Skip to content
CityAM Canada
  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities
Thursday 30 July 2026 8:00 am  |  Updated:  Thursday 30 July 2026 9:13 am

Why AI governance can’t wait: Seven steps every security leader should follow today

By: Khush Kashyap, Senior Director of Governance, Risk and Compliance at Vanta

Add as a preferred source on Google
Professional typing on a laptop displaying Vantas AI Inventory dashboard with various AI agents and their risk levels.

Effective AI use has become a competitive advantage, and organisations are deploying tools and agents across every part of the business. But with great innovation comes great accountability.

Today’s AI isn’t just chatbots – agents are querying databases, calling tools and moving data. And this often happens without oversight over what they can access, or how their risk changes over time. Those blind spots, coupled with the AI skills crisis and lagging governance mean adoption is now outpacing governance.

The risk only grows as agents become more capable and autonomous. But businesses don’t need to choose between speed and control. Instead, it’s about changing our mindset to recognise that governance is core to innovation.

The problem is governance, not AI

AI is only as good as the governance around it, and right now governance is falling short. That’s because traditional IT infrastructure was never built for the speed or scale of AI. Organisations have historically relied on traditional point-in-time governance and annual reviews, but these simply can’t keep pace with the continuous change AI brings. In short, in the AI era what was true yesterday may not be true tomorrow. And the same goes for risk.

Major regulations, such as the EU AI Act, are beginning to catch up, by classifying AI systems into risk tiers, from minimal to unacceptable. In tandem, regulators have already converged on risk-proportionate governance.

But organisations need to move beyond the checkbox. They should apply the same logic to their own AI state – regardless of legislation – and pinpoint how they can truly safeguard their own customers and assets.

Visibility is the foundation of AI governance

One of the biggest emerging governance challenges is that organisations often don’t know the full extent of the AI operating across their business. These unmanaged, unapproved AI tools operate inside company environments without oversight – what we call shadow AI.

Read more

New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

Ultimately you can’t govern what you can’t see, and organisations have a difficult task even identifying their visibility gaps, let alone closing them. AI has now been so widely adopted across enterprises that it sits across almost all approved enterprise platforms, employee devices and browsers. And, increasingly, autonomous agents are embedded into everyday workflows. This means you can’t govern the technology in isolation. You need to ascertain the data your AI tools can access, the vendors behind it and the wider business context, not simply the model itself.

So what’s the solution? The answer starts with triage. Visibility alone isn’t enough. An inventory is a starting point but organisations need to treat all AI tools as risk hotspots, and assess each AI system’s impact and assign its criticality. For instance, a customer-facing agent with database access, and an internal summarisation tool do not warrant the same controls.


Vanta AI agent inventory dashboard showing PR Auto-reviewer details, monitoring, risk, and employee access.

Govern AI as fast as you adopt it

But where do you begin? Organisations struggling to govern their own AI tools should follow seven key steps:

  1. Assess the impact of each AI system and assign risk level: critical, high, medium or low. This should be based on the sensitivity of the data it touches, its level of autonomy, and who it affects – be it customers or employees.
  2. Layer controls proportional to that criticality – high-risk agents warrant human-in-the-loop approval, tightly scoped permissions and defined escalation paths when something goes wrong; low-risk tools need lighter-touch guardrails.
  3. Set clear guardrails around what AI agents are allowed to do, enforcing those boundaries and stopping high-risk actions before they become incidents.
  4. Extend third-party risk management to AI. Know which suppliers embed agents in their products, what data those agents can access, and build contractual protections such as training restrictions, incident notification or audit rights.
  5. Continuously monitor how AI environments evolve, rather than relying on periodic reviews. Reassess criticality when systems change – a rating assigned at onboarding goes stale the moment an agent’s scope, model or data access shifts.
  6. Name an owner to define accountability. This means you can adopt AI with confidence and without unnecessary frictions. In many organisations AI risk falls between security, legal and data teams.
  7. Build ongoing evidence that demonstrates AI is behaving as intended for customers, regulators and stakeholders

By following these steps, governance can become the trust layer that enables organisations to adopt AI with confidence, rather than a source of unnecessary friction.

Governing AI at the speed of adoption

Governance should aim to bolster innovation, rather than stand in its way. Governance may temporarily slow organisations down to speed them up, but once you get the right foundations in place you can move quickly. The organisations that follow this process will see the greatest gains from AI.

The most innovative organisations will build governance into AI from day one, giving the visibility, context and confidence to innovate responsibly. Governance also fails if it only lives in a policy document. Employees need AI literacy, clear acceptable-use guidance, and safe channels to disclose the tools they’re already using – punitive approaches drive AI underground and destroy the very visibility governance depends on. Organisations should be able to go all in on AI, safely, by governing AI as fast as they adopt it.


Vanta logo featuring a purple llama head next to the company name Vanta in bold purple text on a white background.
Read more

Orca Security Report: 99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Partner Content

Categories

  • Partner
  • AI

People & Organisations

  • Alondra Nelson
  • Credo AI
  • IAPP
  • Khush Kashyap
  • Vanta

Trending Articles

  • PwC thought leadership reports ‘100 per cent AI generated’

  • EY and London managing partner fined over £1.3m for audit failure

  • Lloyd’s of London allows staff to work from home as heatwave hits the capital

  • Big Four’s AIM exodus accelerates as mid-tier firms seize mandates

  • As it happened: Stocks jump as oil drops; Unilever shares soar on decade-best sales

More from CityAM

  • New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It

    Business Wire
  • Orca Security Report: 99.9% of Fixable AI Vulnerabilities Remain Unpatched as AI Moves Into Production

    Business Wire
  • OpenAI’s rogue agent doesn’t scare me – the millions of others do

    Opinion
    Breaking news concept with digital globe and graphs, symbolizing global financial trends and data analysis on a business w...
  • ARIS Recognized as a Leader in First Gartner® Magic Quadrant™ for Digital Twin of an Organization Platforms, Believes This Reinforces Need for Trusted Governance and Control of Enterprise AI

    Business Wire
  • Experian accelerates AI-first experiences with ServiceNow AI Platform

    Business Wire
  • The FCA has finally woken up to the AI revolution

    Opinion
    FCA reception area highlighting UKs shift to market-led innovation post-Brexit in financial regulations debate
  • Convertr Appoints Greg Jordan as Chief Product Officer to Strengthen Data Governance for Enterprise B2B Programmes

    Business Wire
  • Kore.ai Partners With Atos to Deliver Sovereign Agentic AI for UK Enterprise

    Business Wire

CityAM Canada — business, markets and opinion for Canadian readers.

Published by CityAM Publishing
3 Borden Street #301, Toronto, Ontario M5S 2M8, Canada
Contact us ›

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Newsroom
  • Contact

Legal

  • Editorial Policy
  • Corrections Policy
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies