Until recently, governance felt like a solved problem—critical but entirely manageable. With the rise of AI, it is now the dominant enterprise anxiety.
AI projects are stalling because companies lack the governance, visibility, and controls to deploy them effectively. I’ve watched this pattern play out across industries over the past two years. Organizations that moved quickly on adoption saw strong results in isolated use cases, but soon discovered their accountability infrastructure had not kept pace. AI moved faster than their governance.
That’s why the main concerns I hear from customers and their boards today are around trust and control. Who authorized this agent to act? What systems can it touch? What stops it from doing something it shouldn’t? Autonomy raises the stakes further, with agents now able to spawn other agents, create multi-step workflows, and make decisions faster than any human can review them. Visibility into that activity, and the ability to manage it over its full lifecycle, is non-negotiable.
To regain control, leaders must look past the AI layer and fix the foundation beneath it.
THE STAKES HAVE CHANGED
Capable AI exists, but without adequate controls, it creates compounding risk instead of compounding value. That distinction is landing hard in the boardroom. Directors who once asked about AI investment are now asking whether anyone can actually account for what it’s doing. AI is making decisions at a speed and volume no human review cycle can match. In June 2025, Gartner projected that 40% of AI initiatives would be cancelled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls.
Ask a large language model the same question twice and you can get two different answers. That’s the nature of how these models work; they’re based on probability. For tasks like customer service and compliance, along with payroll and procurement, that variability is unacceptable. The output must be consistently accurate or the business can’t trust the system running it. When AI lacks the context to understand how work is done, including exceptions, historical decisions, and organizational nuance, processes break down or produce outcomes nobody can explain or audit.
GOVERNANCE STARTS BELOW THE AGENT LAYER
Most governance conversations focus on the agent layer: which AI systems are running, who authorized them, and what they can access. These are necessary questions. But they miss a more foundational issue: AI governance is only as strong as the data governance underneath it.
AI agents operating on ungoverned data that lacks context produce incorrect answers. It does so with confidence and embedded in workflows that carry real consequences. The typical enterprise runs across hundreds of software systems, each with its own data model. In too many organizations, AI is making decisions based on data that nobody has a complete picture of, with no audit trail connecting an outcome back to its source.
We see this play out at scale. ServiceNow runs more than 100 billion workflows and eight trillion transactions per year, creating a record of how work gets done. Feed an AI model that context, including the exceptions and historical decisions, and it starts to produce outcomes that people can rely on. The data layer, the decision layer, and the action layer cannot be treated as separate problems with separate owners. Governance has to span the full chain.
CONTROL IS NOT A DASHBOARD
It’s worth being precise about what control means, because the word gets used in ways that obscure the real challenge.
Control is not a policy document in a compliance folder. It can’t be retrofitted after AI has been embedded across an organization. Meaningful control means knowing, in real time, what AI systems are operating and what actions they’re taking. It means policy enforcement that happens before an action executes. It means a clear, traceable chain of accountability for every consequential output that survives scrutiny from a regulator or an auditor. It also must satisfy a board that is no longer willing to take governance on faith.
GOVERNANCE ENABLES SPEED, NOT THE OPPOSITE
Leadership teams sometimes frame governance as a constraint on how fast they can move with AI, but the evidence tells a different story.
The model wars get the headlines, but they’re not what determines success or failure with AI. What matters is that people get work done faster, processes run without manual intervention, and the business becomes more efficient. The organizations achieving those outcomes—what Oxford Economics and ServiceNow call AI Pacesetters—are significantly more likely to have formal governance in place. Among top performers, 63% have addressed data governance and created AI-specific policies, compared to 42% of their peers. That gap—the deliberate investment in governance infrastructure—is a significant part of what separates them.
This pattern mirrors what happened with cloud a decade ago. The organizations that moved fast without architectural discipline ended up with sprawl and cost structures that took years to untangle. The ones that invested in the governance layer alongside the capability layer came out ahead. AI is following the same pattern, at a faster pace and with higher stakes.
The leaders navigating this shift most effectively have internalized one principle early: AI governance and data governance are not separate functions, and neither is a mere compliance exercise. They’re foundational requirements for operating AI at any meaningful scale. The organizations building that infrastructure now, before the consequences arrive, will move faster, achieve compliance without scrambling, and answer regulators and auditors with confidence.
The organizations that figure this out now will reduce their exposure and earn the institutional trust to do more with AI—faster, at higher stakes, and with the confidence to walk into any board or regulatory conversation knowing exactly what is running and why.
Amit Zavery is president, CPO, and COO of ServiceNow.
Â