Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It

Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.

AI Cybersecurity

AI governance, once the purview of the legal department, is now knocking on the CEO’s door. But many C-Suite executives are still treating it as something to delay addressing until after AI regulations are set in stone. This can be a shortsighted strategy. Consider that 46% of organizations say AI governance and compliance issues are the reason why their AI underperforms, according to the GrantThornton, 2026 AI Impact Survey Report (PDF). These figures lend credence to why leadership should not wait for AI regulations to settle but should apply governance proactively.

AI governance demands urgent leadership oversight because of three converging forces:

  •  Internal AI-safe use policies are falling behind AI adoption. Tools are being used in day-to-day decisions faster than most organizations can define rules for how they should be used.
  • The regulatory environment is fragmented. Some U.S. states are experimenting with their own frameworks; federal action is slow, and major regions such as Europe are taking different approaches.
  • The threat landscape today includes geopolitical tensions, which means state-sponsored actors are leveraging reputational threats such as deepfakes and AI-generated disinformation at scale.

Why Waiting Isn’t a Good Idea

Leaders waiting for a stable set of rules to build an AI-driven security posture is a bad idea. But clarity is not coming any time soon. More than 1,100 AI bills were introduced by State legislatures last year, of which 130 have been enacted into law. This means different laws are vying for your attention. Rather than getting lost in the complex maze of regulations that are pulling in different directions, the focus should be on building resilience instead.

An example of why leadership oversight cannot remain passive is the use of a general-purpose AI tool for sensitive legal conversations or guidance. This use does not come under the ambit of legal privilege. In case of dispute, any information entered into these tools is fully discoverable. So, what might seem like a harmless shortcut, where a person is asking an AI assistant for legal advice, instead of a lawyer, can quickly undo the protection that an organization assumes it has. It’s a small example of a bigger problem. Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.

Regulations as they stand today are not future proof. AI use cases and adoption are evolving quickly, and therefore, specific rules can become redundant. Therefore, AI governance must be underpinned by adaptable frameworks.

What Leadership Ownership Looks Like

Advertisement. Scroll to continue reading.

Owning AI governance is not about predicting a regulation, but about building three essential capabilities:

  • Getting visibility into specific exposure

AI risk is not consistent across different organizations. A healthcare company managing sensitive personal data has a different risk profile than a logistics firm. A company neck-deep in developing AI products faces different challenges than one that uses AI to improve operations. Leadership must have a clear picture of the data it works with, which of that data feeds into or is processed by AI systems, and which state-, federal-, and sector-specific rules actually apply to its use of AI. They also need visibility into what happens in case of exposure. Whether this will result in financial loss, a regulatory fine, reputational damage, a lawsuit, or all four.

  •  Building a Flexible Governance Framework

Compliance is not something you can set and forget. Compliance plans are not everlasting in their efficacy. The focus should be on building structural resilience that endures over time. Make use of AI-assisted monitoring tools. These will help track regulatory and threat developments across jurisdictions. They can flag a new rule or a threat, ensuring that leadership is not caught off guard. Resilience also means the ability to adapt internal processes with updated AI and data policies, as per the information flagged by your monitoring tools.

  • Rehearsing Incident Response

A crisis scenario, such as a cyberattack, data exposure, or even a disinformation campaign, needs an effective response. Ideally, organizations should simulate such a real-world crisis to practice the necessary response procedures. This enables them to react in a planned and coordinated manner that protects operations and restores trust, which is absolutely critical within the first hours of a security incident.

Final Thoughts

AI governance belongs at the executive level because only they can balance technical capability, commercial risk, and regulatory compliance into a unified strategy. In the AI era, the advantage will not belong to organizations that wait for regulatory clarity. It will favor those that proactively embed risk visibility, adaptive governance, and rehearsed crisis readiness into their operations before a disruptive event forces their hand.

RelatedRethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer

RelatedGemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Written By

Steve Durbin is Chief Executive of the Information Security Forum, an independent association dedicated to investigating, clarifying, and resolving key issues in information security and risk management by developing best practice methodologies, processes, and solutions that meet the business needs of its members. ISF membership comprises the Fortune 500 and Forbes 2000.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.