Policies Don't Create Governance. Enforcement Does.

Most organizations think they have AI governance because someone in legal drafted a policy and got it signed off. They don't. A policy sitting in a shared drive doesn't know where your AI is actually running. It doesn't flag it when a model drifts. It doesn't do a single thing when an employee routes a client file through an unapproved tool.
The data backs this up, and it's not close. IBM and the Ponemon Institute surveyed 600 organizations across 17 industries for the 2025 Cost of a Data Breach Report and found that 63 percent of breached organizations either have no AI governance policy at all or are still developing one. Of the ones that do have a policy in place, only 34 percent perform regular audits for unsanctioned AI. Read that again. A third of organizations with a written policy have no mechanism to confirm anyone is following it.
That gap is not a technology problem. It's an accountability problem, and it shows up highest in the org chart, not lowest. McKinsey's March 2025 State of AI report found that only 28 percent of organizations have their CEO taking direct responsibility for AI governance oversight, and only 17 percent say their board does. Meanwhile, Deloitte's 2026 State of AI in the Enterprise survey of over 3,000 leaders found that 74 percent of companies expect to use agentic AI at least moderately within two years, but only 21 percent currently have a mature governance model for autonomous agents. That's a 53 point gap between what's coming and what anyone is prepared to manage.
For healthcare, insurance, and banking, this isn't theoretical. Every automated decision in these industries carries compliance weight. When an AI agent acts on a patient record, a policyholder claim, or a credit file without a governance framework built to catch it, that exposure doesn't stay in IT. It goes to the audit committee, then to the regulator, then to whoever has to explain it to the press.
Here's the distinction that actually matters, and the one most frameworks miss: governance is not a document. It is three things working together.
- Visibility: You can see what AI is running in your environment, who deployed it, and what it touches. Not "we think we know." You know.
- Accountability: A specific person or committee owns the outcome, not "shared responsibility" that means no one owns it.
- Enforcement: There are consequences when the policy is not followed, and a mechanism to catch it when it isn't.
Miss any one of those three and you have a document, not a governance program. Most organizations have built the first draft of a policy and stopped there, assuming the hard part is behind them. It isn't. The hard part is the audit cadence, the escalation path, and the willingness to actually enforce the thing you wrote down.
The cost of skipping that work is measurable. IBM's same report found that organizations with a high level of shadow AI, meaning employees using unapproved, internet-based AI tools, faced an average of $670,000 in additional breach costs compared to organizations with low or no shadow AI. Healthcare breach costs averaged $7.42 million in 2025, the highest of any sector for the fourteenth consecutive year. Financial services averaged $5.56 million. Shadow AI compounds those numbers, and shadow AI is exactly what happens when governance stops at the policy document.
If your board can't answer three questions right now, that gap is worth closing before it closes for you: What AI is actually running in our environment? Who is accountable for it? What happens when someone breaks the policy?
Kona Kai's AI governance diagnostic exists to answer those questions honestly, before an incident forces the answer. Get in touch to talk through what that looks like for your organization.
Sources: IBM / Ponemon Institute, Cost of a Data Breach Report 2025 (ibm.com/reports/data-breach); McKinsey, State of AI: How Organizations Are Rewiring to Capture Value, March 2025; Deloitte, State of AI in the Enterprise 2026.
INSIGHTS












