AI Governance Institute
← AI Governance Playbook

Question 48 of 52

What are the biggest AI governance challenges, and how do we address them?

By Cody Maxwell · AI Governance Institute · August 2026

The recurring obstacles that stall AI governance programs — shadow AI, jurisdictional patchwork, nominal versus real oversight, and resourcing gaps — and the sequencing that gets past each one.

If you only do 3 things, do this:

  1. 1.Shadow AI is the challenge underneath every other challenge. You cannot govern, classify, or report on systems you do not know exist, so discovery has to come before any framework work.
  2. 2.Most governance failures are not missing policy, they are policy that was never technically enforced. Audit whether your human-oversight and approval-gate controls can actually be bypassed, not just whether they are documented.
  3. 3.Do not wait for a mature framework before starting. Sequence the highest-risk gap first and add controls incrementally, since AI capabilities and regulation both move faster than most programs can fully catch up to.

The Situation

Who this is for: Compliance leads, CISOs, and governance program owners who feel behind on AI governance and need to prioritize where to focus first

When you need this: When starting a program, when a board or regulator asks what your biggest AI risks are, or when an incident reveals a gap you thought was covered

The Decision

Which of the common AI governance obstacles are actually blocking your program today, and in what order should you address them?

The Steps

  1. 1Run a shadow AI discovery pass: vendor contract review, employee survey, and network-level audit for unauthorized API traffic to model providers
  2. 2Audit every control you believe is in place to confirm it is technically enforced, not just described in policy — start with human-oversight and approval-gate controls
  3. 3Map which regulations apply to which systems by jurisdiction, rather than assuming one framework covers everything
  4. 4Identify where AI governance ownership is unclear or split across Legal, Risk, and IT, and resolve it explicitly
  5. 5Assess whether your team has the technical literacy to evaluate model behavior, not just draft policy
  6. 6Set a recurring cadence for revisiting your control set as new regulations, enforcement actions, and incidents emerge

The Artifacts

  • Governance obstacle assessment (checklist mapping each common challenge to your current program status)
  • Control enforcement audit template (documented control vs. technically verified control)
  • Jurisdictional applicability matrix (system × jurisdiction × applicable regulation)
  • Governance ownership gap log

The Output

A prioritized list of governance obstacles specific to your organization, each mapped to a concrete remediation step and an owner, replacing a vague sense of being behind with a sequenced plan.

Shadow AI: you cannot govern what you cannot see

The most common AI governance challenge is not a regulatory one, it is a visibility one. Employees adopt AI tools through personal accounts, vendors embed AI features into existing software without flagging it, and departments subscribe to tools outside procurement's normal review. Every governance activity that follows, from risk classification to regulatory mapping, depends on first knowing what AI systems are actually in use.

Discovery has to combine multiple methods because no single one is complete. A vendor contract review catches AI features embedded in approved software. An employee survey, ideally offering amnesty for undisclosed tool use, surfaces adoption that never went through procurement. A network-level audit for outbound traffic to known model provider API endpoints catches what neither of the first two methods will admit to. Programs that skip this step end up governing a fraction of their actual AI footprint.

Controls that exist on paper but not in practice

A second recurring challenge is the gap between documented controls and enforced ones. A human-oversight checkpoint that a bug or a misconfiguration can bypass is not a control, it is a description of intent. Real incidents illustrate this precisely: a content-moderation system whose human-review step could be technically skipped let automated bans reach thousands of users before anyone caught it, and a pre-production approval gate that existed procedurally but was not backed by documented accuracy thresholds let an inventory system reach production before its failure modes were understood.

The fix is to audit control enforcement, not just control documentation. For every control listed in a governance policy, ask whether the system can currently operate as if that control did not exist, and if so, treat that as an active gap rather than a paper compliance item.

The jurisdictional patchwork problem

No single AI law covers all obligations for most organizations. The EU AI Act, a growing list of US state statutes, sector-specific guidance, and international voluntary frameworks all apply differently depending on where users are located, what sector the system operates in, and what kind of decisions it makes. Treating one framework as sufficient coverage is a common and consequential mistake.

The practical response is a jurisdictional applicability matrix: for every AI system, document which regulations plausibly apply based on user geography and use case, then track that mapping as both your system inventory and the regulatory landscape change. This turns an abstract "the law keeps changing" problem into a concrete, maintainable document.

Ownership ambiguity and resourcing gaps

AI governance without a clear owner defaults to no governance. When responsibility is split across Legal, Risk, and IT without an explicit division of labor, risk assessments do not happen, vendor reviews get skipped, and no one owns the decision to pause a deployment when something looks wrong. Resourcing compounds this: many compliance teams are being asked to govern AI without the technical literacy to evaluate what a model is actually doing, which pushes governance toward policy work disconnected from the systems it is meant to control.

Neither problem has a universal fix, but both need to be named explicitly rather than left implicit. Document which function owns which governance activity, and treat technical AI literacy as a training investment for the compliance function itself, not something outsourced entirely to engineering.

Governing something that keeps changing

AI capabilities, deployment patterns, and the regulatory response to both are moving faster than most governance programs can fully absorb. A control set that was adequate for last year's AI deployments may not address agentic systems that take autonomous action, and a compliance posture that was defensible six months ago may have gaps today simply because a new enforcement action redefined what "adequate" oversight looks like.

Programs that treat their control set as a living document, revisited on a recurring cadence rather than set once and left alone, handle this better than programs that wait for a mature, finished framework before acting. Waiting for certainty is itself a governance risk in a domain that has not stopped moving.

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →

More guidance like this, every week

New playbook articles, governance controls, and the regulatory changes driving them. Every Thursday.

Powered by Buttondown.