In Practice: AI in the Enterprise | Day 90: What Comes Next: The Future of Enterprise AI Governance (What to Prepare For Now)

Ninety days of thinking about enterprise AI governance has been useful partly because it’s forced the question: what changes after day 90?

The honest answer is: the challenges ahead are likely to be different from the challenges of today. What follows are observations about emerging patterns and possible directions—not predictions. I’m exploring scenarios rather than asserting certainties.

Today’s governance challenges are structural and procedural. They’re about building governance frameworks that fit foundation models. They’re about distributing governance expertise. They’re about shifting from reactive to predictive. These are hard problems, but they’re addressable with work, with the right expertise, and with organizational will.

The challenges coming are different. They’re about governance in a world where AI isn’t an isolated function—it’s embedded in every part of the business. Where the competition isn’t about who has the best AI. It’s about who can govern AI reliably enough to build customer trust and regulatory confidence. Where the risk surface isn’t models or data in isolation—it’s the complex system of humans, algorithms, and business processes that are deeply entangled.

What follows isn’t a prediction about AI itself. It’s about what enterprise AI governance may need to become.

From Islands to Networks

Today, enterprises still think of AI systems as somewhat discrete things. You have a team working on a recommendation model. Another team working on a fraud detection system. Another on customer service. These are governed separately, with separate risk frameworks and separate accountability.

This was always an artificial isolation. But it was manageable. You could govern each system largely independently.

That’s ending. First, because enterprises are stacking systems—you call the recommendation model, which calls another model, which reads data that’s been transformed by a third system. The risk surface is no longer one model. It’s a network.

Second, because AI is moving from specialized applications to general infrastructure. Language models are becoming utilities. Vision systems are becoming integrated into many workflows. The same foundational system is being used across an organization in dozens of ways, most of which you didn’t architect.

This creates a governance problem that doesn’t exist today: how do you govern a network where the components are interdependent, where the same model is used in multiple contexts, where failures in one place cascade to others?

The governance frameworks of today—designed for individual systems—will not scale to that. You’ll need network-level governance. You’ll need to understand not just whether individual systems are safe, but whether the network is stable. You’ll need to understand emergent behaviors that come from interactions between systems.

The Visibility Problem Gets Harder

Right now, enterprises have an advantage: they’re still building AI systems consciously. Someone in the organization knows about them. There’s a project. There’s a team. There’s a deployment.

That’s changing. As foundation models become more accessible and easier to integrate, organizations could have systems running that nobody in a governance role knows about. A team might fine-tune a model internally for a specific use case. Another team might integrate a public model into a workflow. A third could use an AI service from a cloud provider that abstracts away the model entirely.

This is the governance problem that keeps senior leaders awake at night: shadow AI. Systems running in production, creating consequential outputs, that the governance function doesn’t know exist.

Today, most governance programs are built around the assumption that they have visibility into what’s being built. Tomorrow, they won’t. You can have strong governance processes, but if you don’t know about 60% of the AI systems in your organization, what are you actually governing?

This requires a completely different governance architecture. Not one based on approval gates for known systems, but one based on continuous discovery. Instrumentation. Monitoring. Scanning for systems that are showing characteristics of AI—generating synthetic outputs, making decisions based on pattern recognition, behaving in ways that suggest trained models.

The organizations that are preparing now are starting to think about system discovery. How would you find a deployed model you don’t know about? How would you identify that a system is using AI? What signals would tell you? Those are the governance capabilities you’ll need.

Regulation May Mature (and Create New Risk)

Right now, AI regulation is nascent. Different jurisdictions have different rules. They’re often vague. They’re still being formed. This creates uncertainty, but it also creates breathing room. You can be compliant with one standard and not fully compliant with another.

That may change. Over the next two years, regulation is likely to become more mature. The rules may become more specific, more demanding, more overlapping. Different regions may have conflicting requirements. A system that complies with the EU may not comply with Singapore. Compliance could become increasingly complex.

But here’s the harder part: regulation may create new liability. Right now, if you have a good-faith governance program, regulators are generally forgiving. But as regulation matures, the standard may shift from “did you have a governance program?” to “did you have the right governance program?” And penalties for being wrong could increase.

This creates a risk that most organizations haven’t thought through: governance drift. You could have a program that was state-of-the-art in 2026 and find it outdated by 2028. You might then face a position where you’re compliant with old rules but non-compliant with new ones, but you don’t realize it yet.

Organizations preparing now are building governance programs that are forward-compatible. That can adapt as rules change. That don’t assume the current regulatory environment is stable. Because it’s not.

The Human Factor Will Matter More, Not Less

A common hope in governance is that once you have the right processes and frameworks, execution becomes more routine. You can delegate it. It becomes systematic.

This hope is wrong, especially for AI. The more sophisticated AI governance becomes, the more it depends on human judgment. Is this model output surprising in an important way or an expected way? Does this emerging behavior represent a new risk or just normal variation? When two governance requirements conflict, which do we prioritize?

These aren’t questions you can answer with process. They require judgment. They require experience. They require people who understand both AI and the business deeply enough to see the connections.

Organizations preparing for this are investing in governance people. Not compliance people. People who can reason about risk, who understand technical AI, who can translate between technical and business language, and who are trusted by product teams as helpers, not blockers.

This is counterintuitive. The instinct is that more governance should be less dependent on people, more systematic. But with AI, it’s the opposite. Better governance requires better people.

The Trust Problem Will Emerge

Over the next few years, an interesting dynamic may emerge: AI could start failing in ways that matter. Not catastrophically—not AI systems destroying companies or harming people at scale. But visibly. Systems that discriminate. Systems that produce outputs that turn out to be confidently wrong. Systems that make decisions that, in hindsight, should have been caught.

These failures could be covered. They could be litigated. They could affect customer trust. And they may create an opportunity for enterprises that have genuine governance to differentiate.

Organizations with real governance would be able to say: we caught this. We understand our risks. We know where our systems can and can’t be trusted. We’re not perfect, but we’re reliable.

Organizations without it would be saying: this was an unforeseen edge case. We have controls. We have policies. But they wouldn’t be able to point to concrete governance practices that caught or would have caught the problem.

Trust becomes the battleground. And trust is won through demonstrated governance, not asserted governance.

What You Should Do Now

If you’re responsible for AI governance in an enterprise, here’s what I’d focus on preparing for:

First: Build the capability to discover and map your AI systems. You need to know what’s running in your organization. Invest in scanning. Instrumentation. Monitoring. Not to police, but to understand what you actually have to govern.

Second: Shift from system governance to network governance. Start thinking about how systems interact. Where do failures cascade? Where do emergent behaviors appear? Network-level risks are becoming the dominant risk category.

Third: Prepare for governance evolution. Your current governance program may need significant updates within 18 months. Design it to be updatable. Design it to be forward-compatible. Plan for change.

Fourth: Invest in people. Governance expertise is more valuable than governance process. Build a team that can reason about complex tradeoffs, that’s trusted by the business, that can evolve as the landscape changes.

Fifth: Focus on trust, not compliance. Compliance is table stakes. Trust is the competitive advantage. Build governance practices that genuinely give customers and regulators confidence in your systems.

The Work Continues

Ninety days of thinking about AI governance reveals something important: this is not a problem that gets solved. It’s a problem that gets managed continuously. The organizations that are winning are the ones that accept this. They’re not trying to build governance once and have it work forever. They’re building organizations that can think clearly about AI risk and adjust as the landscape changes.

The challenges of today—framework-building, expertise distribution, governance scaling—are real. And they’ll be solved by enterprises that take the work seriously.

But the challenges ahead are different. They’re about discovering systems you don’t know exist. About governing networks instead of islands. About building trust instead of compliance theater. About developing governance expertise that can evolve as AI itself evolves.

The work of ninety days was about understanding the current moment. The work that comes next is about preparing for what’s coming.

The organizations that are moving fast on enterprise AI are the ones that know this. They’re not waiting for perfect governance in 2026. They’re building governance that can adapt to a 2028 world they don’t fully know yet.

That’s how you prepare for what comes next.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.