Policies Don't Create Governance. Enforcement Does.

July 20, 2026

Most organizations think they have AI governance because someone in legal drafted a policy and got it signed off. They don't. A policy sitting in a shared drive doesn't know where your AI is actually running. It doesn't flag it when a model drifts. It doesn't do a single thing when an employee routes a client file through an unapproved tool. 


The data backs this up, and it's not close. IBM and the Ponemon Institute surveyed 600 organizations across 17 industries for the 2025 Cost of a Data Breach Report and found that 63 percent of breached organizations either have no AI governance policy at all or are still developing one. Of the ones that do have a policy in place, only 34 percent perform regular audits for unsanctioned AI. Read that again. A third of organizations with a written policy have no mechanism to confirm anyone is following it. 


That gap is not a technology problem. It's an accountability problem, and it shows up highest in the org chart, not lowest. McKinsey's March 2025 State of AI report found that only 28 percent of organizations have their CEO taking direct responsibility for AI governance oversight, and only 17 percent say their board does. Meanwhile, Deloitte's 2026 State of AI in the Enterprise survey of over 3,000 leaders found that 74 percent of companies expect to use agentic AI at least moderately within two years, but only 21 percent currently have a mature governance model for autonomous agents. That's a 53 point gap between what's coming and what anyone is prepared to manage. 


For healthcare, insurance, and banking, this isn't theoretical. Every automated decision in these industries carries compliance weight. When an AI agent acts on a patient record, a policyholder claim, or a credit file without a governance framework built to catch it, that exposure doesn't stay in IT. It goes to the audit committee, then to the regulator, then to whoever has to explain it to the press. 


Here's the distinction that actually matters, and the one most frameworks miss: governance is not a document. It is three things working together. 


  • Visibility: You can see what AI is running in your environment, who deployed it, and what it touches. Not "we think we know." You know. 
  • Accountability: A specific person or committee owns the outcome, not "shared responsibility" that means no one owns it. 
  • Enforcement: There are consequences when the policy is not followed, and a mechanism to catch it when it isn't. 


Miss any one of those three and you have a document, not a governance program. Most organizations have built the first draft of a policy and stopped there, assuming the hard part is behind them. It isn't. The hard part is the audit cadence, the escalation path, and the willingness to actually enforce the thing you wrote down. 


The cost of skipping that work is measurable. IBM's same report found that organizations with a high level of shadow AI, meaning employees using unapproved, internet-based AI tools, faced an average of $670,000 in additional breach costs compared to organizations with low or no shadow AI. Healthcare breach costs averaged $7.42 million in 2025, the highest of any sector for the fourteenth consecutive year. Financial services averaged $5.56 million. Shadow AI compounds those numbers, and shadow AI is exactly what happens when governance stops at the policy document. 


If your board can't answer three questions right now, that gap is worth closing before it closes for you: What AI is actually running in our environment? Who is accountable for it? What happens when someone breaks the policy? 


Kona Kai's AI governance diagnostic exists to answer those questions honestly, before an incident forces the answer. Get in touch to talk through what that looks like for your organization. 


Sources: IBM / Ponemon Institute, Cost of a Data Breach Report 2025 (ibm.com/reports/data-breach); McKinsey, State of AI: How Organizations Are Rewiring to Capture Value, March 2025; Deloitte, State of AI in the Enterprise 2026. 


INSIGHTS

By Paul Benvenuto July 20, 2026
Governance, people, data, and process are not sequential steps. They are four load-bearing walls, and in regulated industries, a crack in any one of them shows up as risk somewhere else. Here is where each pillar actually breaks down today, and what the data says about the gap between where most organizations sit and w
By Carly Whitte July 1, 2026
AI success depends on more than technology. Governance, regulation, and operational oversight are helping organizations turn AI pilots into scalable business capabilities.
By Carly Whitte June 27, 2026
Healthcare AI adoption depends on more than technology. Governance, accountability, and AI readiness determine whether AI delivers measurable business value.
By Carly Whitte May 24, 2026
AI-powered “vibe coding” is accelerating enterprise software creation, but governance and security controls are struggling to keep pace. Learn the hidden risks of AI-generated applications and why responsible AI governance is critical for scalable enterprise adoption.
By Carly Whitte May 6, 2026
Why does AI adoption stall in healthcare? Discover how accountability, governance, and risk management influence success beyond change management.
By Carly Whitte April 28, 2026
AI adoption in healthcare often stalls due to unclear accountability, not resistance. Learn how governance design, risk management, and liability structures impact successful implementation.
By Carly Whitte April 5, 2026
Learn the most common enterprise AI implementation challenges and how to overcome them. Improve data, governance, and adoption to drive real business value.
By Carly Whitte April 5, 2026
Discover how to identify high-value AI use cases, evaluate readiness, and build a roadmap that drives measurable outcomes in enterprise organizations.
By Carly Whitte April 4, 2026
What is shiny object AI? Learn why AI initiatives fail without ROI and how to prioritize use cases that deliver measurable business value.
By Carly Whitte April 4, 2026
Why AI projects fail and how to improve success. Explore the role of readiness, governance, and process in AI transformation.