惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

小众软件
小众软件
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
博客园 - 【当耐特】
博客园_首页
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Apple Machine Learning Research
Apple Machine Learning Research
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
量子位
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tailwind CSS Blog
IT之家
IT之家
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
V
Visual Studio Blog
F
Fortinet All Blogs
Martin Fowler
Martin Fowler

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
What AI Governance Can Learn From The Data Governance Era
Vinod Bijlani · 2026-05-29 · via Forbes - Innovation

Vinod Bijlani is an AI practice leader at Hewlett Packard Enterprise.

getty

Every enterprise I speak with has the same story. AI initiatives in flight, promising pilots in the works, ambitions to deploy at scale and somewhere in the middle of it all, a growing recognition that the organization does not yet have the governance infrastructure to manage what it is building.

I have spent the last year studying how the world's most AI-mature organizationsparticularly in financial services, where the regulatory and reputational consequences of getting it wrong are highest—have gone about defining and operationalizing their AI governance strategies. What I found was not a story about compliance. It was a story I had seen before, in a different context.

It looked exactly like what happened with data governance a decade ago, and the parallels are too instructive to ignore.

AI Governance Is Having Its Data Governance Moment

In the early 2010s, enterprises were sitting on vast lakes of customer data, transaction records and operational signals. The promise was enormous. The reality was chaos: duplicate records, inconsistent definitions, no clear ownership and regulators beginning to circle. The organizations that paused to build data governance frameworks before scaling their data programs were the ones that eventually monetized that data with confidence. AI is at exactly that inflection point. And the first crisis, just like in the data era, is visibility. In the data world, nobody knew where all the data lived, who owned it or whether two systems using the term "customer" meant the same thing.

AI has the same sprawl problem, only faster and with higher stakes. According to McKinsey's 2025 State of AI report, 88% of organizations are now using AI in at least one business function, yet only 1% consider their AI strategies mature. Models are being deployed by individual teams, vendors are embedding AI into SaaS tools without announcement and agentic systems are autonomously accessing data and executing actions that nobody has formally approved.

The answer, just as it was with data, starts with knowing what you have. An AI inventory often called an AI Card is the governance equivalent of the data catalog: a continuously refreshed record of every model, agent and pipeline in production, with its risk tier, data classification, owner, compliance tags and deployment scope attached. You cannot govern what you cannot see. This has always been true for data. It is true for AI.

What The Leading Organizations Built

The enterprises I studied are heavily regulated institutions where the cost of ungoverned AI is concrete, and it shows up in regulatory action, customer harm or very public reversals.

Commonwealth Bank of Australia (CBA) became the first Australian bank to publish a comprehensive report on how it ideates, develops, deploys and manages AI at an organizational level. CBA's AI Governance model is anchored in six principles—fairness, transparency, privacy and data protection, reliability and security, environmental and social and accountability—embedded directly into its Code of Conduct and operationalized. CBA established a dedicated AI governance forum and had engaged over 27,600 employees in AI literacy training. The governance was not bolted on after deployment. It was the deployment condition.​

JPMorgan Chase established an Explainable AI Center of Excellence, a firm-wide model risk governance function and a C-suite AI governance council that mandates transparency, human-in-the-loop oversight and regulatory alignment before any model reaches production. With over 450 agentic AI use cases deployed and its internal LLM suite in daily use by more than 230,000 employees, JPMorgan earned the No. 1 global AI maturity ranking in the 2025 Evident AI Index.

The Three Layers Of A Functioning AI Governance Strategy

Across these organizations, the same architectural pattern emerged, one that mirrors how mature data governance programs are structured and maps directly to Gartner's AI TRiSM framework for AI trust risk and security management.

Layer 1 - Discovery And Inventory: AI Governance begins with the AI inventory. Every model, agent and pipeline—including shadow AI deployed without central oversight—needs to be discovered, classified by risk tier, assigned an owner and tagged against applicable regulatory frameworks. This is not a one-time audit. It is a living, continuously refreshed record. The diagnostic question is simple: can you list every AI system running in your organization right now? If the answer is uncertain, that is where AI Governance starts.

Layer 2 - Runtime Policy Enforcement: Data governance matured when organizations moved from reactive data quality fixes to proactive controls built into pipelines. AI governance is undergoing the same shift. Enforcement needs to operate at the point of all AI interactions, detecting prompt injection, scanning outputs for sensitive data before delivery, sandboxing agentic systems to enforce least-privilege access and generating tamper-proof audit trails in real time. Gartner projects that enterprises embedding runtime AI governance controls will reduce regulatory compliance costs by 20%, the same efficiency logic that made automated data quality controls a standard investment a decade ago.

Layer 3 - Compliance, Audit And Policy Lifecycle: Mature data governance programs produce continuous lineage and evidence trails that satisfy auditors without heroic manual effort. AI Governance needs the same capability—automated evidence collection mapped to frameworks like the NIST AI Risk Management Framework, the EU AI Act and ISO 42001, paired with dashboards that surface AI risk posture, policy drift and incident trends continuously. This is what converts AI governance from a periodic review into an operating discipline, the same transition data governance made when it moved from compliance project to core infrastructure.

The Window To Build Proactively Is Narrowing

Data governance took most enterprises a decade to get right, and those that started late paid the price in fines, remediation costs and lost competitive ground. The trajectory for AI governance is compressing. Gartner forecasts that fragmented AI regulation will grow fourfold, covering 75% of the world's economies and driving over $1 billion in total compliance spend by 2030. The organizations building AI governance now as infrastructure, not as a compliance reaction, will not be caught rebuilding their foundations when that regulatory wave arrives.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?