Discover more about

Umain Works

Thank you for your message!
We will be in touch shortly.
Oops! We couldn't send your message at this time. Please try again later.
AI Implementation & Execution

AI Governance is no longer optional.

Compliance proves your AI is safe. Governance proves it's under control. Only the third step proves it's worth what it costs.
Rúben Sousa
22 Jul 26
7
min read

The experiment is over

For most companies, AI began as an experiment. One team, one pilot, a model that worked well enough in a demo. Governing it was a good intention you could safely postpone, because the cost of postponing was close to zero.

That time is over. AI now runs at scale, and it has started to act on its own. We have agents that decide and execute, usually with access to sensitive data and systems. The moment AI touches real risk and real value, it stops being a technical detail and starts showing up in the P&L and in the company's reputation. It becomes a boardroom subject. And boards have begun to ask the uncomfortable question: what is all of this actually returning? "We're experimenting" no longer passes as an answer.

Regulation has stopped being a distant threat too. There are deadlines, obligations, and fines with serious numbers attached. And it is no longer only the regulator who bites. A regional court in Munich recently held Google responsible for what its AI Overviews said about two publishers, which the AI summaries wrongly tied to scams and "dubious business practices." The court did not reach for new AI legislation. It treated the AI's answer as Google's own words and applied the ordinary law on false and damaging statements. Google is appealing the decision, but the principle is already unsettling for anyone who puts an AI to speak in their name: the responsibility is yours, not your technology provider's.

This is the backdrop against which Gartner published its first-ever Magic Quadrant for AI Governance Platforms, and named IBM a Leader. A first Magic Quadrant is a signal in itself. It marks the moment a market stops being experimental and gains a reference point, which removes the last excuse from anyone still waiting for the field to get serious. IBM put it about as plainly as it can be put: "governance is no longer a future consideration, as responsible AI is now a business imperative." Gartner goes further, expecting AI governance to become "a requirement of all sovereign AI laws and regulations worldwide" by 2027.

You can't govern what you can't see

A soft shaft of daylight crossing an empty warm off-white space, revealing hundreds of tiny dust motes suspended in the air. Only two or three are in sharp focus, one of them glowing faint orange, while the rest are barely visible.
It was never hidden. It was only never looked for.

The most common warning sign is almost mundane. Companies do not know where their own AI is. Models and agents run inside teams that nobody has mapped, the shadow AI that never shows up on any inventory, and when someone finally asks for that inventory, few can produce it.

The real problem is not AI sitting still, waiting for approval. It is AI spreading everywhere while nobody can see where it lives, how much it is used, or what it produces. Adoption races ahead and governance trails behind, trying to catch up. From there it becomes a chain. What you can't see, you can't control. What you can't control, you can't justify. So when the board asks what all this AI is returning, there is no record connecting each use case to its value. The adoption numbers are missing, the cost numbers are missing, the return numbers are missing, and without them no answer holds.

It tends to break in two places first. In cost, which lands in the budget and cannot be explained case by case. And in the boardroom, when someone asks for the account, how many systems do we run, what do they do, what do they cost, what are they worth, and discovers it does not exist.

Why the foundation matters

A mature approach does not start from scratch. It starts from lineage. IBM did not treat AI governance as a brand-new island. It built it on the GRC principles that enterprises have trusted for years, which means AI risk comes to sit next to the rest of the company's risk instead of in a parallel silo nobody opens. Gartner points to the same foundation in its evaluation, noting that watsonx.governance "embeds IBM OpenPages GRC" and arrives with "prebuilt policy and control mappings" for the EU AI Act, the NIST AI RMF, and ISO/IEC 42001.

That answers the most paralysing question in the room, the one that stops programs before they begin: where do I start? The regulatory and standards mappings come ready, instead of asking every organisation to rebuild them from nothing. And the scope is not limited to models. It reaches applications and agents too, which is exactly where risk is now growing fastest.

There is a detail that is easy to miss. The progression IBM proposes is simple. First you see what you have. Then you bring it under control. Then you become able to answer for it. IBM itself treats that final step as a way to maximise the return on AI, not only to reduce its risk. For me, that settles an old argument. The value step is not a contrarian idea bolted on at the end. It is where the whole arc was always heading. It is also why we chose to build on this technology before the analysts blessed it, and why Gartner naming IBM a Leader confirmed a decision we had already made.

Alive, not filed

The line between governance that works and governance that does not is the line between measuring and documenting. Governance on paper is a single moment in time: a risk assessment done once, filed away, and never opened again until the next audit. Governance that works is alive. Every use case has an owner who answers for the outcome, a business case that keeps getting updated, and metrics followed in production, all in the same place.

Gartner draws the same distinction, describing traditional GRC tools as static repositories that behave "more like cloud-based spreadsheets" than live systems. The plain version is this. When governance is only a repository, it's dead weight. When it becomes the operating system of the AI program, it's what keeps the program standing.

The hard part is not where you think

Gartner names implementation effort as the main obstacle, and even cautions that IBM's model "requires significant implementation effort" and can mean "a longer time to value." I agree there is a hard part, but I think it is pointed at the wrong place. Seeing what you have and putting controls in place is the part that installs. It takes work, but technology and process get you there. The part that genuinely costs, and where almost everyone stumbles, is the next one: getting business owners to answer for the value of each use case instead of handing AI back to IT, and keeping that alive as new use cases arrive almost every week. That does not install. It is practised, every single day.

There is good news buried in that difficulty. Time to value shortens dramatically if you tie every control to a value metric on day one. The usual mistake is to handle compliance first and leave value for later. That "later" rarely comes.

Where to start

Before any list of steps, one change of sequence matters more than the rest. Governance has to enter at the beginning of each use case, as a requirement, not as a rubber stamp at the end. Requirements like fairness, security, privacy, data residency, and explainability translate directly into engineering specifications. Rebuilding an application later to make it compliant costs far more than building it correctly the first time. It is the same lesson Paulo drew about execution, that the hard part is structural, not technological.

After that, three steps. The first is the inventory, because you cannot govern or measure what you do not know exists, so you begin by seeing everything, shadow AI included. The second is to put risk and value on the same object, so each use case carries its risk classification, its controls, and its expected value metric side by side. The third is to operationalise with people rather than paperwork, which means continuous monitoring and a named owner who answers for the result, not a PDF in a folder. If I had to pick the single gesture that changes the outcome, it is the second one: tie a value metric to each use case at the very start.

This is the approach we bring to an organisation as IBM partners. Not a document to be admired, but a way to stand a governance program up on IBM's technology, and to hold that discipline of risk beside value from the first design conversation. The step almost nobody builds is the last one: an owner, a business case, and a value metric on every use case, living in the same record as the risk. That is the part we care about most.

The mistakes to avoid are the mirror image of all this. Treating governance as documentation, producing flawless reports that change nothing in the operation. Leaving it until the end, once AI is already everywhere, when standing it up early is precisely when it costs the least. Buying governance technology without the capacity to operate it, because a platform with no team and no discipline behind it is just an expensive shelf. And the subtlest mistake of all, the one fewest people notice: stopping at control. Proving your AI is safe, and never going on to prove it is worth what it costs.

Three steps, not one

A field of fine strokes gathered into three drifts of light climbing from lower left to upper right, labelled Compliance, Governance and Accountability. The lower two are grey and contained. A wide, nearly empty gap separates them from the third, which is warm orange, denser, and opens off the right edge of the frame.
The distance between the second step and the third is where most companies stop.

That last mistake is the whole point of this article. There are three steps, not one. Compliance builds the base. Governance builds the control. And only accountability turns that control into value. Most companies build a solid foundation and never climb the final step. They settle for the regulator's question, is this safe, and never reach the board's question, is this worth what it costs. What connects the two is the part that surprises people. That third step does not need a second platform. It stands on the same foundation the first two already forced you to build. This is how AI governance stopped being a conversation for the compliance officer and became one for the CEO and the CFO.

There is also a reason of timing that makes this urgent rather than merely philosophical. As agents multiply, AI consumption is about to explode. Goldman Sachs, in its 2026 research on the agentic economy, expects global AI token use to rise around 24 times by 2030. Because the price per token keeps falling while the invoices keep rising, everyone will rush to control cost. But controlling cost only answers how much we spend. It says nothing about what the spending is for, or whether it pays off. The value question, what each agent actually does and what it returns, is the one that will go unowned, and it is the only one you can answer from the same governance foundation. That, for me, is the next real theme. We have to stop managing AI by the invoice and start managing it by the value.

Compliance proves your AI is safe. Governance proves it's under control. Only the third step, an owner and a business case and a value metric on every use case, sitting in the same record as the risk, proves it's worth what it costs. Most companies built the foundation and never climbed the last step. That is where the value is.

Share this post
AI Governance
Responsible AI
EU AI Act
AI ROI
Executive Perspective

Start where it matters.

You’re under pressure to act, but clarity comes before tools.

That’s why we usually start with AI Value Discovery, a structured process to identify where AI creates measurable impact, before any solution is implemented.