AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

Four Corporate AI Governance Gaps Partnership on AI Says Organizations Must Close Now

What happened

The Partnership on AI published Corporate AI Governance Matters Now More Than Ever on May 30, 2025, identifying four structural deficiencies it argues are present in most corporate AI governance programs. The four domains cited are supply chain responsibility, end-user terms and conditions, AI assurance ecosystems, and real-time monitoring of autonomous AI agents. The publication is global in scope and directed at enterprises that develop, procure, or integrate third-party AI components at scale. While it carries no binding legal force, it draws on documented incident data and emerging regulatory convergence across frameworks including the EU AI Act, ISO 42001, and the NIST AI RMF Playbook. The Partnership on AI is a recognized multi-stakeholder body whose membership includes major technology deployers and civil society organizations, giving the guidance significant practitioner weight.

Why it matters

  • ·Regulatory exposure is elevated because the four gaps identified by the Partnership on AI align directly with conformity obligations under the EU AI Act, DORA, and sector-specific guidance from bodies such as the Financial Stability Board, meaning organizations that have not closed these gaps may face scrutiny as enforcement mechanisms mature.
  • ·Operational impact is immediate for enterprises running agentic AI systems, as the guidance explicitly states that static model documentation and periodic audits are structurally inadequate to govern autonomous agents that execute code, access external data, and initiate transactions without per-action human approval.
  • ·Organizational risk is compounded by AI supply chain complexity, because a single deployed model may incorporate components from multiple upstream providers with distinct training data provenance and update cadences, creating accountability gaps that traditional IT vendor risk management frameworks were not designed to address.

Governance controls affected

What to do now

  • Re-examine your existing AI system inventory to confirm it captures agentic systems and AI components embedded in third-party software, as these are the categories most likely to be absent from prior classification exercises.
  • Audit third-party AI vendor contracts against supply chain responsibility criteria, specifically verifying that agreements require disclosure of upstream model components, training data sourcing practices, and incident notification obligations.
  • Review your agentic AI monitoring controls for implementation completeness, with particular attention to any agents granted tool access, API permissions, or the ability to initiate transactions without per-action human approval.
  • Begin scoping a standing AI assurance function as a continuous organizational capability rather than a project-level activity, defining required tooling, staffing, and reporting cadence.
  • Prioritize agent monitoring and supply chain gap remediation for operations in regulated industries such as financial services, healthcare, and critical infrastructure, given convergent regulatory expectations from DORA and the EU AI Act.

What to watch next

Compliance teams should monitor enforcement guidance from EU AI Act supervisory authorities as they begin operationalizing conformity assessment requirements that align with the continuous assurance model the Partnership on AI describes. Sector-specific signals from the Financial Stability Board and healthcare regulators regarding agentic AI oversight are expected to intensify through late 2025 and should be tracked for additional specificity on real-time monitoring obligations. Organizations should also watch for updated playbooks from NIST and ISO working groups that may translate the assurance ecosystem concept into auditable control frameworks, which would give the Partnership on AI guidance stronger procedural grounding in formal compliance programs.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-08-10

181,874 Meetings Exposed After tl;dv Ignored Six-Month Disclosure

A security researcher found that tl;dv, an AI meeting recording platform used by more than two million people, left its entire Firestore meetings database readable by any authenticated user due to a missing tenant isolation control. The exposure covered 181,874 meeting records across 84,312 users, including government agencies in 23 countries, universities, and corporations. The vulnerability was disclosed in January 2026 but remained unpatched as of July 2026, despite the company's published claims of SOC2, GDPR, and EU AI Act compliance.

Research2026-08-16

AI Credit Brokers Create a Silent Supply Chain Breach in Enterprise API Programs

Vectoral researcher Matt Lenhard has documented a functioning secondary market in which brokers purchase unused AI inference credits from startups and resell them at discounts of 30 to 80 percent through marketplaces, Telegram channels, and direct outreach. Buyers route their AI workloads through broker-controlled pools of provider API keys, bypassing direct contractual relationships with the underlying model providers. The arrangement exposes enterprise compliance programs to undisclosed data processing chains, unknown data residency, and potential violations of provider terms of service.

Corporate Policy2026-08-12

Anthropic's 'Project Panama' Exposes Training Data Sourcing as a Supply-Chain Risk

Reports from rare booksellers and a 2025 lawsuit have revealed that Anthropic ran a covert program called 'Project Panama' under which millions of print books were purchased and destroyed to extract training data. The accounts raise concerns about deceptive procurement, irreplaceable cultural loss, and undisclosed data sourcing practices. Enterprise compliance teams that rely on commercially-licensed AI models now face heightened exposure across training data provenance, vendor due diligence, and IP risk programs.