AI is no longer a future consideration. It is already embedded across operations, from customer interaction and compliance monitoring to software development and decision support. Yet as adoption accelerates, organizations face a more fundamental challenge: how to deploy AI safely, at scale, and have confidence in the results.
Many organizations are adopting AI faster than their governance, data and control environments can support. This creates visibility gaps that delay decisions and weaken confidence in controls, echoing risks long associated with spreadsheets and end-user computing (EUC) adoption.
Trustworthy AI is not simply the result of better models. It is the result of better conditions around those models. Without governance and visibility, even advanced systems become difficult to control. When data is weak, AI can produce confident outputs built on unreliable foundations.
The organizations that will lead in AI are not those with the largest budgets, the most models or the most ambitious pilots. Instead, they will be those that create conditions for AI to be used responsibly, consistently and sustainably. They will focus their investments on use cases that generate measurable business value.
Three pillars matter most: governance, shadow AI management and data discipline.
1. Governance: The architecture of accountability
The first pillar is governance. To address the need for AI oversight, leading organizations are now developing policies, forming committees, establishing principles and launching internal task forces. These are important first steps, but they’re not enough on their own.
AI governance becomes effective only when it establishes clear accountability. Key accountability questions include the following:
- Who owns the AI system?
- Who is responsible for its performance?
- Who approves its use?
- Who monitors it after deployment?
- Who challenges whether the output is appropriate?
- Who is accountable for remediation when something goes wrong?
It’s common for a business team to own the use case, while IT manages the platform. Data teams might be responsible for the underlying datasets. Oversight roles can span compliance, risk, legal and cybersecurity. Vendors could supply the model or infrastructure. As a result, many people are involved, but accountability for the final outcome is not always clearly defined.
This accountability gap is one of the most important risks in enterprise AI.
A well-designed governance framework should provide a clear path to responsible AI adoption by defining decision rights, approval pathways, risk classifications, minimum controls and escalation triggers. In practical terms, this starts with an AI inventory, named ownership for material use cases, risk-tiering and minimum control requirements that vary according to the level of impact.
Findings from Protiviti’s AI Pulse Survey 2026: Shadow AI & Cyber Risk Insights also indicate that organizations with formal AI governance frameworks report stronger visibility and greater confidence in their controls.
The key is proportionality. Not every AI use case carries the same risk. A tool used to summarize internal meeting notes should not require the same level of scrutiny as AI used to support credit decisions, financial crime monitoring or customer-impacting decisions. Effective governance allows organizations to distinguish between low-risk and higher-risk use cases, applying stronger controls where the potential impact is greater.
AI governance may require dedicated intake, review and oversight mechanisms, including the board and the organization as a whole treating AI as a standing governance priority, particularly while adoption remains emerging and fragmented. But these mechanisms should connect into existing risk, compliance, technology, data, third-party and assurance frameworks rather than becoming a permanent parallel structure.
2. Shadow AI: The risk you cannot see
The second pillar is shadow AI; this term refers to the use of AI tools by employees or business units without formal approval, oversight or integration into the organization’s control environment. In many ways, it is the next evolution of spreadsheet and EUC risk: business-led technology adoption that solves actual problems but creates control gaps when it becomes embedded without ownership, validation or monitoring. This can include employees using personal generative AI accounts, business teams adopting unapproved software-as-a-service (SaaS) tools or developers experimenting with open-source models.
This behavior is usually not driven by bad intentions. Employees are often trying to work faster, solve problems or improve productivity. When approved enterprise tools are too slow, too restrictive or unavailable, they find alternatives.
The problem is that unmanaged AI use can create significant risks. Employees may enter confidential information, client data or proprietary code into tools without understanding how that information is stored, processed or used. Without proper vetting, third-party dependencies can emerge, particularly as AI becomes integrated into less visible SaaS and vendor tools.
A general prohibition is not the answer. Blocking AI tools without providing viable alternatives often drives usage further underground. A better response is to make responsible AI use easier than misuse by offering approved tools, clear rules, fast approvals, controlled testing environments and practical employee education.
Discovery is therefore a critical capability. Organizations need tools and processes that allow them to detect where AI is being used, by whom, for what purpose and at what level of scale. This is particularly important where something initially developed for personal use as a productivity accelerator starts to be adopted by wider teams or used more extensively in business processes. Discovery helps identify when teams are becoming overly reliant on AI solutions that may be delivering value but remain little more than working prototypes.
3. Data: The foundation AI cannot fix
Data is the third pillar. AI does not fix poor data. It amplifies it. If the underlying data is incomplete, biased, outdated or poorly governed, the AI output may appear sophisticated while resting on unreliable foundations.
Many organizations have complex legacy environments, inconsistent data ownership, and data sitting across multiple systems with different definitions, quality standards and access controls. Lineage may be incomplete. Consent and legal bases for AI-related use may not be clearly documented.
For AI to be trusted, organizations need to know what data is being used, where it came from, whether it is appropriate for the use case and whether it meets defined quality standards. This does not mean that every organization must complete a multiyear data transformation before deploying AI. That is unrealistic. The practical starting point is not enterprisewide data perfection. Instead, organizations should confirm that the data supporting priority AI use cases is owned, traceable, lawful, sufficiently complete and fit for purpose.
Protiviti’s AI Pulse Survey 2025: How Data Confidence Drives AI ROI confirms this point: Progress with AI closely correlates with the quality and management of data, and as organizations mature, their data practices become more structured and intentional.
A more pragmatic approach is to focus on priority use cases. Organizations should identify the AI initiatives with the greatest business value, assess the specific data requirements for those use cases and address the most important data gaps in parallel with controlled pilots.
Manage three pillars together, not in isolation
The three pillars are structurally connected and should be managed as one integrated program. The mistake many organizations make is to treat governance, shadow AI and data as separate issues.
Governance without shadow AI visibility risks governing only the official AI estate while missing the tools already being used across the business. Governance without data discipline creates policies around systems whose inputs may not be trusted. Shadow AI discovery without a governance framework leaves organizations with a list of risks but no clear mechanism to assess, approve, restrict or remediate them.
The lesson from spreadsheet and EUC risk is clear: Once business-critical tools become embedded without visibility, ownership or controls, remediation becomes harder. AI raises the same challenge, but at greater speed and scale. The organizations that lead will be those that create the conditions for responsible adoption before fragmented experimentation evolves into embedded risk.
Toby Steindler, a senior manager with Protiviti’s risk and compliance practice in Zurich, contributed to the article.
This blog is part of a series on AI governance. In the next post, we will examine the first pillar in more detail: what effective AI governance looks like in practice, why accountability is still being underbuilt and how organizations can create governance structures that enable responsible adoption rather than slow it down.


