Skip to content
Layer 1The governance stack/ Enterprise

Enterprise Governance

Who is accountable for AI — and for which AI?

The operating model above every AI system: named accountability, an inventory of everything AI in the enterprise, risk-tiered intake, policy that maps to regulation, and the councils and escalation paths that make decisions stick. Every framework — NIST AI RMF, ISO/IEC 42001, the EU AI Act — starts here, because none of the other layers can work if nobody owns them.

The risk, in one line

Without named accountability and a live inventory, every other governance layer is theater.

Why leadership should care

  • Regulators now regulate AI users, not just AI builders: EU deployer duties, Korea's AI Basic Act, and US state transparency laws all attach obligations to enterprises that merely deploy AI.
  • Only 28% of organizations report CEO-level oversight of AI governance (McKinsey, 2025) — accountability gaps are the norm, and they surface in court: Air Canada was held liable for its own chatbot's invented policy.
  • Ungoverned adoption burns money as well as trust: 95% of GenAI pilots produced no measurable P&L impact (MIT, 2025), and Gartner expects over 40% of agentic projects canceled by end-2027.
28%
of organizations report CEO-level oversight of AI governance — McKinsey State of AI, 2025
Decisions only leadership can make
  • Who is the single accountable executive for AI, and what does the board see quarterly?
  • What is our AI risk appetite — which uses are encouraged, tolerated, and prohibited?
  • How fast must the governed path be, so teams choose it over going around it?
Risks concentrated at this layer
Read the claims right
RegulationEU AI Act (deployer duties, Art. 26)StandardISO/IEC 42001 AI management systemPracticeNIST AI RMF — GOVERNStandardISO/IEC 42005 impact assessment
In the room — discussion points

You cannot govern what you have not inventoried, and you have not governed what nobody owns.

  • Most AI governance programs fail at step zero: nobody can list their AI systems. Discovery plus a registry is the honest starting point.
  • Regulation now reaches deployers. Even if you build nothing, EU deployer duties, Korea's act, and US state laws already name you.
  • The fastest governed path wins. If review takes six weeks, your real AI estate is whatever shadow tools your teams adopted in week one.
  • Ask any vendor — including Google — where policy is enforced, not where it is written.
Questions to ask your organization
  • Who is your single accountable executive for AI today?
  • Could you produce a complete list of AI systems — including agents and AI embedded in SaaS — this week?
  • How long does it take a low-risk AI use case to get approved?
  • Which of your AI uses would the EU AI Act or your sector regulator call high-risk?
  • What evidence could you hand an auditor tomorrow that your controls actually ran?