In this week's Wednesday AI Insights, we flagged one stat that mattered more than any product launch: only around 8% of organisations globally have a comprehensive AI governance framework, even though 88% are already using AI across business functions. That gap is the story. Not the next model release, not the next chip deal — the fact that most companies are running AI in production with no one clearly accountable for how it's used, what it's trained on, or what happens when it gets something wrong.
This piece is the full breakdown: who actually controls AI governance right now, what it costs companies that get it wrong, and the concrete steps to put in place before regulators, courts, or your own employees force the issue.
Who controls AI governance right now
There is no single global authority for AI. Instead, four very different regimes are setting the rules simultaneously — and most companies operating internationally are now subject to more than one at once.
| Region | Who's in charge | Approach |
|---|---|---|
| European Union | EU AI Office, under the EU AI Act | Binding, risk-tiered law with the highest fines in the world for non-compliance. |
| United States | No single federal AI law. Sector regulators (FDA, FAA, NHTSA, EEOC, FTC) plus ~38 states with their own AI statutes. | Fragmented, sector-by-sector, enforcement-driven rather than pre-emptive. |
| China | Cyberspace Administration of China (CAC), with the Ministry of Science and Technology and MIIT | Content and information-security controls; generative AI and recommendation algorithms must be registered with the state. |
| UAE | Federal AI and Data Authority (newly consolidated, July 2026) | Centralised single authority combining AI policy, digital economy, and data governance. |
| Global voluntary standards | NIST (US), ISO/IEC (international) | Not law, but increasingly the reference architecture regulators and auditors expect companies to demonstrate against. |
The practical implication: if you operate across even two of these jurisdictions, you don't have one AI compliance problem — you have four, and they don't agree with each other. A system that's compliant in the US under sector-specific rules can still be a high-risk system requiring conformity assessment in the EU, and a registrable algorithm in China.
The cost of getting this wrong
This isn't theoretical. The fines and enforcement actions are already happening.
Some of the enforcement actions already on the record this year:
- FTC v. Rite Aid — the FTC banned Rite Aid from using AI facial recognition in stores for five years, ordered deletion of all facial images collected, and mandated a full AI governance program with accuracy testing before any future AI surveillance tool can be deployed.
- Anthropic's $1.5B settlement — following findings that Claude was trained on pirated books, Anthropic agreed to delete the infringing datasets and shift to licensed training sources.
- A federal court ruling (SDNY, May 2026) — a government agency was found to have delegated a legally consequential sorting decision to ChatGPT without adequate human oversight or validation. The court was explicit: an organisation "cannot escape liability by scapegoating" the AI tool it chose to deploy.
- Montefiore Medical Center — covered in this week's Wednesday AI Insights: 12 nurses laid off and replaced with AI software, now a live labour grievance over contract language never updated for AI deployment.
The pattern across every one of these: it was never really about the AI model failing. It was about the absence of a human process wrapped around it — no oversight, no documentation, no accountable owner, no plan for what happens when something goes wrong.
"Every one of these cases has the same root cause. It's never really the model that fails — it's the absence of a human process wrapped around it. No owner, no oversight, no paper trail. That's not a technology gap. That's a management gap, and it's entirely fixable."
— Lisa Warren, Founder & CEO, Neural Horizons AI
What companies need to do now
None of this requires waiting for a mandate. The companies that will avoid becoming the next headline are putting the following in place now, not after an incident forces their hand.
The governance checklist
- Name an accountable owner. A single person or committee responsible for AI governance — even part-time, even one person, as long as it isn't "everyone and no one."
- Build a live AI system inventory. Every model and AI tool in use, including ones brought in through vendors and SaaS products you didn't build yourself. You can't govern what you haven't catalogued.
- Classify by risk. Map each system against a recognised framework — NIST AI RMF (Govern, Map, Measure, Manage) or ISO/IEC 42001 — so "high-risk" isn't a guess, it's a documented assessment.
- Map every jurisdiction you operate in. UAE, US, EU, and China are four different rulebooks. A system compliant in one may not be compliant in another.
- Build human oversight into every consequential decision. The SDNY ruling is the clearest warning yet: "the AI did it" is not a legal defence. Every high-stakes AI output needs a documented human review step.
- Vet third-party and vendor AI. Most of your AI risk isn't the model you built — it's the fifteen SaaS tools your teams already use that quietly added AI features.
- Write the incident and grievance process before you need it. Montefiore shows what happens when AI deployment outruns internal process and existing labour agreements.
- Train your people. Employees are already using AI tools whether there's a policy or not. An unclear or absent AI use policy is itself a governance failure.
- Report to the board, on a schedule. AI governance that lives in a slide deck from six months ago isn't governance — it needs a standing cadence, like financial or security risk reporting.
Lisa Warren: the bottom line
"Governance is not the tax you pay for using AI responsibly. It's the thing that lets you use AI at all, at scale, without it blowing up in your hands. The 8% of companies who've actually built this out aren't moving slower than everyone else — they're the ones who'll still be standing when the first wave of enforcement hits the other 92%."
— Lisa Warren, Founder & CEO, Neural Horizons AIWhy this can't wait
The EU AI Act's highest-risk provisions are already enforceable, and its high-risk system deadlines — even after this year's delay — now sit at December 2027 and August 2028. That sounds distant until you remember that conformity assessments, technical documentation, and governance infrastructure take months to build properly, not weeks. The US patchwork of roughly 38 state AI laws means new obligations are landing on an ongoing basis, not a single fixed date. And as we covered in this week's Wednesday AI Insights, China is actively positioning itself to shape global AI governance norms at this week's World AI Conference in Shanghai — whatever framework it proposes will influence how every multinational operating there has to comply.
None of these four regimes are waiting for companies to catch up. The only real choice a business has is whether it builds governance on its own terms, now, or has it imposed after an incident, a lawsuit, or a regulator does it for them.