Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

AI is moving faster than the structures built to govern it

September 16, 2026
5 min read
Kira Ciccarelli

Kira Ciccarelli

Senior Manager of Research & Programs

AI has moved beyond the technology team. It's helping draft board materials, monitor compliance activity, analyse risk and inform decisions across the business. That makes AI an enterprise governance issue. Boards need to understand where it is being used, what data sits underneath it and who remains accountable for the outcome.

The challenge is not simply whether an organisation has an AI policy. It is whether its existing governance, risk and compliance model can provide a connected view of AI use, risk, controls and ownership. For many organisations, that view is still fragmented across business functions, systems and spreadsheets.

That gap matters because AI does not repair weak governance. It can expose it, accelerate it and make it harder to see.

Why fragmented GRC creates an AI blind spot

Traditional GRC models were often designed around a periodic review. It was a set formula: Risk reports moved to the board on a set cycle; compliance teams responded to regulatory change; audit teams tested controls after processes were established.

AI changes that rhythm because it can generate, recommend and act at a much faster pace.

If governance, risk, compliance and audit operate in separate systems, a signal identified in one function may not reach the people who need it elsewhere. A data-quality issue known to audit may never be visible to the team using the same data in an AI-assisted compliance workflow. A third-party risk may sit outside the board’s view of AI exposure. An output can look precise while the underlying context remains incomplete.

Connected GRC does not mean putting every decision in one dashboard. It means creating a reliable line of sight between risk signals, data, controls, owners and board reporting. That connection makes it easier to identify where AI is active and test whether oversight is keeping pace.

More data is not the same as better insight

AI can process more information than any individual team. But volume and speed do not guarantee clarity. If the source data is siloed, duplicated, stale or inconsistent, the output can reproduce the same weaknesses at greater speed.

That's why data governance is a foundation for responsible AI adoption. Leaders need to know where information came from, whether it is current, who owns its quality and how it was used. The more consequential the decision, the more important traceability becomes.

Boards don't need to understand every technical detail of a model. But they do need confidence that management can explain the data, control and accountability behind an AI-assisted decision. If an output cannot be traced or challenged, it cannot support defensible oversight.

The risks extend beyond the model

Model accuracy and bias matter, but they are only part of the risk picture. AI governance also has to account for explainability, third-party exposure, security, regulatory scrutiny, reputation and cost.

Consider third parties. AI features can enter the organisation through products and suppliers already in use. That can create important questions about where data goes, how outputs are generated and who is responsible when a vendor’s AI feature influences a business decision.

Accountability cannot sit with the system itself. Named people must remain responsible for approving use cases, setting autonomy limits, reviewing high-impact outputs and responding when something goes wrong. Human review should be designed into the workflow, not added only after an incident. That shift, from broadly stated AI principles to accountable board practice, is where many organisations still struggle.

Five key AI GRC questions boards should be asking right now

These questions look at AI governance not from an abstract principle but an operating discipline. They also help leadership identify where policy, process and technology are out of step.

  1. Where is AI already being used, including tools adopted outside a central approval process?
  2. What data feeds each use case, and who is accountable for data quality?
  3. Which decisions are AI-assisted and which, if any, can proceed without human approval?
  4. How quickly would the organisation detect, escalate and explain a flawed output?
  5. Can risk, compliance, audit and governance teams see the same material AI risks and controls?

Build the foundations before scaling the use case

Responsible adoption does not require every organisation to reach the same level of AI maturity at the same time. It does require leaders to put the foundations in place before use expands.

Start by mapping current AI use. Define ownership and decision rights, guided by a structured AI risk management framework. Document where human approval is required. Strengthen data lineage and quality controls. Build role-specific skills so directors and GRC teams can interrogate outputs rather than simply accept them. Then connect the systems and workflows that carry risk information to the people responsible for acting on it.

The goal is not to slow innovation. It's to give people enough clarity and control to use AI with confidence. Strong governance creates the conditions for teams to move faster because the boundaries, evidence and responsibilities are clear.

AI is not the risk. Ungoverned AI is. The organisations
that move now, on governance, on data, on skills and
on accountability, will be the ones that turn AI from
an exposure into an advantage.

A practical guide for the next stage of AI oversight

Diligent and Board Agenda explore these issues in The AI odyssey: An inflection point for governance, risk and compliance (GRC).

The whitepaper examines the shift from reactive compliance to connected, intelligence-led GRC, the data challenge underneath AI and the practical steps boards and GRC leaders can take to prepare. It is designed to help senior leaders move beyond broad AI discussion and test whether accountability, controls and oversight are ready for operational use.

Download the whitepaper here.

Explore More

AI Governance Guide Public Sector

Guide

· Apr 22, 2026

· 1 min read

From AI talk to real impact: How today’s public leaders do more without adding headcount

Unlock the potential of AI in public governance with our comprehensive guide designed for clerks, city administrators, and governance teams. Learn to streamline agenda preparation, enhance compliance, and create a transparent workflow that aligns elected officials and staff on responsible AI use. Download now to transform your public sector operations in just 90 days.

Guide

· Dec 1, 2025

· 1 min read

AI governance policy template: Ensure compliance & reduce risk

A structured template designed to help organizations establish a framework for the responsible, ethical and transparent use of AI.

People discussing the board's role in leading and enabling GRC

Blog

· Nov 18, 2025

· 13 min read

The board's role in leading and enabling GRC

By Michael Rasmussen

Learn how boards lead effective GRC strategies. Discover the board's role in governance, risk management and compliance oversight.