ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

AI Talk: From pilots to production - governing AI that's already in your organisation 

On 9 June 2026, AI Talk host Kevin Craine was joined by Nick Mullen, Governance, Risk, and Compliance Manager, Mutual of Omaha; Michael R. Clarke, Founding Principal, Jaeger-Plymouth Advisors, LLC; Benjamin Benhan, General Counsel - Privacy, Cybersecurity, Artificial Intelligence, Office of the Los Angeles City Attorney; and Stuart Merry, Head of AI Strategy & Enablement, LRN. 

Views on news 

Ninety percent of enterprises are actively adopting AI agents, according to a survey by Kong, and 79% of enterprises expect full-scale adoption of agentic AI in the next three years. However, there’s still a bottleneck: keeping agents governed and secure.  Real AI governance is about control: who can build agents, what data they can access, what gets released to production and how you track everything once it’s running.

 

A practical eight-layer framework of must-haves for any CIO looking to govern and scale AI includes strong AI governance combining role-based access control, version control, environment isolation, approval workflows, identity management and interface security to ensure only authorized users can build, access and deploy agents while limiting agents to the data and systems they need.

 

Meanwhile, comprehensive observability and audit logs provide full visibility into agent activity, enabling organizations to detect issues, meet compliance requirements, investigate incidents and quickly roll back unwanted changes. Agentic AI adoption requires evidence-based trust and a shift from traditional to authority governance frameworks.  

 

Tackling shadow AI and extending GRC to generative and agentic AI 

Close to half of all employees use their own personal, unsanctioned and mostly non-enterprise level AI systems. Therefore, the first step to transparent AI use is to establish who use AI and for what workflows. It’s even more of a problem that employees will run their pilots and proof-of-concept with ungoverned shadow AI, using the company’s proprietary data and IP in unsanctioned systems. Those experimenting with AI also need a disruptive mindset to avoid building AI solutions on top of old processes. Human oversight is also key for evaluating pilot projects to see their real value and to assess whether they’re worth scaling. AI outputs must also be continuously validated and hallucinations detected.  

 

Upscaling AI systems usually comes with compliance challenges against a patchwork of regulatory regimes across the globe. Vendor injected AI is another concern. Businesses must have some visibility of what data processing takes place in their vendors’ workflows, as well as of their retention policies and decision support systems. Vendors’ shadow AI use can further complicate the visibility challenge. Individuals must be accountable for the decisions that agentic systems make and there should always be an option to switch the system off if it goes off rail.

 

Monitoring and internal auditing plans must be extended to cover who is liable for AI agents’ mistakes, where human supervision can be supported with supervisor AI agents. From a legal perspective, there are three fundamental questions to ask: what data went into the AI, what decisions and actions were based on the outcome of the data analysis and who approved that decision.  

 

In data governance, there is always a data owner, and this should be extended to AI agent-powered use cases too.  Data owners should be experts on leveraging data for a given use case and be able to understand how the AI model behaves and what the associated risks are. As guardrails won’t cover each and every scenario, it’s key that individuals within the organisation understand the company culture, the ethical approach of the company to AI use and have the right literacy training in AI regulation to make the right decisions and calls if an AI agent misbehaves.

 

When applied to AI, some governance models are more likely to fail than others. If governance and GRC frameworks are incapable of managing the risk that generative or agentic AI poses, technology can help to upgrade the current system. However, it’s important that all functions using that technology are consulted prior to the procurement of any new technology.  

 

What compliance will be interested in is whether responsible AI is part of the business’s operating model, if the business has a cross-functional governance body, a use case inventory, a risk tiering rubric and whether it has performed an impact assessment. For companies operating in the EU, it’s also crucial how they categorise risk and what risk categories their activities fall into.  All AI regulatory frameworks have requirements on visibility, data governance, AI policies and vendor onboarding.  

 

The panel’s advice 

  • To be compliant, you must have your evidentiary artifacts in hand to showcase with confidence that you’ve gone through the steps necessary to mitigate risks.  
  • Use existing frameworks, don’t reinvent the wheel.  
  • The GRC function should also find use cases for gen AI and agentic AI deployments.  
  • Map out the top ten risks AI is introducing to your organisation. Then scope out the control coverage to control those risks. With effective prompts, even non-experts can utilised AI to identify and quantify risks. Although not a solution by itself, it can give you a good idea of where to start. 
  • Frameworks such as the NIST AI RMF – one of the most mature ones – as well as NIST CSF, NIST 800-53 and 800-171will provide you with the blueprint that you can follow to meet audit requirements when regulators knock on your door. From a data governance and management perspective ISO 38505 have been the most recommended by panellists. 
Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543