In this week's Wednesday AI Insights, we flagged one stat that mattered more than any product launch: only around 8% of organisations globally have a comprehensive AI governance framework, even though 88% are already using AI across business functions. That gap is the story. Not the next model release, not the next chip deal — the fact that most companies are running AI in production with no one clearly accountable for how it's used, what it's trained on, or what happens when it gets something wrong.

This piece is the full breakdown: who actually controls AI governance right now, what it costs companies that get it wrong, and the concrete steps to put in place before regulators, courts, or your own employees force the issue.

Who controls AI governance right now

There is no single global authority for AI. Instead, four very different regimes are setting the rules simultaneously — and most companies operating internationally are now subject to more than one at once.

RegionWho's in chargeApproach
European UnionEU AI Office, under the EU AI ActBinding, risk-tiered law with the highest fines in the world for non-compliance.
United StatesNo single federal AI law. Sector regulators (FDA, FAA, NHTSA, EEOC, FTC) plus ~38 states with their own AI statutes.Fragmented, sector-by-sector, enforcement-driven rather than pre-emptive.
ChinaCyberspace Administration of China (CAC), with the Ministry of Science and Technology and MIITContent and information-security controls; generative AI and recommendation algorithms must be registered with the state.
UAEFederal AI and Data Authority (newly consolidated, July 2026)Centralised single authority combining AI policy, digital economy, and data governance.
Global voluntary standardsNIST (US), ISO/IEC (international)Not law, but increasingly the reference architecture regulators and auditors expect companies to demonstrate against.

The practical implication: if you operate across even two of these jurisdictions, you don't have one AI compliance problem — you have four, and they don't agree with each other. A system that's compliant in the US under sector-specific rules can still be a high-risk system requiring conformity assessment in the EU, and a registrable algorithm in China.

The cost of getting this wrong

This isn't theoretical. The fines and enforcement actions are already happening.

€35M / 7%EU AI Act max fine for prohibited AI practices — whichever is higher, of global turnover
€15M / 3%EU AI Act fine tier for high-risk system non-compliance
$3.5B+paid by major tech companies in AI governance fines and settlements in the past year alone

Some of the enforcement actions already on the record this year:

The pattern across every one of these: it was never really about the AI model failing. It was about the absence of a human process wrapped around it — no oversight, no documentation, no accountable owner, no plan for what happens when something goes wrong.

"Every one of these cases has the same root cause. It's never really the model that fails — it's the absence of a human process wrapped around it. No owner, no oversight, no paper trail. That's not a technology gap. That's a management gap, and it's entirely fixable."

— Lisa Warren, Founder & CEO, Neural Horizons AI

What companies need to do now

None of this requires waiting for a mandate. The companies that will avoid becoming the next headline are putting the following in place now, not after an incident forces their hand.

The governance checklist

Lisa Warren: the bottom line

"Governance is not the tax you pay for using AI responsibly. It's the thing that lets you use AI at all, at scale, without it blowing up in your hands. The 8% of companies who've actually built this out aren't moving slower than everyone else — they're the ones who'll still be standing when the first wave of enforcement hits the other 92%."

— Lisa Warren, Founder & CEO, Neural Horizons AI

Why this can't wait

The EU AI Act's highest-risk provisions are already enforceable, and its high-risk system deadlines — even after this year's delay — now sit at December 2027 and August 2028. That sounds distant until you remember that conformity assessments, technical documentation, and governance infrastructure take months to build properly, not weeks. The US patchwork of roughly 38 state AI laws means new obligations are landing on an ongoing basis, not a single fixed date. And as we covered in this week's Wednesday AI Insights, China is actively positioning itself to shape global AI governance norms at this week's World AI Conference in Shanghai — whatever framework it proposes will influence how every multinational operating there has to comply.

None of these four regimes are waiting for companies to catch up. The only real choice a business has is whether it builds governance on its own terms, now, or has it imposed after an incident, a lawsuit, or a regulator does it for them.