ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

Building success with AI through effective governance

AI’s legal pitfalls are rarely about technology, argues Daniel Stangu at Intellias; they’re governance and implementation failures

There’s a consistent pattern emerging across organisations: when artificial intelligence (AI) programmes run into legal or regulatory trouble, the root cause is almost never the model itself. It’s not the accuracy, architecture, or the vendor. The real failures tend to emerge from more familiar ground – in governance, in data handling, and in unclear ownership.

 

Companies tend to fixate on the technology, and that’s only natural. But the issues that ultimately trigger legal exposure are the same ones that’ve tripped up businesses for decades: poor controls, weak accountability and a lack of clarity about how systems should be used in the first place.

 

In other words: the most significant AI risks facing businesses today are not technical failures. They’re governance failures, disguised as technical ones.

 

 

Governance gaps create preventable AI failures

Even as AI adoption accelerates, governance maturity has not kept pace. Research suggests that fewer than half of organisations have a formal AI governance policy in place, and the outcome is predictable – exposure around data protection, transparency, and accountability.

 

In real-world deployments, the same issues surface again and again: employees pasting sensitive data into public AI tools because no guardrails exist; AI systems influencing decisions in hiring, pricing, or service eligibility without documentation or human oversight, and organisations deploying AI without recording how outputs were generated or validated.

 

And then there’s shadow AI – another growing concern. When official tools or policies are missing, teams often reach for consumer tools that “just work”. We see this frequently in our work with organisations: inconsistent data environments, disconnected workflows, and missing enterprise-grade alternatives create the perfect conditions for unmanaged AI use.

 

So from a legal point of view, the issue doesn’t lie in ChatGPT or any other tool. The issue is actually in the vacuum around it: a lack of rules on data usage, no logging, no auditability, and no accountability.

 

The risks become even more serious when AI starts to influence high-impact or regulated decisions. Governance professionals are already raising the alarms – 74% of UK governance leaders say they are worried about the accuracy of AI-generated content on corporate reporting, according to research from The Chartered Governance Institute UK & Ireland (CGIUKI). A strong signal that oversight is lagging behind adoption.

 

 

“We didn’t build it” is not a defence

One of the most common misconceptions is that the responsibility for AI risks lies primarily with the vendor. Many organisations assume that if they are using an off-the-shelf-product - whether a chatbot, analytics platform or AI assistant - the legal responsibility sits with the provider.

 

It doesn’t.

 

A simple principle to follow is this: providers are responsible for the product, deployers are responsible for its use.

 

Developers and vendors must ensure their systems meet technical, security and documentation standards. They are responsible for building tools that are robust, secure and, where necessary, regulatory-ready.

 

But once the tool enters your environment, the accountability shifts.

 

The deploying organisation is entirely responsible for what data goes into the system, who can access it, what decisions the AI is allowed to influence, how inputs are validated, and how incidents are detected, escalated, and resolved.

 

Contracts may allocate commercial risk between parties, but they rarely remove statutory obligations. Under frameworks such as UK GDPR and emerging AI governance guidance, organisations remain accountable for how personal data is processed and how automated decisions affect individuals.

 

So when something goes wrong, “We didn’t build it” won’t hold up. Not in court, not with regulators, and not with customers.

 

 

Compliance doesn’t slow AI down – it enables it

It’s easy to assume that compliance teams are blockers to progress – slowing innovation by adding more rules and more oversight.

 

But the opposite is true. The organisations that scale AI the fastest are the ones that build governance into the deployment process from day one.

 

And it should all begin with visibility. Companies need a clear inventory of where AI is being used across the organisation – the tools deployed, the data flowing through it, and the processes it touches. Without all of this, governance is based on nothing more than guesswork.

 

It’s from there that organisations can adopt a risk-tiered model, because not every AI application needs the same level of control. For example, a summarisation assistant and an automated lending model carry fundamentally different stakes. Risk-tiering ensures that governance measures remain proportionate rather than burdensome.

 

Practical guardrails also play a crucial role in reducing shadow AI. This can include approved AI tools, clear “do not enter” rules for sensitive data, logging of AI interactions, and documented validation workflows.

 

And because modern AI is deeply interwoven with external providers, organisations must harden third-party governance. Contracts should reflect how data is handled, retained, audited, and protected, all aligned with how AI is actually used, not just how it’s described.,

 

The goal is not to slow teams down with bureaucracy. It’s to create a foundation that enables innovation to move quickly without exposing the organisation.

 

 

Governance is the true AI infrastructure

AI is often framed as a technological revolution, and in many ways, it is. But for businesses, the real transformation is organisational.

 

Organisational success is not determined by the most advanced models – focussing only on the technology risks missing the bigger challenge. Successful organisations build strong data governance, clear ownership structures, auditable processes, unified architecture, and a culture that understands and manages its tools.

 

When these core elements are aligned, AI becomes scalable, safe and sustainable.

 

Because when legal problems arise, they are rarely rooted in the algorithm, but in the operating model around it.

 


 

Daniel Stangu is Senior VP, Head of Digital Solutions Office at Intellias

 

Main image courtesy of iStockPhoto.com and Shinsei Motions

Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543