ServicesVantageIndustriesCase StudiesInsightsAboutContactSchedule a Consultation
Home / Insights / AI Governance

Why AI Governance Is Becoming a Board-Level Issue

Regulators and customers are starting to ask how you govern the AI tools you’ve already adopted.

Two years ago, AI governance was a topic for a conference panel. Today it shows up in customer security questionnaires, in cyber insurance applications, and, in Texas, in a state law with an attorney general behind it. Boards that used to ask “what is our AI strategy?” are now being asked a harder question by the people who buy from them and regulate them: “how do you govern the AI you already use?”

Most mid-market companies cannot answer that yet. Here is why the question has arrived, and what a defensible answer looks like.

The tools are already in the building

The first thing every AI governance engagement finds is that adoption ran ahead of decisions. Sales is drafting proposals in a chatbot. Finance has a plugin summarizing contracts. Engineering has a coding assistant with access to the repository. Someone in HR is screening resumes with a tool nobody in leadership has evaluated.

None of that was approved in the sense of “a decision was made.” It was adopted, one license at a time, because the tools are useful. The governance problem is not stopping that; it is knowing what is in use, what data it touches, and who is accountable when it produces a bad outcome.

What changed: three sources of pressure

Customers. Enterprise procurement teams have added AI sections to their vendor questionnaires. If you sell to larger companies, you are being asked whether you use AI in delivering your service, whether customer data is used to train models, and what controls prevent that. “We’re not sure” is a losing answer in a competitive deal.

Regulators. Texas passed the Texas Responsible Artificial Intelligence Governance Act (TRAIGA, House Bill 149) in 2025, and it took effect January 1, 2026. It is narrower than early drafts, focusing on prohibited uses such as manipulation and unlawful discrimination, and it is enforced by the Texas Attorney General with a cure period before penalties. It also creates a safe-harbor style defense for organizations that follow a recognized framework such as the NIST AI Risk Management Framework. The practical message for a Texas company is that having a documented governance program is now the difference between a cure letter and an enforcement action. (Source: Texas H.B. 149, 89th Legislature.)

Boards and insurers. Directors are being told by their counsel that AI use is an oversight matter under the same duty-of-care reasoning that made cybersecurity a board topic. Cyber insurers are starting to ask about AI use in underwriting. Neither group wants a technical answer; they want evidence that management has a process.

What a defensible program looks like

The NIST AI Risk Management Framework, published in January 2023 and voluntary by design, organizes the work into four functions: Govern, Map, Measure, and Manage. You do not need to adopt it wholesale to benefit from the structure. For most mid-market companies the practical version is:

  1. Inventory. A list of the AI tools and features in use, what data each one can reach, and a business owner for each. This is the step most companies skip and the one every regulator and customer will ask about first.
  2. Acceptable use policy. Short, specific, and enforceable. Which categories of data may go into which categories of tool. What requires review before deployment. Who approves new tools.
  3. Risk tiers. Not every use case deserves the same scrutiny. Drafting a marketing email is low risk. Making decisions about people (hiring, credit, healthcare) is high risk and should get real review, because that is where both TRAIGA and federal anti-discrimination law bite.
  4. Vendor terms. Confirm, in writing, whether each vendor trains on your data, where it is processed, and how long it is retained. This is a contract review, not a technical one.
  5. Accountability. One named executive who owns the program and reports on it to the board on a schedule. That single sentence in the board minutes is worth more than most policy documents.

Where the vCISO fits

AI governance is not a standalone discipline. The controls that protect data going into an AI tool are the same identity, data classification, and vendor management controls a security program already needs. A company with a working security program can add AI governance in weeks. A company without one is going to discover that the AI policy has no foundation to stand on.

That is why we treat AI governance as part of the security leadership work rather than a separate project. The AI Risk Advisory engagement is the fast path to a program: inventory, policy, risk tiers, and a board briefing. If you already have a security leader, they can run it. If you do not, that is the more urgent gap.

A question to take to your next board meeting

“Can we produce, this week, a list of every AI tool in use across the company and what data each one can access?” If the answer is yes, you are ahead of most. If it is no, that is the first deliverable, and everything else follows from it.

If you want help getting there, schedule a consultation.

Related services

Where this comes up in our work.

AI Risk AdvisorySee the service →Virtual CISOSee the service →

More insights

This site