ITRADE works with STEM organizations to close Technology, Talent, & Security gaps. See how →
A director in operations wires a model into a workflow on a Thursday afternoon, because a vendor made it a checkbox. Legal doesn't hear about it. Security doesn't hear about it. The AI policy sits in a shared drive with a version number, untouched.
That gap has a number. The American Arbitration Association surveyed 500 senior legal and executive leaders at large U.S. and Canadian organizations: 87% say they have AI governance in place. 22% say it works (AAA, "From Principles to Practice," May 2026). The breaks cluster in escalation, audit readiness, and how late legal gets pulled in.
The clock already started. EU AI Act enforcement began 2 August 2026 - prohibited practices, Article 50 transparency, AI literacy, general-purpose AI models - with Annex III high-risk rules landing 2 December 2027 (European Commission, AI Act Service Desk). Vendor contracts signed last year mostly don't account for it.
And the systems moved faster than the oversight. IBM's Institute for Business Value, with Oxford Economics, surveyed 2,000 CIOs and CTOs across 33 geographies and 19 industries in Q1 2026: 77% say AI adoption is outpacing their governance, enterprises averaged 54 AI agent incidents in twelve months, 37% of those caused data exposure or a breach, and 11% consider themselves prepared for the agent scale coming this year (IBM IBV 2026 Tech Leader Study). Breach math followed - nearly $5M average, up 12%, with AI-driven attacks up 56% and adding about $1M each (IBM, Cost of a Data Breach Report 2026).
The layer nobody's securing
Almost every AI security control on the market - MITRE ATLAS, OWASP Top 10 for LLMs - guards the model after it ships. The decision that created the risk happened months earlier, when someone picked the data, the vendor, and the use case with no gate in front of them. That is the layer the NIST AI Risk Management Framework governs: four functions - Govern, Map, Measure, Manage - applied to design, development, use, and evaluation, released January 26, 2023, now in revision under the White House AI Action Plan, with a Critical Infrastructure Profile concept note out April 7, 2026 (NIST).
The gap is widest where nobody's looking
Read the coverage and the RMF looks industrial. In practice the exposure is worst where AI arrived through a SaaS renewal instead of a capital project. The same three questions apply everywhere it shows up: which decision does the model influence, who owns that decision today, and what happens when it's wrong.
In healthcare, ambient scribing, triage assist, and prior-auth automation arrived without a gate; the RMF forces you to name whose PHI trains it, who overrides it, and what gets logged.
In logistics, routing, forecasting, and exception handling raise a blunter question: what happens when the model is confidently wrong at scale.
In financial and back-office functions, underwriting, claims, collections, and service now need explainability a regulator will accept.
In public sector and education, eligibility screening, admissions, and casework triage need someone accountable when an individual is affected.
In energy and manufacturing, predictive maintenance, quality, and process control need a defined loop the model can touch, under whose authority.
Buyers are asking too
ISO/IEC 42001, the AI management system standard, had roughly 350 certified organizations worldwide by spring 2026 (assembled from certification-body and company announcements; no official global register exists) - small enough that it still wins deals, growing fast enough that it won't for long.
What to do Monday
Inventory before policy. Every AI system in production, including what shipped inside tools you already bought. If it takes more than a week to list, that's your finding.
One named owner per system. Escalation is where governance breaks, and escalation requires a person who answers the page.
Map each system to a decision - who makes it today, what the override path is.
Audit non-human identities. Agent credentials and service accounts with production access are the surface most programs leave outside identity governance. Fewer than half of organizations secure them (IBM, 2026).
Pick your pairing and set a date. RMF for structure, 42001 if procurement is asking, EU AI Act if you have European exposure.
|
The decision that created the risk happened months earlier, when someone picked the data, the vendor, and the use case with no gate in front of them.
Total investment: one hour with the right people in the room. Cost of skipping it: the audit you can't pass.
Bianca architects the systems most leaders buy in pieces - talent, technology, and security, designed to work as one.
