On 9 June 2026, AI Talk host Kevin Craine was joined by Nick Mullen, Governance, Risk, and Compliance Manager, Mutual of Omaha; Michael R. Clarke, Founding Principal, Jaeger-Plymouth Advisors, LLC; Benjamin Benhan, General Counsel - Privacy, Cybersecurity, Artificial Intelligence, Office of the Los Angeles City Attorney; and Stuart Merry, Head of AI Strategy & Enablement, LRN.
Views on news
Ninety percent of enterprises are actively adopting AI agents, according to a survey by Kong, and 79% of enterprises expect full-scale adoption of agentic AI in the next three years. However, there’s still a bottleneck: keeping agents governed and secure. Real AI governance is about control: who can build agents, what data they can access, what gets released to production and how you track everything once it’s running.
A practical eight-layer framework of must-haves for any CIO looking to govern and scale AI includes strong AI governance combining role-based access control, version control, environment isolation, approval workflows, identity management and interface security to ensure only authorized users can build, access and deploy agents while limiting agents to the data and systems they need.
Meanwhile, comprehensive observability and audit logs provide full visibility into agent activity, enabling organizations to detect issues, meet compliance requirements, investigate incidents and quickly roll back unwanted changes. Agentic AI adoption requires evidence-based trust and a shift from traditional to authority governance frameworks.
Tackling shadow AI and extending GRC to generative and agentic AI
Close to half of all employees use their own personal, unsanctioned and mostly non-enterprise level AI systems. Therefore, the first step to transparent AI use is to establish who use AI and for what workflows. It’s even more of a problem that employees will run their pilots and proof-of-concept with ungoverned shadow AI, using the company’s proprietary data and IP in unsanctioned systems. Those experimenting with AI also need a disruptive mindset to avoid building AI solutions on top of old processes. Human oversight is also key for evaluating pilot projects to see their real value and to assess whether they’re worth scaling. AI outputs must also be continuously validated and hallucinations detected.
Upscaling AI systems usually comes with compliance challenges against a patchwork of regulatory regimes across the globe. Vendor injected AI is another concern. Businesses must have some visibility of what data processing takes place in their vendors’ workflows, as well as of their retention policies and decision support systems. Vendors’ shadow AI use can further complicate the visibility challenge. Individuals must be accountable for the decisions that agentic systems make and there should always be an option to switch the system off if it goes off rail.
Monitoring and internal auditing plans must be extended to cover who is liable for AI agents’ mistakes, where human supervision can be supported with supervisor AI agents. From a legal perspective, there are three fundamental questions to ask: what data went into the AI, what decisions and actions were based on the outcome of the data analysis and who approved that decision.
In data governance, there is always a data owner, and this should be extended to AI agent-powered use cases too. Data owners should be experts on leveraging data for a given use case and be able to understand how the AI model behaves and what the associated risks are. As guardrails won’t cover each and every scenario, it’s key that individuals within the organisation understand the company culture, the ethical approach of the company to AI use and have the right literacy training in AI regulation to make the right decisions and calls if an AI agent misbehaves.
When applied to AI, some governance models are more likely to fail than others. If governance and GRC frameworks are incapable of managing the risk that generative or agentic AI poses, technology can help to upgrade the current system. However, it’s important that all functions using that technology are consulted prior to the procurement of any new technology.
What compliance will be interested in is whether responsible AI is part of the business’s operating model, if the business has a cross-functional governance body, a use case inventory, a risk tiering rubric and whether it has performed an impact assessment. For companies operating in the EU, it’s also crucial how they categorise risk and what risk categories their activities fall into. All AI regulatory frameworks have requirements on visibility, data governance, AI policies and vendor onboarding.
The panel’s advice


© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543