of governance. Organizations need visibility into what production systems actually do.

Who is accountable when something goes wrong?

Escalation, incident response and decision authority should be established before an incident occurs.

Inventory comes before control

One of the most common AI governance problems is also one of the most basic:

Organizations cannot govern AI systems they do not know exist.

AI capabilities increasingly enter organizations through SaaS platforms, cloud services, developer tools, productivity applications and vendor products—not only through formal enterprise AI initiatives.

The result can be a fragmented environment where the organization has an AI policy but no reliable picture of its actual AI footprint.

A practical AI inventory should capture more than the name of the tool.

At minimum, organizations should understand:

• Business purpose • Accountable owner • Underlying provider or model • Data being accessed • Integrations and tools available • Decisions or actions the system can influence • Risk classification • Approval status • Monitoring requirements • Review date • Retirement or decommissioning process

The inventory becomes the foundation for risk-based governance.

Govern exercised authority, not only granted authority

Agentic AI creates another important distinction.

Traditional access governance asks:

What is this identity authorized to access?

Agent governance must also ask:

What did the agent actually access and do?

An agent may technically have permission to access multiple systems while only being expected to use a subset of those permissions for a particular business purpose.

That means organizations will increasingly need to compare authorized scope with exercised scope.

Logs should make it possible to understand which tools were invoked, which data was accessed, which actions were taken and where exceptions occurred.

Recent ISACA guidance highlights this distinction: valid credentials and authorized access do not necessarily mean an agent's actual behavior remained consistent with the purpose for which that access was granted.[1]

Boards do not need another AI framework

Leadership teams are already surrounded by frameworks, standards and emerging regulation.

What they need is an operating model.

A practical governance structure can begin with:

Discover → Classify → Approve → Control → Monitor → Evidence → Review

That is far more valuable than producing a large AI control catalog that the business cannot operationalize.

The goal should not be to slow innovation.

The goal should be to create enough governance that successful AI experimentation can safely become enterprise-scale capability.

The urgency is becoming increasingly clear. ISACA's 2026 technology research found that AI and machine learning led technology priorities among surveyed digital trust professionals, while only 13% described their organizations as very prepared to manage generative AI risks.[2]

The executive question

Executives should ask one deceptively simple question:

If one of our AI systems took an inappropriate action tomorrow, could we determine who owned it, why it was allowed, what it did and what controls were supposed to prevent it?

If the answer requires several teams and several days to reconstruct, the organization may have AI adoption—but it does not yet have mature AI governance.

The organizations that scale AI successfully will not be those with the longest AI policies.

They will be those that can connect innovation to ownership, control, evidence and accountability.

That is where AI governance is heading.

Ready to move from AI policy to accountable governance?

As AI moves from generating content to taking action, governance needs to move with it. theSlate Co. helps organizations translate emerging AI risks into clear ownership, practical controls, and accountable execution.

Book a 30-Minute GRC Strategy Call

Not sure where your organization stands today?

Assess Your GRC Readiness

Sources

[1] ISACA, “Four Governance Questions to Ask Before an AI Agent Goes Live”, August 24, 2026.

[2] ISACA, “ISACA Looks Ahead to Top Tech Trends of 2026”, 2025.