8 min read

The AI Control Gap

AI governance is becoming too small for the risks it is meant to manage. The real challenge is no longer responsible AI use, but whether organizations can still see, control, explain and stop the systems shaping their data, decisions, costs and dependencies.
The AI Control Gap
Visual concept by Eckhart Mehler. Image generated with AI, 2026.

Why AI Governance Is Becoming Too Small for the Risks It Is Supposed to Manage


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


Most organizations believe AI governance means policies, approvals and compliance.

A steering committee.
An AI policy.
A short assessment form.
Maybe a register of approved tools.
Perhaps a new role called AI Officer.

All of this is useful.

None of it is enough.

Because AI is creating a much larger problem.

  • Who controls the data?
  • Who controls the models?
  • Who controls the agents?
  • Who controls the cost?
  • And who can stop the system when it starts acting in ways nobody anticipated?

That is the real AI governance question.

Not whether an organization has rules.

Whether it still has control.

Governance is becoming too small

For years, organizations have learned to govern technology through familiar mechanisms.

Policies define what is allowed.
Approvals decide what may proceed.
Risk assessments identify concerns.
Compliance functions document obligations.
Security teams protect systems.
Privacy teams protect personal data.

This model worked reasonably well when technology was mostly predictable.

Applications had owners.
Infrastructure had boundaries.
Users had identities.
Systems changed through releases.
Costs could be budgeted.
Responsibility could usually be assigned.

AI breaks several of these assumptions at the same time.

It does not merely process data. It interprets it.

It does not merely execute rules. It produces recommendations, judgments and increasingly actions.

It does not merely support users. It can become an active participant in workflows.

And it does not merely create a new software category. It changes the organization’s relationship with knowledge, authority, cost and accountability.

This is why conventional AI governance is at risk of becoming a compliance wrapper around a much more profound organizational shift.

The danger is not that organizations fail to create an AI policy.

The danger is that they create one — and believe they have solved the problem.

The first gap: visibility

You cannot govern what you cannot see.

Most organizations do not have a reliable picture of where AI is already used.

They know about the visible initiatives: the enterprise chatbot, the approved Copilot deployment, the innovation lab, the pilot with a strategic vendor.

But AI is rarely limited to visible initiatives.

It is embedded in SaaS products.
Activated through new features.
Used through browser extensions.
Accessed through individual API keys.
Connected to internal documents.
Built into departmental workflows.
Tested by teams without central knowledge.
Used informally by employees trying to do their jobs faster.

This is the beginning of the AI control gap.

The formal AI portfolio may look small.

The real AI footprint is often much larger.

And the problem is not simply Shadow AI.

It is that the organization may not know:

  • which models are being used;
  • which data is being entered;
  • which documents are being retrieved;
  • which applications are connected;
  • which agents have permissions;
  • which vendors are processing information;
  • which business decisions are influenced by AI;
  • which employees have started relying on AI outputs;
  • which costs are accumulating outside central budgets.

A register is necessary.

But a register populated only by self-declaration is not visibility.

Real visibility requires connection to the operational reality of the organization.

Procurement systems.
Cloud platforms.
Identity systems.
SaaS inventories.
Security telemetry.
Data-loss prevention signals.
Architecture repositories.
Business process ownership.

AI governance cannot become a form that employees complete after a system already exists.

It must become a capability that detects where AI is entering the organization before critical dependencies become invisible.

The second gap: authority

AI does not remove accountability.

It redistributes it.

That is not the same thing.

When an employee uses AI to draft an email, summarize a report or prepare a presentation, responsibility may still appear straightforward.

But the picture changes quickly when AI begins to influence decisions.

A model prioritizes cases.
An agent recommends suppliers.
A copilot summarizes risks.
A system ranks candidates.
A workflow suggests actions.
An assistant creates entries in a business system.
A predictive model influences resource allocation.

At that point, the organization must answer a question that is often avoided:

Who owns the decision when a human follows an AI recommendation?

The answer cannot be “the AI Officer.”

It cannot be “IT.”

It cannot be “the vendor.”

And it cannot be “the user clicked approve.”

The business owner remains responsible for the outcome.

But many organizations have not designed their processes for this reality.

They have not defined:

  • when AI may recommend;
  • when AI may decide;
  • when a human must intervene;
  • what evidence a human needs before accepting an output;
  • who can override an AI recommendation;
  • what level of error is tolerable;
  • how decisions can be reconstructed later;
  • who carries responsibility when the outcome causes harm.

This is the authority gap.

The organization introduces intelligence into a process without redesigning the accountability model around it.

Human-in-the-loop becomes a reassuring phrase.

But a person is not meaningfully “in the loop” merely because they press a button.

Human oversight only exists when the person has the competence, time, authority and evidence needed to challenge the system.

Otherwise, the organization has not created human control.

It has created human liability.

The third gap: technical control

The most important AI security issue is not the chatbot.

It is the agent.

A chatbot may answer questions.

An agent can act.

It can retrieve information.
Call APIs.
Create tickets.
Trigger workflows.
Read documents.
Update records.
Prepare transactions.
Interact with customers.
Coordinate other tools.
Use machine identities.
Operate continuously.

This is where AI becomes an identity and authorization problem.

The central question is no longer:

What can the model generate?

It becomes:

What is the model allowed to do?

An AI agent with access to Microsoft 365, SAP, SharePoint, HR systems, CRM platforms or internal workflows is not merely an innovation feature.

It is a new technical actor in the organization.

It needs an identity.

It needs defined permissions.

It needs logging.

It needs limits.

It needs a kill switch.

And it needs to be treated with the same seriousness as a privileged technical account.

Many organizations are not prepared for this.

They are still discussing AI policies while agents are beginning to receive access to production environments.

They are still debating ownership while connectors are being activated.

They are still defining governance while model-driven workflows are being built around sensitive data.

This creates a dangerous imbalance.

Technical capability is moving faster than organizational control.

The CISO sees this clearly because security operations provide the necessary sensorik.

A SOC sees suspicious access patterns.
A SIEM sees unusual API calls.
Identity systems reveal new permissions.
DLP sees data leaving the organization.
Threat intelligence identifies new attack patterns.
Incident response exposes where controls failed.

An AI governance function without this operational connection is blind.

It may know what was approved.

It may not know what is actually happening.

The fourth gap: economic control

AI is also changing the economics of technology.

Traditional software was often purchased through predictable models.

Licenses per user.
Infrastructure per month.
Projects with defined budgets.
Support contracts with known costs.

Generative AI introduces a different model.

The organization pays for usage.

For prompts.
For context.
For retrieval.
For output.
For model calls.
For agent loops.
For reasoning.
For storage.
For vector databases.
For safety filters.
For monitoring.
For model upgrades.

This is not simply a licensing question.

It is a new form of operational economics.

A user may see one short answer.

Behind that answer, the system may have processed a large context, retrieved multiple documents, performed several tool calls, invoked a model repeatedly and created costs that are invisible to the user.

An agent makes this more complex.

It may plan, retrieve, verify, retry and repeat.

Each step may consume tokens.

Each loop may add cost.

Each new capability may increase usage faster than the organization expects.

The result is a new governance challenge:

How much does AI cost per useful outcome?

Not per license.

Not per month.

Not per team.

Per useful, reliable and controlled outcome.

This requires a different type of transparency.

Which process consumes the most tokens?

Which model is used for which task?

Which teams are using premium models for simple work?

Which agents are looping without adding value?

Which RAG systems are loading excessive context?

Which use cases generate cost without measurable benefit?

Which dependencies are becoming economically irreversible?

The AI Officer should not become the chief budget owner for all AI spending.

But AI governance must ensure that no productive AI system goes live without a defined economic logic.

A budget owner.

A business case.

A cost limit.

A usage forecast.

A fallback model.

A stop condition.

Without this, token consumption becomes the next Shadow IT problem.

Only more expensive.

The fifth gap: sovereignty

The final control gap is sovereignty.

Many organizations still approach sovereignty as a location question.

Where is the data stored?

In which country is the cloud region?

Is the provider European?

These questions matter.

But they are not enough.

Data sovereignty is not simply about where data sleeps.

It is about who can access it, use it, move it, change it, export it, train on it, retain it and recover it.

In AI environments, sovereignty extends beyond data.

It includes:

  • the model;
  • the training and update process;
  • the prompts;
  • the retrieval sources;
  • the vector database;
  • the logs;
  • the identities;
  • the APIs;
  • the encryption keys;
  • the support model;
  • the sub-processors;
  • the contractual rights;
  • the ability to exit.

An organization may store data in Europe and still lose control.

It may depend on a provider that can change the model.

It may rely on a proprietary agent framework.

It may lack access to logs.

It may be unable to export prompts, workflows or embeddings.

It may not control the keys.

It may not know who can provide support access.

It may not be able to reconstruct what the system did.

It may not have a realistic exit path.

This is not a theoretical concern.

It is the emerging reality of AI dependency.

The question is not whether external AI services should be used.

They will be used.

The question is whether the organization can continue to operate, investigate, migrate and recover when the relationship with the provider changes.

Sovereignty is not isolation.

Sovereignty is retained agency.

The problem with current AI governance

Most AI governance models are still built around three assumptions.

First: AI is primarily a compliance issue.

Second: AI is primarily an IT deployment issue.

Third: AI risk can be managed through approvals.

All three are incomplete.

Compliance matters.
IT matters.
Approvals matter.

But none of them alone creates control.

A compliant AI system can still be technically uncontrollable.

A secure AI system can still be economically irrational.

A well-designed platform can still create unacceptable dependencies.

An approved use case can still lack a clear business owner.

A registered model can still act in ways nobody expected.

The real governance question is therefore broader:

Can the organization see, understand, control, explain and reverse the AI-enabled actions that affect its data, decisions, money, people and reputation?

That is the standard that matters.

Not whether the policy exists.

Whether the organization retains the ability to act when the policy is no longer enough.

From AI governance to an enterprise control model

AI governance must evolve.

It must become an enterprise control model with clear responsibilities.

The AI Officer should coordinate the governance architecture:

  • AI inventory;
  • risk classification;
  • lifecycle management;
  • control requirements;
  • evidence;
  • escalation;
  • management reporting.

The CISO should own security control:

  • identity;
  • permissions;
  • technical monitoring;
  • detection;
  • incident response;
  • threat intelligence;
  • resilience;
  • kill-switch capability.

The Data Protection Officer should remain independent and protect rights:

  • lawful processing;
  • purpose limitation;
  • data minimization;
  • transparency;
  • impact assessments;
  • rights of affected individuals.

Data governance should own the quality and trustworthiness of information:

  • provenance;
  • data ownership;
  • trusted sources;
  • retention;
  • classification;
  • quality standards.

IT and enterprise architecture should own platforms and technical lifecycle:

  • integration;
  • model routing;
  • observability;
  • operating models;
  • resilience;
  • change management.

Finance and FinOps should own the economic reality:

  • budgets;
  • cost allocation;
  • forecasting;
  • consumption monitoring;
  • value tracking.

Business leaders should own outcomes:

  • purpose;
  • benefit;
  • process design;
  • human oversight;
  • decision accountability.

And executive leadership must own the final question:

Which AI risks are we willing to accept?

This is not bureaucracy.

It is the minimum structure needed to prevent AI from becoming an unmanaged source of organizational power.

Control before scale

The organizations that succeed with AI will not necessarily be the ones that deploy the most models.

They will be the ones that understand where intelligence is entering their business — and where control is leaving it.

They will know which data is being used.

They will know who owns the decision.

They will know what agents can do.

They will know what each system costs.

They will know where dependency is growing.

And they will know how to stop, investigate, explain and recover when something goes wrong.

That is the new standard.

Not AI adoption.

AI control.

The AI risk is not that machines become intelligent.

The AI risk is that organizations become unable to explain who is still in control.


Publication Note & Disclaimer
This article was
originally published on LinkedIn on January 30, 2026 and may have been edited or updated for publication on this site.

It reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.