AI Insights

Governance in AI: More Than Just Compliance

Effective AI governance goes beyond compliance, and the evidence from 2025 and 2026 shows that the organizations scaling AI fastest treat governance as an operating capability.

  • Only 26 percent of enterprises say governance keeps pace with AI deployment
  • High levels of shadow AI can add $670,000 to average breach costs
  • Strong AI governance requires runtime controls, auditability, and named ownership
  • HITL works when oversight is risk-tiered and supported by machine-enforced constraints
  • Standards like ISO 27001, ISO 42001, SOC 2, GDPR, and RBI FREE-AI anchor long-term control
By Rejith Krishnan8 min read
Abstract wireframe governance wave in magenta on navy with checkpoint gates and one green approval ring.

Research report, Governed autonomy

Governance in AI: More Than Just Compliance

For CISOs and security leaders, 13 September 2026, 9 minute read

Effective AI governance goes beyond compliance, ensuring data integrity, security, and ethical AI deployment in enterprises. The evidence from 2025 and 2026 is that the organizations scaling AI fastest are the ones that treated governance as an operating capability, not a paperwork exercise.

26%of enterprises say governance keeps pace with AI deployment
$670Kadded to average breach cost by high levels of shadow AI
97%of AI-breached organizations lacked AI access controls

Sources: Smarsh and FTI Consulting, 2026; IBM Cost of a Data Breach Report, 2025.

1. The Governance Gap in AI Deployments

AI adoption has outrun the controls around it, and the pattern repeats across every major survey. In the 2026 Enterprise AI Trends Study from Smarsh and FTI Consulting, only 26% of enterprises said their governance practices were keeping pace with AI deployment. Most are shipping faster than they are supervising.

The confidence gap is as serious as the control gap. Grant Thornton's 2026 AI Impact Survey of 2,500 US business leaders found that 78% lacked strong confidence they could pass an independent AI governance audit within 90 days.

The cost of that gap is now measurable. IBM's 2025 Cost of a Data Breach Report, produced with the Ponemon Institute, found that high levels of shadow AI, meaning unapproved AI tools adopted without security sign-off, added an extra $670,000 to the average breach. Among organizations that suffered an AI-related security incident, 97% lacked proper AI access controls, and 63% had no AI governance policy at all.

The oversights follow a pattern a CISO will recognize. No inventory of the AI actually in use, including AI embedded in vendor products. No access controls between models, agents, and sensitive data. No audit trail of what an AI system did or why. And no tested containment: Kiteworks' 2026 annual survey of 459 security and compliance professionals found 79% operating without a tested kill switch for AI systems.

Shadow AI is now one of the three costliest breach factors IBM tracks. The gap is not a tooling problem. It is an accountability problem.

2. Building a Comprehensive AI Governance Framework

A compliance checklist is not a framework. The useful reference point is ISO/IEC 42001, published in December 2023 as the first international standard for an AI management system. It follows the same Plan-Do-Check-Act structure as ISO 27001 and adds Annex A controls for AI-specific risks such as bias, transparency, accountability, and data governance. Whether or not certification is the goal, its shape is the right one: governance as a system that runs continuously, not a policy that gets reviewed annually.

In practice, a framework that ensures both compliance and operational integrity covers seven elements:

  • A complete inventory of AI systems, including AI embedded in vendor products
  • Risk-tiered classification that decides how much oversight each use case gets
  • Data governance covering lineage, quality, and access controls on training and retrieval data
  • Model lifecycle controls: validation, adversarial testing, change management, drift monitoring
  • Runtime observability with an audit trail for every action an AI system takes
  • Incident response that includes a tested kill switch, not an assumed one
  • Named ownership: board visibility, an accountable executive, and a cross-functional review body

The hard part is the distance between claiming and running these controls. In research cited by Deloitte, 87% of executives said their organizations have AI governance frameworks, yet fewer than 25% had fully operationalized them. Governance that lives in a document fails quietly. It has to be enforced where AI executes, at the point of action, with evidence generated as a side effect of normal operation.

3. Role of HITL in Governed Autonomy

Human-in-the-loop is the control that turns autonomy into governed autonomy: a qualified person, with context and the authority to intervene, embedded at defined decision points in an AI workflow. It is also a regulatory requirement. Article 14 of the EU AI Act and NIST's AI Risk Management Framework both call for human oversight that is demonstrable, not implied.

Weak HITL is a generic review prompt that someone clicks through. Strong HITL is risk-tiered: automation thresholds that decide which actions proceed unattended, structured escalation paths for the rest, and documented override records that stand up in an audit. The difference matters more as agents replace assistants. Deloitte research finds close to three quarters of companies plan to deploy agentic AI within two years, while only 21% report a mature model for governing agents.

Agents chain actions at machine speed, so a human cannot review every step. The workable model pairs machine-enforced constraints at runtime, such as policy checks on tool use and data access, with humans as the escalation tier for high-consequence decisions: moving money, changing production systems, touching regulated data. Reviewers need training on what to approve and when to escalate. Presence in the loop is not the same as practice.

Governed autonomy means the system can prove who approved what, and when. Autonomy without that proof is just risk moving faster.

4. Compliance Standards: ISO 27001, SOC 2, GDPR, RBI

Model technology churns quarterly. Governance frameworks do not, which is what makes them worth investing in: the standards below have stayed stable anchors while the AI stack underneath them changed. Map internal controls to them once, then reuse that fabric for every audit, customer questionnaire, and regulator conversation.

ISO 27001 and ISO 42001

ISO 27001 remains the security baseline every AI system inherits. ISO 42001 extends the same management-system structure to AI itself. Because the two share structure, holding 27001 typically cuts the 42001 effort by a third to a half, and 42001 certificates are already held by AWS, Anthropic, and Microsoft.

SOC 2

The attestation enterprise buyers ask of every AI vendor. A SOC 2 report gives independent evidence that security, availability, and confidentiality controls operate as described. For AI deployments the scope question is the one to press: whether model pipelines, retrieval stores, and agent infrastructure sit inside the audited boundary.

GDPR and the EU AI Act

AI systems mishandling personal data expose the enterprise to GDPR penalties of up to EUR 20 million or 4% of worldwide turnover. The AI Act's transparency obligations became enforceable on 2 August 2026, and the Digital Omnibus deferred most high-risk system obligations to 2 December 2027. The deferral is preparation time, not a reprieve.

RBI FREE-AI

The Reserve Bank of India's FREE-AI framework, released 13 August 2025, sets out 26 recommendations across six pillars under seven guiding principles. It is advisory today, but it signals what supervisors of regulated financial entities will expect, and it echoes the direction regulators in Singapore and the EU are already taking.

5. Case Study: Successful Governance Implementation

Singapore's DBS Bank is the clearest public example of governance as an enabler rather than a brake. Since 2019 it has run every AI use case through its Responsible Data Use framework, which asks three questions in order. Can we use the data, covering security, privacy, access, and quality. Should we use it, judged against the PURE principles: Purposeful, Unsurprising, Respectful, Explainable. And how do we use it, through risk-based model governance with materiality assessments, an AI registry, and senior management accountability.

The structure is what makes it work. A Group Responsible Data Use Committee provides oversight, the Chief Data Office owns the frameworks, and a cross-functional Responsible AI Taskforce adds controls as generative AI use cases scale. The results are documented: the framework sustains trust in more than 800 AI/ML models, and DBS used it to roll out over 20 generative AI use cases in a single year. The bank projects AI/ML will contribute SGD 1 billion to revenue over five years.

DBS did not scale AI despite governance. It scaled because governance answered the questions its competitors were still debating.

Where lowtouch.ai fits

Everything above describes controls that have to live where AI executes. That is the design principle behind lowtouch.ai: governed AI agents that run air-gapped on-prem or in a private cloud, so data never leaves the perimeter, with policy checks and a full audit trail on every action an agent takes. Human-in-the-loop approval gates cover high-consequence decisions, and ISO 27001, SOC 2, and GDPR controls are in place from day one. Deployments reach production in four to six weeks.

Book a demo

Sources

  1. Smarsh and FTI Consulting, 2026 Enterprise AI Trends Study, July 2026.
  2. Grant Thornton, 2026 AI Impact Survey, early 2026.
  3. IBM and Ponemon Institute, Cost of a Data Breach Report 2025.
  4. Kiteworks, Data Security and Compliance Risk: 2026 Annual Survey Report, July 2026.
  5. ISO, ISO/IEC 42001:2023, AI management systems.
  6. Deloitte, ISO 42001 Standard for AI Governance and Risk Management.
  7. Konfirmity, ISO 42001: The AI Management System Standard, 2026.
  8. Strata, Human-in-the-Loop: A 2026 Guide to AI Oversight, May 2026.
  9. Optro, AI governance stats for 2026 (citing Deloitte), May 2026.
  10. Norton Rose Fulbright Data Protection Report, The EU AI Act: when does it become enforceable now?, July 2026.
  11. Covington, EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions, May 2026.
  12. Legal Nodes, EU AI Act 2026 Updates, April 2026.
  13. Chambers and Partners, A Framework for Using AI in the Indian Financial Sector, 2025.
  14. Scrut, Exploring RBI's FREE-AI, 2026.
  15. DBS Bank, Ethical and Responsible AI in Banking.
  16. Celent, DBS: Ethical GenAI at Scale.
  17. DBS Bank, DBS' AI-Powered Digital Transformation.

Build grounded agents

Build agents that reason inside your business logic

See how lowtouch.ai turns enterprise rules, policies, and semantic context into governed agents running inside your appliance.

About the Author

Rejith Krishnan

Rejith Krishnan

Founder and CEO

Rejith Krishnan is the Founder and CEO of lowtouch.ai, a platform dedicated to empowering enterprises with private, no-code AI agents. With expertise in Site Reliability Engineering (SRE), Kubernetes, and AI systems architecture, he is passionate about simplifying the adoption of AI-driven automation to transform business operations.

Rejith specializes in deploying Large Language Models (LLMs) and building intelligent agents that automate workflows, enhance customer experiences, and optimize IT processes, all while ensuring data privacy and security. His mission is to help businesses unlock the full potential of enterprise AI with seamless, scalable, and secure solutions that fit their unique needs.

LinkedIn →