Photo By: Philipp Katzenberger
Artificial intelligence has quickly moved from an emerging technology conversation to a board-level governance issue. A recent survey found that 85% of firms now view AI as a bigger compliance concern than cybersecurity. For Melissa Cohoe, Global Strategist for Security, Risk & Resilience at NewRocket, that shift is consistent with what she is hearing from customers.
AI is creating risk across multiple areas at once, including cybersecurity, privacy, governance, third-party and operational risk. It is also introducing risks that are unique to AI. At the same time, organizations are adopting the technology rapidly and using it to transform how work gets done. That combination is making AI compliance both increasingly important and increasingly complex.
One of the biggest challenges is also one of the most basic: organizations often do not know where AI is being used.
Even companies that have started building inventories of their AI platforms can struggle to achieve complete visibility. Employees may be using public AI tools without approval, while AI capabilities can be embedded within third-party applications that do not appear in traditional technology inventories.
This creates a difficult governance problem. Organizations cannot effectively manage risks they cannot see.
Cohoe says the uncertainty around AI usage is closely connected to concerns about regulatory fines and reputational damage. If an organization does not know what AI it has, where it is being used or what information is flowing through it, it is difficult to assess its exposure.
“The first step is to know what you have,” she says.
That visibility problem also reveals one of the biggest misconceptions about AI governance. Organizations cannot simply apply the same governance approaches they used for previous technology transformations.
AI is being adopted at a speed and scale that can quickly outpace traditional governance processes. Periodic reviews and conventional approval processes may not be enough when AI is continuously being introduced into applications, workflows and business processes.
Cohoe believes organizations need to move toward continuous assurance, embedding compliance, governance and assurance activities into everyday work. The goal is not simply to add more controls. It is to make compliance easier to follow by reducing friction and integrating it into existing workflows.
That becomes particularly important as organizations try to balance risk management with innovation.
Cohoe sees compliance as something that should enable responsible innovation rather than prevent it. “Consider it as guardrails, not roadblocks,” she says.
That requires both a cultural and structural change. Compliance needs to be perceived as a way to help organizations innovate safely, rather than as an obstacle to progress. At the same time, governance needs to be proportionate to the risk involved.
Organizations should consider both the potential value and the risk of an AI initiative before deciding how much governance it requires. A high-risk, low-reward initiative may not warrant investment in the first place. For initiatives that move forward, compliance efforts should reflect the organization’s risk appetite and the potential impact of the technology.
Establishing those thresholds requires upfront work, including executive agreement on risk appetites, investment decisions and expected returns. But doing that work early can make subsequent compliance decisions much easier and help prevent governance from becoming a checkbox exercise.
The nature of AI blind spots also changes as organizations mature. Companies with no formal AI management may have little visibility into their AI estate, leaving them exposed to widespread shadow AI and AI sprawl.
Organizations with inventories have more control, but may still not know how employees are using approved tools. An employee could enter confidential information into a public AI platform, for example, or build an AI agent that becomes an important part of a business process without formal oversight.
For more mature organizations, the challenge may shift toward AI embedded in third-party software. These capabilities can be difficult to identify and may not appear in traditional AI inventories.
For CIOs trying to determine where to begin, Cohoe recommends starting with the organization’s current state rather than applying a universal checklist. If there is no visibility into the AI estate, establish an inventory and define ownership. If the organization cannot determine which AI assets require additional scrutiny, establish a risk-based assessment process. If those capabilities already exist, build a cross-functional governance model that brings together business, technology, risk, compliance and security.
AI governance is also increasingly becoming a boardroom issue, but Cohoe sees a communication gap between technical leaders and executives. Technology leaders often discuss features, functions and technical findings, while boards focus on business outcomes, risk, investment and impact.
Closing that gap requires technical leaders to translate AI risks into business terms that executives can act on.
There is also no universal answer to who owns AI governance. Responsibility may sit with an AI center of excellence, IT governance, a dedicated AI governance function or multiple teams. Cohoe believes the strongest approach is ultimately a shared responsibility that brings together operations and technology with risk, compliance and security.
Yet while AI requires new approaches, Cohoe cautions against treating AI governance as completely separate from everything that came before. Organizations can learn from governance practices developed around cloud computing, mobile technology and other major transformations.
The opportunity is to retain the foundations that still work, learn from past experience and adapt governance to the speed and scale of AI.
For organizations navigating the next phase of AI adoption, success will depend less on creating the most restrictive controls and more on building the visibility, accountability and continuous assurance needed to manage risk while keeping innovation moving.

More Stories
The STEM or liberal arts choice describes a labour market that no longer exists
Hyundai CRETA and Its Continued Presence in the Mid-Size SUV Segment
Why the Honda Unicorn Is Trending in 2026