Large enterprises have spent the past two years building AI policies, committees and approval processes. A new EY survey suggests that the next governance problem is more operational: whether organisations can see, control and audit AI systems once they begin acting on their own.

EY commissioned an online survey of 202 US senior AI decision-makers at publicly traded companies with at least $1 billion in annual revenue. Ninety-eight per cent of respondents said their organisation has formal AI governance policies. Yet 47% said their organisation had previously bypassed its AI governance process for urgent deployments, while 36% reported an AI incident or failure that caused a materially negative impact.

The agentic AI findings are more revealing. Among respondents whose organisations use agentic AI, 49% said existing governance had not yet been specifically updated for agentic risks and 26% said their organisation could not detect unauthorised AI agents operating internally. The survey has a reported margin of error of plus or minus seven percentage points, so these figures should be read as evidence from this sample rather than as a census of enterprise AI.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

Traditional AI governance has often focused on model selection, data use, bias, privacy and human review. Agentic systems add a different class of questions because software can call tools, retrieve data, trigger workflows and take actions across enterprise systems. That makes inventory, identity, permissions and observability part of governance rather than purely technical concerns.

The practical challenge is straightforward to state and difficult to implement. An organisation needs to know which agents exist, who owns them, which systems and data they can access, what actions they are allowed to take, how those permissions can be revoked and what evidence is retained after an action occurs. Governance committees can approve a use case, but they cannot govern an agent they cannot see.

The EY findings therefore point toward a second generation of enterprise AI governance. The first generation was policy-led: define acceptable use and establish oversight. The next is likely to be enforcement-led: connect those policies to identity, access controls, runtime monitoring, audit evidence and incident response.

For financial institutions and other highly regulated organisations, that transition matters because the cost of an autonomous error can be higher than the cost of a poor answer from a chatbot. As agents move closer to operational systems, governance will increasingly be judged by whether controls actually operated, not by whether a policy document existed.


Conquered Your Data? - Now Combat Your AI
Souvik Choudhury, an AI and Data Governance Specialist at Fractal Analytics with a background spanning Infosys, HSBC and several startups, joins Stewart Tinson to unpack why data governance and AI governance can’t be treated as sequential problems, and why so many organisations discover the gap between them the hard way. Souvik argues that traditional data governance remains the foundation everything else is built on, and that AI agents amplify existing weaknesses rather than replacing the need for accountability, contextualisation and lineage. He walks through a real project example where an organisation believed it had solved data governance by using agents to generate column definitions, only to discover the definitions were pulled from generic internet knowledge rather than the organisation’s own policies, leaving a false sense of confidence behind a genuinely ungoverned dataset. The conversation covers where accountability actually sits when an autonomous agent makes a bad decision, why third-party models don’t dilute an organisation’s own responsibility for outcomes, and why Souvik pushes back on the idea that governance is an innovation-killing bureaucracy rather than the structural work that makes innovation possible in the first place. He also sets out a practical, staged approach to evaluating AI governance tooling rather than jumping straight to an enterprise platform, and offers a way to actually measure AI governance maturity using a weighted scoring model across multiple pillars. The discussion closes on an unexpected angle: the sustainability cost of AI infrastructure, and why Souvik believes environmental impact deserves a seat alongside profitability and productivity in any serious cost-benefit conversation about agentic AI.
Share this post
The link has been copied!