1. Biggest governance challenges before scaling Generative AI
The biggest challenge is not the technology itself—it is establishing clear accountability and control at enterprise scale. Organizations need to know which AI systems are being used, for what purpose, what data they consume, what decisions they influence, who owns the risk, and how performance will be monitored throughout the lifecycle.
I would focus on six fundamentals: an enterprise AI inventory; risk-based classification of use cases; clear business and technology ownership; data/privacy/security controls; independent validation and monitoring; and strong third-party AI governance.
Generative AI further presents risks including hallucinations, data leakage, exposure of intellectual property, inconsistent model behavior, and the rapid evolution of third-party models. NIST’s Generative AI Profile underscores the importance of managing these risks across the full AI lifecycle, rather than relying solely on controls implemented at the point of deployment.
From a quality perspective, I would treat AI like any mission-critical product: define requirements, establish acceptance criteria, verify performance, maintain traceability, monitor production behavior, and continuously improve.
2. Balancing AI innovation and AI risk
I don’t see innovation and governance as opposing forces. Good governance should accelerate safe innovation rather than become an approval bureaucracy.
The answer is a risk-based approach. A low-risk productivity assistant should not go through the same governance process as an AI system influencing engineering decisions, customer commitments, safety, recruitment, finance, or regulatory compliance.
I would establish three broad lanes:
• Experiment: controlled sandbox, approved datasets and tools, rapid experimentation.
• Scale: formal validation, security/privacy review, measurable business value and operational ownership.
• High-impact AI: stronger independent assurance, human oversight, explainability, auditability and executive risk acceptance.
This allows teams to innovate quickly within predefined guardrails. NIST’s AI RMF similarly structures AI risk management around governance and lifecycle activities rather than prescribing one control level for every use case.
The principle I would use is: move fast on experimentation but raise the quality gate as the impact of the AI decision increases.
3. Role of boards and executive leadership
The board should not be reviewing individual models. Its responsibility is to ensure that management has established an appropriate AI risk appetite, accountability model and assurance mechanism.
Executive leadership should answer some very fundamental questions: What decisions are we comfortable delegating to AI? Where must humans remain accountable? Which risks are unacceptable? How will incidents reach executive attention? How do we know AI is actually improving customer and business outcomes?
Where organizations often struggle is moving from policy to operating discipline. Having an AI committee or responsible-AI principles is not enough. Governance needs measurable controls, accountable owners, reporting mechanisms and evidence that those controls actually work.
International frameworks increasingly emphasize exactly these principles—transparency, robustness, safety and accountability—and ISO/IEC 42001 provides a management-system approach for continuously governing AI across an organization.
For boards, therefore, the conversation should evolve from “How much AI are we adopting?” to “How much value are we creating, at what risk, and how do we know our controls are effective?”
4. Compliance without losing agility
Organizations should avoid building separate governance processes for every new regulation. Instead, build a common AI control framework once and map regulatory requirements onto it.
Practically, I would establish an AI regulatory radar, maintain an enterprise AI inventory, classify systems by risk, conduct AI impact assessments where appropriate, maintain model/data documentation and decision traceability, establish vendor requirements, test controls periodically, and retain evidence for audit or regulatory review.
This is particularly important now. In the EU, major AI Act provisions became applicable on 2 August 2026, including transparency obligations for certain AI systems, while enforcement powers also became applicable from that date. The regulatory implementation schedule contains specific exceptions and transitional provisions, so organizations operating in Europe need use-case-level applicability assessments rather than assuming every AI system has identical obligations.
The key is compliance by design: integrate these checks into architecture, development, procurement and release processes instead of performing a compliance review just before go-live.
5. Most overlooked AI risks
Hallucination and bias receive considerable attention, but I believe some of the more underestimated enterprise risks are third-party AI, shadow AI and automation bias.
Employees may send sensitive information into unapproved AI tools. SaaS applications can introduce embedded AI capabilities without an organization realizing that its AI footprint has changed. Vendors can update models underneath an enterprise solution. And perhaps most importantly, people may gradually stop challenging AI recommendations simply because the system appears consistently confident.
I would therefore manage AI across five dimensions: data, model, application, human and supplier risk.
Controls should include approved AI platforms, data classification and DLP controls, adversarial and scenario-based testing, grounding and retrieval controls where appropriate, human-in-the-loop requirements for consequential decisions, output verification, monitoring for model or performance drift, vendor contractual requirements, and clear incident-response procedures.
NIST’s GenAI guidance explicitly recognizes a broad set of risks beyond accuracy alone, reinforcing the need for lifecycle controls rather than treating hallucination as the sole GenAI problem.
A particularly important quality principle is: never confuse fluent output with verified output.
6. How technology governance changes with AI-powered decision-making
A strong response from a transformation-leadership perspective would be:
My approach has evolved from governing technology delivery to governing technology outcomes. Traditional governance focused heavily on architecture, cybersecurity, schedule, cost, availability and change management. Those remain important, but AI introduces another dimension: the behavior of the system itself can change depending on data, context, prompts and model versions.
Therefore, governance cannot end at production release. We need continuous assurance—monitoring accuracy, reliability, security, user behavior and business outcomes throughout the AI lifecycle.
From a quality perspective, I increasingly see governance moving from periodic checkpoints toward continuous quality engineering: clear requirements, risk-based validation, traceability, production monitoring, feedback loops and corrective action.
And for AI-assisted decision-making, I believe accountability must remain very clear: AI may recommend or assist, but accountability for important business outcomes cannot become ambiguous.
That lifecycle approach is consistent with both NIST’s AI RMF and ISO/IEC 42001’s emphasis on continuously managing and improving AI governance rather than treating it as a one-time certification exercise.
7. Advice to CIOs, CISOs and technology leaders
My advice would be: don’t start with an AI strategy; start with a business and customer-value strategy and determine where AI can materially improve it.
Then build responsible AI into the engineering system rather than creating a separate governance layer around it. Establish common platforms, reusable guardrails, approved models, standardized evaluation methods and automated controls so development teams don’t have to reinvent governance for every AI use case.
I would keep five questions visible at executive level:
Are we creating measurable value? Can we trust the output? Can we protect the data? Can we explain and audit what happened? Do we know who is accountable when something goes wrong?
If organizations can answer those questions consistently, responsible AI becomes an enabler of transformation rather than a constraint on transformation.
The strongest organizations will not necessarily be those that deploy AI fastest. They will be those that can scale AI repeatedly while maintaining customer trust, quality, security and accountability. Frameworks such as NIST AI RMF and ISO/IEC 42001 increasingly provide practical structures for institutionalizing that capability.
A strong closing statement for the discussion
“AI governance should not be designed to prevent organizations from taking risk. It should enable them to take the right risks deliberately, with clear accountability and measurable controls. In the end, responsible AI is fundamentally a quality issue: delivering the intended outcome consistently, safely and with the trust of the customer.”

