Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

The AI Governance Report.

Ask who signs off deployment of an AI system that materially influences a decision about a person. The answer is usually a steering group, a forum, or a role that exists on a slide. Sixty-three per cent of breached organisations had no AI governance policy of any kind, and the harder problem sits inside the remaining thirty-seven. A committee can approve a direction, but it cannot be accountable, since accountability means one name against one decision and one date, which is the unit a conformity file is assembled from.

In depth

Governance Is Unowned More Often Than It Is Absent.

01

Committees approve, and then nobody is accountable.

Ask who signs off deployment of a system that materially influences a decision about a person, and the answer is normally a group rather than a person, which is comfortable for everybody in the room and useless to an assessor. Accountability means a single name against a decision and a date. The access numbers describe the same gap in technical form: only 40 per cent of organisations control access to their models and data, and fewer than half secure their non-human identities.

In shortfewer than half secure their non-human identities
02

An assessor cannot audit an intention.

High-risk conformity asks for artefacts instead: data governance records showing what the input data was and how it was checked, automatically generated logs retained for a defined period, human oversight that was genuinely in place, and post-market monitoring output. Each of those is retrospective, describing a stretch of operation that was either instrumented or was not. Sixteen months of operating history cannot be manufactured in the sixteenth month, whatever the document says.

In shortwhatever the document says
03

Shadow AI is a governance failure before it is a security one.

One in five breaches in 2025 traced back to unsanctioned tools, at a premium of roughly $670K over the average, which most teams read as an attack surface problem and stop there. The sharper reading is that an organisation with shadow AI cannot produce an inventory, and without one it cannot classify risk, assign an owner or say what it runs. Blocking tools does not produce that list, though a registration path faster than the workaround does.

In shortBlocking tools does not produce that list, though a…
The detail

Two Governance Patterns, And Only One Survives An Assessor.

Put the two side by side and the difference is not budget or sophistication. It is where the governance lives: in a document store, or in the deployment path, where the system cannot run at all without leaving the record behind it.

Zone · 01

Where the inventory comes from

In the first pattern it is a spreadsheet somebody maintains by hand, accurate on the day it was written and quietly wrong a quarter later. In the second it falls out of a model registry and a gateway that refuses unregistered calls, so the list is a consequence of operating rather than an act of goodwill by a busy team.

Zone · 02

Who carries the consequence

One named person owning a system end to end, its classification, its evaluation results, its incidents and its retirement, will refuse a system that cannot be logged, since they are the one who gets asked to explain a decision it made. A forum approves the same system, as no individual in it carries the result. The forum still sets policy and reviews exceptions.

Zone · 03

How the record is made

Evidence assembled when an auditor asks describes what people could remember and find. Evidence produced while operating describes what happened: every model version, prompt change and dataset swap logged and dated, oversight captured at the points where a human disagreed with the system, monitoring kept as a time series. The second kind cannot be written in a hurry.

By the numbers

The figures that make it a board-level conversation.

63%
of breached organisations had no AI governance policy of any kind
92%
of organisations with an AI-related breach had no proper controls on access to their AI systems
$4.99M
global average cost of a breach, up 12 per cent year on year
Inside the report

What you'll take away.

01

Step 1 - Build the inventory, including what nobody sanctioned

Every model, agent, embedded vendor feature and API call, with an owner, its data and whether a person is affected by the output. Read the network logs and the expense ledger, not just the survey responses.

02

Step 2 - Put one name against every system, in writing

Someone with the authority to stop it, not a function and not a forum. Publish the list where the board can see which systems still have nobody against them this quarter.

03

Step 3 - Switch logging on before the next policy draft

Inputs, outputs, model and prompt version, the reviewer and the decision that followed, kept for the period conformity expects. It is worth little today and a great deal in two years.

04

Step 4 - Refuse model access that did not come through the gateway

It generates the inventory for you, closes the shadow AI path that carried a $670K premium in 2025, and supplies the access control that 92 per cent of AI breach victims turned out to lack.

Questions

Frequently asked.

We already have an AI policy, so what is actually missing?

Usually the operating record. A policy states a position, and a conformity review asks for dated artefacts: input data records, generated logs, oversight decisions and monitoring output covering a period of real use. If those are assembled by hand when somebody asks, you have a position rather than evidence.

Why is a governance committee not enough to own an AI system?

A committee can approve a direction and review exceptions, and both are useful. It cannot be the accountable party, since a conformity file records who decided what and when. Name one person per system with authority to stop it. Systems that nobody will put their name against are the ones worth looking at first.

The high-risk deadline moved to December 2027, so why start this quarter?

The obligations are retrospective. Logs, monitoring and oversight records describe how a system has been run, so their value accrues month by month and cannot be backdated. Teams that carried on instrumenting in 2026 will arrive with years of record. Teams that paused will arrive with a binder.

How do we handle shadow AI without banning the tools people want?

Make the sanctioned route faster than the workaround. A registration path that takes a morning, a gateway that refuses unregistered calls, and a short list of approved models will reclaim more usage than a block list. Unsanctioned tools carried a $670K premium on breaches in 2025, so this pays for itself.

How does this report differ from your other AI governance papers?

This one is the board position: who owns what, and why documents fail an assessor. AI Governance Under Regulation covers the duties and dates in detail, and AI Governance: An Engineering Reference is the control catalogue that produces the evidence. Read this for the argument, those two for the specifics.

Who should be reading this?

Boards, executives and heads of risk who have to answer for AI outcomes without owning the systems that produce them. It assumes no technical background and takes a position rather than listing options, so it is short enough to read before a board meeting and specific enough to act on afterwards.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send The AI Governance Report straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

A committee cannot sign the file, so give every system a name.

Bring your highest-risk system and we will walk through who owns it, what it records, and what an assessor would be handed today. Ninety minutes with the engineers who build these systems, no deck. SECTION 7 - FAQ - 5 to 8 questions

Book a governance review