Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

AI governance is fast becoming an unmanageable chore

AI adoption in the enterprise is way up — and so too are IT leaders, into the night, dealing with the risks and governance issues of AI use.

To be sure, increasing attention to AI governance is a welcome addition to enterprise AI strategies, shifting an anything-goes approach toward risk-aware plans of action directed toward value. But it’s also taking an unspoken toll on those responsible — with the challenges of agentic AI mounting fast.

Not only are four in five senior business decision-makers, including CIOs, CISOs, and CDOs, using more of their day to manage AI risk, but their working hours are up 26% on average due to the issue, according to a new survey released by AI governance platform vendor OneTrust.

Contrast that to recent findings from Boston Consulting Group, which found that 42% of frontline employees who regularly use AI save nearly a full day of work each week, the majority of whom are given no guidance on what to do with that time saved, and you get an organizational picture of rampant activity, questionable direction, and lots of high-salaried time spent on cleanup and oversight.

Much of leaders’ extra time spent on managing AI risk is due to an increased awareness of AI risk and governance, IT leaders and industry observers say, but triage and other factors play a significant role as well.

For example, a third of respondents to OneTrust’s survey say they’ve seen employees use unapproved AI because approved tools or processes weren’t available quickly enough. Eighty-six percent have reported AI-related incidents, and over a quarter have experienced two or more incidents of AI systems taking unapproved actions.

However, as Blake Brannon, chief innovation officer at OneTrust, sees it, a huge part of the equation is AI adoption, with use skyrocketing.

“You’ve got the sheer volume and adoption of AI in organizations,” he says. “Whatever AI they were using at the beginning of the year, it’s probably more than 2x what they’re now looking at using inside the company, and that’s a compounding thing.”

Governing citizen coders and unsanctioned use

One key factor is increasing permission for non-IT employees to use AI to build their own apps, Brannon says. That move toward citizen development sparks a greater need for governance, he adds.

“We’re seeing exponential growth, not necessarily in different AI providers or tools, although that is growing, but the explosion of citizen builders and the new creativity that has been unlocked,” he says.

AI is creating new challenges for IT leaders as fast as they can understand them, he says, and the technology complicates risk management because of the speed at which it can make decisions and create problems.

“Security, compliance, risk management historically have just had to govern humans,” he says. “Humans were deterministic, and they moved at human speed.”

Viren Meghani, technical architect at Tata Consultancy Services, also sees IT leaders spending more time on AI governance and risk management than a year ago, but believes that’s largely related to shadow AI.

“Interestingly, this increase isn’t coming from overseeing the approved tools,” he says. “Instead, it’s all about chasing down the unapproved ones.”

Meghani believes employees’ urgency for AI solutions is a key factor. “People don’t wait around; they find a tool that works for them,” he says of unsanctioned AI use. “Then, governance has to scramble to put controls in place around something that was never properly evaluated.”

Spending more time on governance also doesn’t mean IT leaders are doing it correctly, he adds.

“Time spent reacting to incidents doesn’t equate to time spent on building effective controls,” he says. “If you’re busy investigating what an unapproved tool did, you’re not really governing; you’re just putting out fires.”

The organizations taking AI governance seriously invest time in architecture before deployment, using methods such as data lineage, model versioning, escalation paths, and audit trails, Meghani explains. “That kind of work might not grab headlines, but it’s what really helps to lower the number of incidents,” he adds.

Awareness isn’t readiness

Conal Gallagher, CIO and CISO at IT management software vendor Flexera, also believes taking governance seriously doesn’t mean organizations have achieved AI readiness.

“The risk surface of AI has expanded so quickly that the time designated to managing that risk continues to increase,” he notes. “Just one year ago, much of the focus was on enabling employees to experiment with AI, but now we’re seeing cases where autonomous agents create other agents and identify vulnerabilities at incredible speed.”

Governance is constantly playing catch-up to the changes happening with AI, Gallagher adds.

“Our IT team’s approach is to be judicious about which capabilities we put into employees’ hands and to slow deployment when we don’t understand the risk well enough,” he says. “We’re also applying established security principles to make sure agents don’t have greater access to capabilities than they actually need. The technology may be new, but some of the most important controls are still familiar ones.”

Anant Adya, EVP and head of Americas delivery at Infosys, says he’s spending more time managing AI risks now than a year ago, a natural shift, he adds, given the company’s move from experimentation to enterprise-scale adoption.

“While it does require additional attention, it is becoming embedded into our operating model rather than simply adding hours to the day,” he says of Infosys’ added emphasis on governance, security, privacy, compliance, and responsible AI practices.

That effort to operationalize governance and control is vital as the technology moves into core business workflows, Adya says, especially as agentic AI — what’s next — will only add another level of urgency.

“As these systems gain greater autonomy, they can access sensitive data, interact with other systems, and take actions on behalf of an organization,” he says. “Enterprises need strong identity controls, continuous monitoring, and appropriate human oversight.”

The struggle for good governance remains an issue for many organizations, but CIOs facing an overwork problem playing catch-up on AI governance are advised to get a handle on enforcing what matters before autonomous workflows compound the challenge.


Read More from This Article: AI governance is fast becoming an unmanageable chore
Source: News

Category: NewsSeptember 25, 2026
Tags: art

Post navigation

PreviousPrevious post:The wrong million tokensNextNext post:The AI transformation underway at Musinsa

Related posts

OpenAI wants you to use AI — but not to train its AI
September 25, 2026
Microsoft’s new Copilot unifies enterprise context for chat and code
September 25, 2026
Is your AI strategy creating “dark zombies”?
September 25, 2026
The wrong million tokens
September 25, 2026
The AI transformation underway at Musinsa
September 25, 2026
The SaaSpocalypse isn’t killing software spend
September 25, 2026
Recent Posts
  • OpenAI wants you to use AI — but not to train its AI
  • Microsoft’s new Copilot unifies enterprise context for chat and code
  • Is your AI strategy creating “dark zombies”?
  • The wrong million tokens
  • AI governance is fast becoming an unmanageable chore
Recent Comments
    Archives
    • September 2026
    • August 2026
    • July 2026
    • June 2026
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.