AI adoption in the enterprise is way up — and so too are IT leaders, into the night, dealing with the risks and governance issues of AI use.
To be sure, increasing attention to AI governance is a welcome addition to enterprise AI strategies, shifting an anything-goes approach toward risk-aware plans of action directed toward value. But it’s also taking an unspoken toll on those responsible — with the challenges of agentic AI mounting fast.
Not only are four in five senior business decision-makers, including CIOs, CISOs, and CDOs, using more of their day to manage AI risk, but their working hours are up 26% on average due to the issue, according to a new survey released by AI governance platform vendor OneTrust.
Contrast that to recent findings from Boston Consulting Group, which found that 42% of frontline employees who regularly use AI save nearly a full day of work each week, the majority of whom are given no guidance on what to do with that time saved, and you get an organizational picture of rampant activity, questionable direction, and lots of high-salaried time spent on cleanup and oversight.
Much of leaders’ extra time spent on managing AI risk is due to an increased awareness of AI risk and governance, IT leaders and industry observers say, but triage and other factors play a significant role as well.
For example, a third of respondents to OneTrust’s survey say they’ve seen employees use unapproved AI because approved tools or processes weren’t available quickly enough. Eighty-six percent have reported AI-related incidents, and over a quarter have experienced two or more incidents of AI systems taking unapproved actions.
However, as Blake Brannon, chief innovation officer at OneTrust, sees it, a huge part of the equation is AI adoption, with use skyrocketing.
“You’ve got the sheer volume and adoption of AI in organizations,” he says. “Whatever AI they were using at the beginning of the year, it’s probably more than 2x what they’re now looking at using inside the company, and that’s a compounding thing.”
Governing citizen coders and unsanctioned use
One key factor is increasing permission for non-IT employees to use AI to build their own apps, Brannon says. That move toward citizen development sparks a greater need for governance, he adds.
“We’re seeing exponential growth, not necessarily in different AI providers or tools, although that is growing, but the explosion of citizen builders and the new creativity that has been unlocked,” he says.
AI is creating new challenges for IT leaders as fast as they can understand them, he says, and the technology complicates risk management because of the speed at which it can make decisions and create problems.
“Security, compliance, risk management historically have just had to govern humans,” he says. “Humans were deterministic, and they moved at human speed.”
Viren Meghani, technical architect at Tata Consultancy Services, also sees IT leaders spending more time on AI governance and risk management than a year ago, but believes that’s largely related to shadow AI.
“Interestingly, this increase isn’t coming from overseeing the approved tools,” he says. “Instead, it’s all about chasing down the unapproved ones.”
Meghani believes employees’ urgency for AI solutions is a key factor. “People don’t wait around; they find a tool that works for them,” he says of unsanctioned AI use. “Then, governance has to scramble to put controls in place around something that was never properly evaluated.”
Spending more time on governance also doesn’t mean IT leaders are doing it correctly, he adds.
“Time spent reacting to incidents doesn’t equate to time spent on building effective controls,” he says. “If you’re busy investigating what an unapproved tool did, you’re not really governing; you’re just putting out fires.”
The organizations taking AI governance seriously invest time in architecture before deployment, using methods such as data lineage, model versioning, escalation paths, and audit trails, Meghani explains. “That kind of work might not grab headlines, but it’s what really helps to lower the number of incidents,” he adds.
Awareness isn’t readiness
Conal Gallagher, CIO and CISO at IT management software vendor Flexera, also believes taking governance seriously doesn’t mean organizations have achieved AI readiness.
“The risk surface of AI has expanded so quickly that the time designated to managing that risk continues to increase,” he notes. “Just one year ago, much of the focus was on enabling employees to experiment with AI, but now we’re seeing cases where autonomous agents create other agents and identify vulnerabilities at incredible speed.”
Governance is constantly playing catch-up to the changes happening with AI, Gallagher adds.
“Our IT team’s approach is to be judicious about which capabilities we put into employees’ hands and to slow deployment when we don’t understand the risk well enough,” he says. “We’re also applying established security principles to make sure agents don’t have greater access to capabilities than they actually need. The technology may be new, but some of the most important controls are still familiar ones.”
Anant Adya, EVP and head of Americas delivery at Infosys, says he’s spending more time managing AI risks now than a year ago, a natural shift, he adds, given the company’s move from experimentation to enterprise-scale adoption.
“While it does require additional attention, it is becoming embedded into our operating model rather than simply adding hours to the day,” he says of Infosys’ added emphasis on governance, security, privacy, compliance, and responsible AI practices.
That effort to operationalize governance and control is vital as the technology moves into core business workflows, Adya says, especially as agentic AI — what’s next — will only add another level of urgency.
“As these systems gain greater autonomy, they can access sensitive data, interact with other systems, and take actions on behalf of an organization,” he says. “Enterprises need strong identity controls, continuous monitoring, and appropriate human oversight.”
The struggle for good governance remains an issue for many organizations, but CIOs facing an overwork problem playing catch-up on AI governance are advised to get a handle on enforcing what matters before autonomous workflows compound the challenge.
Read More from This Article: AI governance is fast becoming an unmanageable chore
Source: News

