The Four Pillars of AI Success: Governance, People, Data, and Process

July 20, 2026

Most AI strategies do not fail because the technology underperforms. They fail because organizations treat AI as a single initiative instead of four separate disciplines that have to mature together. Governance without workforce readiness produces a policy nobody follows. Data readiness without process redesign produces a clean pipeline feeding a workflow that was never rebuilt to use it.


Governance, people, data, and process are not sequential steps. They are four load-bearing walls, and in regulated industries, a crack in any one of them shows up as risk somewhere else. Here is where each pillar actually breaks down today, and what the data says about the gap between where most organizations sit and where they need to be. 


Governance: policies don't create governance. Enforcement does. 

Most organizations think they have AI governance because someone in legal drafted a policy and got it signed off. They don't. IBM and the Ponemon Institute surveyed 600 organizations for the 2025 Cost of a Data Breach Report and found that 63 percent of breached organizations either have no AI governance policy or are still developing one. Of the ones that do have a policy, only 34 percent audit for unsanctioned AI. That gap shows up highest in the org chart: McKinsey's 2025 State of AI survey found only 28 percent of organizations have their CEO directly overseeing AI governance, and just 17 percent say their board does. Deloitte's 2026 State of AI in the Enterprise found 74 percent of companies expect to use agentic AI within two years, but only 21 percent have a governance model mature enough to manage it. 


Governance is not a document. It is three things working together: 


  • Visibility into what AI is actually running in your environment 
  • Accountability, meaning a specific person or committee owns the outcome 
  • Enforcement, meaning there are consequences when policy is not followed 

Miss any one of those and you have paperwork, not a program. 


People: AI literacy isn't training. It's an operating model. 


Deloitte names the AI skills gap as the single biggest barrier to integration right now, ahead of budget and technology maturity. McKinsey's 2026 AI Trust Maturity Survey found that nearly 60 percent of organizations cite knowledge and training gaps as the primary barrier to responsible AI, up from about 50 percent the year before. The gap is widening while spend on closing it goes up, and the reason is the unit of measurement. A workshop teaches someone to use a tool. It does not teach a claims adjuster when to trust a model's output, or an underwriter how to explain an AI-assisted decision to a regulator. 


Capability, not completions, is what closes the gap: 


  • Frontline roles need to know when AI output is reliable enough to act on 
  • Underwriting and clinical roles need to explain AI-assisted decisions in plain language 
  • Compliance roles need new technical skills like model auditing and bias testing 

None of that happens in a single session, and none of it happens outside the flow of actual work. 


Data: AI is only as trustworthy as the data behind it. 


PwC's 2026 AI Performance Study surveyed 1,217 executives and found that nearly three quarters of AI's economic value is captured by just one fifth of organizations. The differentiator is not a better model. Those top organizations are 1.7 times more likely to have a Responsible AI framework, 1.5 times more likely to have a cross-functional governance board, and their employees trust AI outputs at twice the rate of everyone else. Trust comes from knowing where data originated, who touched it, and what controls sat around it the whole way through, not from a more sophisticated model. McKinsey's research on AI data readiness argues most organizations manage data like a storage problem when they should manage it like a supply chain, since a single document can expand into text, tables, metadata, and quality scores that AI systems reuse and recombine downstream. 


The data causing the most exposure is usually getting the least attention. Before your next AI initiative launches, ask: 


  • Where does data quality break down, and who owns fixing it 
  • Is lineage visible for your highest-risk AI use cases, or assumed 
  • What unstructured assets, like clinical notes and policy documents, carry no governance at all 


Process: Agentic AI changes how work gets done. 


Deloitte's finding that 74 percent of companies expect to use agentic AI within two years, against only 21 percent with mature governance for it, is a workflow problem as much as a governance one. Every process most organizations run today was built for AI that waits to be asked. Agentic AI does not wait. It initiates and chains actions across systems on its own, and workflows built around human-reviewed steps have no place for that kind of actor. The World Economic Forum's January 2026 AI at Work report makes the point directly: one healthcare organization took a lab-order process from thirty minutes to a few seconds by rebuilding the workflow first and deploying AI second, reclaiming roughly 30,000 hours a year. 


KPMG's Q4 2025 AI Pulse Survey found that 60 percent of organizations restrict agent access to sensitive data without human oversight, meaning 40 percent do not. Four controls close most of that gap: 


  • Clear rules for when an agent's action requires human review first 
  • Explicit policies for what data and systems an agent can touch 
  • A traceable audit record built for an examiner, not internal debugging 
  • A defined escalation path when an agent's behavior deviates from expectations 


Bringing the four pillars together 


These four pillars do not advance on separate timelines. A governance policy without a workforce that understands it is theater. A clean data foundation feeding a workflow nobody redesigned is wasted effort. The organizations pulling ahead are treating all four as one system, built and audited together, not four separate initiatives competing for the same budget. 


Kona Kai works with healthcare, insurance, and banking leaders to close these gaps before an exam, an audit, or an incident force the conversation. Get in touch to talk through where your organization actually stands across all four. 


Sources: IBM / Ponemon Institute, Cost of a Data Breach Report 2025; McKinsey, State of AI: How Organizations Are Rewiring to Capture Value, March 2025; McKinsey, State of AI Trust in 2026; McKinsey, AI Data Readiness: The Key to Scaling Impact, June 2026; Deloitte, State of AI in the Enterprise 2026; PwC, 2026 AI Performance Study, April 2026; World Economic Forum, AI at Work: From Productivity Hacks to Organizational Transformation, January 2026; KPMG Q4 2025 AI Pulse Survey. 

INSIGHTS

By Paul Benvenuto July 20, 2026
Most organizations think they have AI governance because someone in legal drafted a policy and got it signed off. They don't. A policy sitting in a shared drive doesn't know where your AI is actually running. It doesn't flag it when a model drifts. It doesn't do a single thing when an employee routes a client file thro
By Carly Whitte July 1, 2026
AI success depends on more than technology. Governance, regulation, and operational oversight are helping organizations turn AI pilots into scalable business capabilities.
By Carly Whitte June 27, 2026
Healthcare AI adoption depends on more than technology. Governance, accountability, and AI readiness determine whether AI delivers measurable business value.
By Carly Whitte May 24, 2026
AI-powered “vibe coding” is accelerating enterprise software creation, but governance and security controls are struggling to keep pace. Learn the hidden risks of AI-generated applications and why responsible AI governance is critical for scalable enterprise adoption.
By Carly Whitte May 6, 2026
Why does AI adoption stall in healthcare? Discover how accountability, governance, and risk management influence success beyond change management.
By Carly Whitte April 28, 2026
AI adoption in healthcare often stalls due to unclear accountability, not resistance. Learn how governance design, risk management, and liability structures impact successful implementation.
By Carly Whitte April 5, 2026
Learn the most common enterprise AI implementation challenges and how to overcome them. Improve data, governance, and adoption to drive real business value.
By Carly Whitte April 5, 2026
Discover how to identify high-value AI use cases, evaluate readiness, and build a roadmap that drives measurable outcomes in enterprise organizations.
By Carly Whitte April 4, 2026
What is shiny object AI? Learn why AI initiatives fail without ROI and how to prioritize use cases that deliver measurable business value.
By Carly Whitte April 4, 2026
Why AI projects fail and how to improve success. Explore the role of readiness, governance, and process in AI transformation.