4.8.2026
André Hellemeier
Table of contents
Governance gets a bit of a bad rep on the whole. It's one of the least-loved disciplines, even though it's one of the most critical areas in AI.
Let's be honest: the moment someone adds AI governance to the agenda, people start rolling their eyes:
"Yes, we know we have to do it somehow. But let's keep the effort to a minimum."
And yet from the studies we've looked at (more on those later), one thing is clear: Organizations that ignore governance and treat it as a box-ticking exercise increase the risk of paying the price later.
So, what exactly is AI governance, and why is it actually a much more interesting topic than most people think?
What is AI governance?
AI governance is the framework of policies, roles, processes, and responsibilities that ensures AI systems are deployed responsibly, transparently, and in compliance with applicable regulations.
It answers questions such as:
-
Who owns an AI system or model?
-
Who decides which AI models may be used?
-
Who ensures regulatory requirements and internal policies are followed?
-
How is everything documented when regulators come knocking?
It sounds like a lot because it is. Not only does AI governance cover a wide range of topics, but it also requires someone with a broad understanding of multiple disciplines and the experience to connect them effectively.
AI governance sits at the intersection of business, technology, law, and ethics. It brings these perspectives together and embeds them into the organization through clear responsibilities, consistent processes, and long-term accountability.
One lesson I've learned: If governance is treated as just another project or another software tool, you might as well save the investment and hope nothing goes wrong. Maybe you'll get lucky. But if you don't, the costs will be significantly higher.
So why does nobody want to do it?
Truthfully, AI governance combines the traits of several roles that, even individually, aren't exactly the life of the party.
-
The detail-oriented specialist: AI governance requires an understanding of regulatory frameworks (EU AI Act, NIST AI Risk Management Framework (NIST AI RMF), GDPR implications), as well as a grasp of technical model risks and organizational structures. It takes a strong communicator with a big-picture view. Most teams don't have this expertise bundled in one place. And when they do, it is rarely listened to because it sounds too complex.
-
The rule-maker: The one who sets the boundaries, writes policies, defines processes, conducts training. This is the thankless work behind the scenes. Nobody celebrates the person who designed the review process for AI use cases; usually, it's just seen as "extra work." But everyone complains when it's missing.
-
The warner who has to say "no": "This model cannot go live like this." "The data quality is not sufficient." "We need an impact assessment before we proceed." This doesn't make them popular, especially not with business teams who are under time pressure and want to deploy yesterday rather than today.
This combination of specialized expertise, rulemaking, and warning makes AI governance a task that requires leadership that everyone needs, but nobody volunteers for. A survey by Diligent shows that 61% of compliance teams are already reporting regulatory burnout. It’s hardly surprising, then, that governance is often put off.
What happens if you ignore it?
What happens if you ignore it anyway? The short version: It can get expensive.
-
According to a recent Informatica study (2026), three out of four companies admit that their governance hasn’t kept pace with the speed of their AI adoption.
-
McKinsey’s State of AI Trust in 2026 report shows that only about one third of organizations have reached a maturity level of 3 or higher (out of 5) in strategy and governance. The technology is racing ahead, while the guardrails are still in the drafting stage.
-
The consequences are real: 99% of companies surveyed in the Swiss Cyber Institute Report reported financial losses due to AI-related risks, with 64% of those losses exceeding $1 million. More than half (58%) of executives identify a lack of governance systems as the main reason AI projects do not go into production.
-
80% of companies have 50+ GenAI use cases in the pipeline, but only a handful are live. The Stanford AI Index documented 233 harmful AI-related incidents in 2024, a 56% increase over the previous year. And from hallucinating chatbots to AI-powered fraud: Reputational risks are no longer just a theoretical concern.
-
The conclusion of Deloitte’s State of AI in the Enterprise 2026 report is clear: Companies where senior leadership is actively involved in AI governance achieve significantly greater business value than those that leave the matter solely to technical teams.
Why is governance actually hot as hell?
Companies that invest in governance early on get to production faster because they have fewer product recalls, fewer compliance crises, and less rework. Governance is therefore a strategic asset, not a tactical measure.
McKinsey s hows that investments in Responsible AI correlate strongly with higher maturity levels and realized business value. According to IBM, organizations with a Chief AI Officer have a roughly 10% higher return on AI investment. This isn’t because of yet another leadership position filled by someone with years of experience, but rather because of a clearly structured approach and well-defined accountability.
The market is desperately seeking these people: 26% of organizations now have a CAIO, up from 11% two years ago. Among FTSE 100 companies, the figure is as high as 48%, with 65% of these appointments having been made in the last two years. IAPP reports that 68% of privacy professionals have already taken on AI governance tasks.
Regulatory requirements make this inevitable. The EU AI Act has been in effect since August 2024 and will be phased in gradually throughout 2026. Inventories, roles, documentation, training, and monitoring structures can't be established overnight, so those who start now will have a head start. Those who wait will struggle with falling behind and time pressure.
Investments are on the rise. According to Informatica, 86% of companies plan to increase their data management investments in 2026, with a clear focus on privacy, security, and governance.
AI governance is no longer a niche topic. It is the arena where it is decided whether AI will scale within the company or get stuck.
Where to start: The role every organization needs
Before we get into tools and frameworks, we need a person. Someone who takes responsibility for the topic, drives it forward, and keeps everything on track. Let’s call this role the AI Governance Coordinator, AI Representative, or AI Officer, depending on the size of the company.
This person must not only be thoroughly familiar with the EU AI Act, GDPR, and industry-specific requirements, but also possess strong communication skills to translate these complex concepts for the various target audiences within the company, in addition to solid regulatory expertise. They also need to have a basic technical understanding of how AI models work, what data quality means in the context of AI, and where the typical risks lie.
Organizational and communication skills are important too. Governance means building structures, aligning stakeholders, and establishing processes. At its core, this is change management. They need to be able to communicate just as effectively with board execs as with developers.
And finally, they need a good dose of pragmatism: governance must work in everyday practice, not just exist on paper in an audit file. This brings us to the topic of operationalization, which is often underestimated. And it explains why governance is often nothing more than a paper tiger. Those who build structures also need the expertise, the drive, and the resources to implement them.
Should the Chief Data Officer also lead AI governance?
In many organizations, the Chief Data Officer (CDO) is a natural starting point for AI governance, because they're often already dealing with governance, risk management, compliance, and cross-functional coordination. Plus, they're used to establishing the type of structures that work across organizational boundaries.
That said, our experience shows that AI governance quickly becomes much bigger than a data function. You'd be surprised at how quickly questions around legal requirements, security, procurement, HR, IT, risk management, and business ownership emerge.
AI governance cannot realistically be owned by a single department in the long run.
This perspective is also reflected in research conducted with 23 global CDOs. One of the most frequently recommended approaches is establishing an AI Governance Steering Committee that brings together relevant stakeholders and shares responsibility across the organization.
So, to summarise:
-
Just start somewhere.
-
Don’t wait for the perfect setup.
-
A CDO can successfully initiate and sponsor the topic.
-
Over time, establish a governance structure that distributes responsibility more broadly...
-
And appoint a person to coordinate and drive the topic.
How FELD M can help
Whether you're just starting your AI governance journey or looking to strengthen an existing governance function, FELD M supports you where it matters most.
Data & AI strategy
Together, we identify your biggest opportunities and integrate governance into your overall AI and data strategy.Governance framework design
From defining roles and responsibilities to developing policies and operational governance processes, we build frameworks that work in practice, not just on paper.AI literacy & training
From introductory prompt engineering sessions to comprehensive AI literacy programs, we prepare your teams to use AI responsibly and effectively.Technical implementation
As both a consulting and implementation partner, we support the full AI lifecycle from data infrastructure and data quality to production-ready AI solutions.Privacy & compliance
Our experts ensure your AI initiatives comply with GDPR, the EU AI Act, and industry-specific regulatory requirements.
What to do next
- Start with a reality check: How many AI initiatives are currently running in your company, and how many of them are being transparently and regularly reported on and monitored? If the answer is "few to none," you're not alone. But it is time to change that.
- Next, identify the right person: Who could take on the responsibility for governance? And what does this person need to succeed?
- And then: Let's talk.
AI governance is the discipline that determines whether your AI investments create lasting business value or simply accumulate risk.
And perhaps that's why the people willing to take ownership of it are the real heroes of AI transformation.