// AI GOVERNANCE / THE OPERATING SYSTEM

AI Governance for Commercial Teams

The share of organizations with a written AI governance policy fell this year. Not rose. Fell, from 37 percent to 32 percent. In the same twelve months, AI-related breach costs climbed and shadow AI incidents more than doubled. If a policy were the control, more breaches should have meant more policies, not fewer. They mean something else: the document was never the thing standing between a company and an incident.

This is the first piece in a six-part series on AI governance built for commercial teams, not compliance departments. Marketing, sales, and revenue operations are running AI in production now, mostly without anyone from security in the room. The next five pieces take apart the four surfaces this one names. This one makes the case for why the policy was always the wrong artifact to build.

The policy declined while the risk grew

IBM's 2026 Cost of a Data Breach Report, published July 29, 2026 from 602 organizations across 17 industries and 16 countries, studied between March 2025 and February 2026, is the primary source for the numbers in this piece. Two of its findings sit next to each other and do not fit the story most companies tell themselves about governance.

First, the share of organizations with a documented AI governance policy fell from 37 percent to 32 percent year over year. Second, in that same window, AI-related breaches averaged 5.33 million dollars against 4.70 million for breaches with no AI involvement, AI-driven attacks rose 56 percent, and shadow AI incidents, employees using AI tools nobody approved, more than doubled among breached organizations, from 20 percent to 43 percent, pushing average cost from 4.63 million to 5.39 million and triggering a regulatory fine in roughly one incident in five.

Put those two findings in the same sentence and the read changes. Fewer companies are writing the document, and the companies that are getting breached are not the ones missing a document. They are the ones missing a mechanism.

What the incident data actually shows was missing

Here is the finding that reframes the whole problem. Among organizations that experienced an AI-related security incident, 92 percent lacked proper AI access controls at the time it happened. Not 92 percent lacked a policy. Ninety-two percent lacked controls, the operating mechanism a policy is supposed to produce.

Just as telling: only 19 percent of organizations coordinate between their AI governance function and their security team. Those are frequently two different people, in two different departments, who have never had a structured conversation about what the other one is doing. A policy signed by one and unknown to the other is not governance. It is paperwork with no owner on the operational side.

One more number worth sitting with: only 46 percent of organizations secure machine identities, meaning the credentials an AI agent uses to touch a CRM, a data warehouse, or a customer record are, for more than half of companies, not managed the way a human employee's login would be. That is the access surface this series covers next, and it is where the actual exposure lives, not in whether a PDF exists somewhere in a shared drive.

Governance as four surfaces, not one document

The fix is not a better policy. It is refusing to let a document stand in for a mechanism, and building four specific, checkable operating surfaces instead. Each becomes its own piece in this series.

Access. What can the system reach, and who approved that reach. Marketing automation that can touch the CRM, the product catalog, and the approved claim language is doing real work. The harder discipline is knowing what it was deliberately never connected to, and being able to name the reason.

Review. Every team says a human reviews the output. The only question that separates a real control from a rubber stamp is whether anyone has ever actually stopped something at that gate. A zero stop rate is not evidence of quality. It is evidence the gate does nothing.

Logging. Six months from now, when someone asks why the system said a specific thing to a specific person, can you reconstruct it: which model, which prompt, which retrieved context, which output, tied together. Most teams cannot, because they never pinned the model version, and the same prompt against an unpinned model stops being reproducible the moment the provider ships an update.

Audit scope. Whether the AI layer sits inside or outside your next formal audit. Most companies quietly keep it out, because putting it in forces answers about where the data goes, what the retention terms are, and who reviewed the vendor. The companies that put it in scope can describe exactly what had to change. That is a materially stronger position than a policy nobody has tested against an actual audit.

The regulatory floor is arriving whether the mechanism exists or not

Article 50 of the EU AI Act, the transparency obligations, took effect August 2, 2026, per the European Commission's own guidance. Providers of AI systems that interact directly with people must disclose that the interaction is with AI unless that is already obvious. Providers generating synthetic audio, image, video, or text must mark that content in a machine-readable, detectable format. Deployers using emotion-recognition or biometric-categorization systems must disclose that to the people affected, and deepfake content must be labeled clearly at first exposure. A limited grace period runs to December 2, 2026 for the content-marking obligation specifically, on systems already on the market. Penalties reach 15 million euros or 3 percent of global annual turnover, whichever is higher.

Article 14 sets a separate bar for human oversight on high-risk systems: a human overseer must be able to understand the system's capabilities and limits, stay alert to the tendency to over-trust its output, and be able to override or reverse a decision. For certain high-risk cases, the Act requires two separate people to confirm an action before it takes effect, a four-eyes principle with no ambiguity about what compliance looks like.

Neither article asks for a policy statement. Both ask for a demonstrable mechanism. A company that has spent the year building four operating surfaces is most of the way to compliant already. A company with a policy PDF and nothing behind it has a document that will not survive being asked to prove any of this.

Two frameworks, and why neither one is the whole answer

Two standards get cited constantly in this conversation and they solve different problems. ISO/IEC 42001 is a certifiable management system standard, the only one of the two that produces an actual certificate after an external audit. NIST's AI Risk Management Framework is voluntary, with no certification body and no formal audit attached to it, but it moves faster to implement and adapts as risk changes.

Neither is a substitute for the four surfaces above. ISO 42001 can certify that a management system exists around AI. It does not, by itself, prove your access controls are enforced or that your review gate has ever stopped anything. The frameworks are the scaffolding a mature program hangs on. They are not the program.

Why marketing cannot outsource this to security

The instinct in most companies is to treat AI governance as a security or legal problem and route it away from the commercial functions actually running the tooling day to day. The data argues against that instinct directly: only 19 percent coordination between AI governance and security means the split itself is the failure, not a reason to pick a side.

Spencer Stuart's December 2025 CMO survey, covered in depth in The Last CMO, found AI strategy and implementation most often led by the CTO or CIO, at 44 percent of companies, with the CMO at 32 percent and the CEO at 19 percent. That split is exactly the coordination gap showing up at the leadership level. A marketing team running AI-generated content, personalization, and outbound at scale without a seat at the governance table is the shadow AI problem in miniature, sanctioned inside the building rather than snuck in from outside it. Whether a single seat should hold both the commercial and the AI mandate is the argument in who should own AI: CAIO vs CTO vs CIO. Governance does not resolve that argument. It just makes the cost of losing it concrete and dated.

The series

Six pieces, publishing weekly:

  1. AI Governance for Commercial Teams: the operating system, not the policy PDF. This piece.
  2. What Actually Enters SOC 2 Scope When You Automate With AI: the audit-scope surface. September 8.
  3. The Human Gate That Isn't a Rubber Stamp: the review surface. September 10.
  4. What to Connect and What to Refuse: the access surface, MCP connectors. September 15.
  5. The AI Audit Log: the logging surface, reconstructing why the model said that. September 17.
  6. AI Vendor Review: where your data actually goes. September 22.

The discipline underneath all six is the same one behind AI Commercialization: the complete guide. The technology proving it runs and the business proving it is under control are two different claims, and this series exists because most companies have only made the first one.

Frequently asked questions

What is AI governance for a commercial team?

Not a written policy. IBM's 2026 Cost of a Data Breach Report, published July 29, 2026 from 602 organizations across 17 industries and 16 countries studied between March 2025 and February 2026, found that the share of organizations with a formal AI governance policy fell this year, from 37 percent to 32 percent, while AI-related breach costs and shadow AI incidents both climbed. A policy that is not enforced is not a control. Real AI governance is four operating surfaces: who can access which data and models, who reviews output and whether that review has ever stopped anything, whether a decision can be reconstructed after the fact, and whether the AI layer sits inside or outside a formal audit's scope.

Why do AI governance policies fail to prevent incidents?

Because a policy is a document and a breach is a system failure. IBM's 2026 report found that among organizations that suffered an AI-related security incident, 92 percent lacked proper AI access controls at the time it happened, and only 19 percent had any coordination between their AI governance function and their security team. A policy on file answers neither question. The organizations avoiding these incidents turned the policy into an enforced mechanism.

What is shadow AI and how big a problem is it in 2026?

Employees using AI tools that were never vetted or approved, the same pattern shadow IT followed a decade earlier. IBM's 2026 report found shadow AI incidents more than doubled among breached organizations, from 20 percent to 43 percent year over year, driving average breach cost from 4.63 million dollars to 5.39 million, and triggering a regulatory fine in roughly one incident in five. The fix is making the sanctioned option good and fast enough that shadow use has no reason to exist.

What does the EU AI Act require starting August 2026?

Article 50's transparency obligations took effect August 2, 2026. Providers of AI systems interacting directly with people must disclose the interaction is with AI unless obvious, and providers generating synthetic content must mark it in a machine-readable, detectable format. Deployers must disclose emotion-recognition or biometric-categorization use and label deepfakes clearly at first exposure. A grace period runs to December 2, 2026 for the content-marking obligation on systems already on the market. Penalties reach 15 million euros or 3 percent of global turnover. Article 14 separately requires human oversight on high-risk systems, including a two-person confirmation requirement for certain high-risk actions.

Who should own AI governance, the CMO, the CTO, or security?

IBM's 2026 report found only 19 percent of organizations coordinate between AI governance and security, which is the actual failure, not which title owns a policy document. Spencer Stuart's December 2025 CMO survey found AI strategy led by the CTO or CIO at 44 percent, the CMO at 32 percent, and the CEO at 19 percent. Governance does not require one owner. It requires four operating surfaces, access, review, logging, and audit scope, each with a named owner who talks to the others, which is precisely the coordination most organizations are missing.


Sources

Breach costs, AI access control and policy figures, shadow AI statistics: IBM, "Cost of a Data Breach Report 2026" (published July 29, 2026; 602 organizations, 17 industries, 16 countries, fieldwork March 2025 to February 2026). EU AI Act Article 50 transparency obligations and penalties: European Commission, Digital Strategy FAQ (accessed August 2026). EU AI Act Article 14 human oversight requirements: Article 14, EU AI Act. ISO 42001 versus NIST AI RMF certification and adoption comparison: TrustCloud (checked August 2026). CMO AI-ownership split: Spencer Stuart, "The AI Reckoning" (December 2025; no published sample size or fieldwork dates, treat as directional).


About the author

Jeff Brokaw is a sitting CMO and Certified Chief AI Officer who ships AI in production, not slideware. He has been building AI systems commercially since 2016. He built the commercial engine behind $185M in new-business revenue for a defense manufacturer, and authored the go-to-market behind a $114M institutional raise that came together in under 30 days.

Have a policy but no mechanism?

If your AI governance is a document nobody can point to a control behind, that is the conversation I have for a living.