Artificial intelligence adoption is accelerating faster than most organizations can govern it. Globally, generative AI tools are already embedded into daily operations, often long before organizations have fully assessed the risks they introduce. Recent research highlighted by TechRadar found that almost a third of European businesses still do not have a formal AI policy in place, despite growing AI adoption across professional environments. The governance gap is already operational.
For cybersecurity, information security professionals and leaders, this creates a familiar challenge. New technology has entered organizations at speed, while governance, oversight, and accountability struggle to keep pace. The difference with AI is the scale, accessibility, and autonomy involved. Employees no longer need specialist technical expertise to deploy powerful AI capabilities into business processes. In many cases, they simply open a browser tab.
This challenge is particularly visible among small and medium-sized enterprises. SMEs represent the largest portion of the business ecosystem, yet many operate with limited governance resources, overstretched teams, and growing compliance obligations. AI tools promise productivity gains and operational efficiencies, which makes adoption difficult to resist. However, AI adoption without governance creates cyber, operational, and legal risk that many organizations are still underestimating.
The European Union has recognized these risks and responded with an expanding regulatory ecosystem that includes the EU AI Act, the NIS2 Directive, the Digital Operational Resilience Act (DORA), and the Cyber Resilience Act (CRA). Together, these frameworks signal a clear expectation. Organizations must be able to understand, govern, and account for how AI systems operate within their environments.
The challenge now lies in operationalizing those expectations in ways organizations can realistically implement.
A Tangle of Frameworks with One Shared Objective
At first glance, the European regulatory landscape can appear fragmented. Organizations are trying to interpret overlapping obligations across multiple frameworks, each with its own terminology, scope, and enforcement mechanisms. Yet underneath this complexity sits a consistent message. AI governance and cyber resilience are now inseparable.
The EU AI Act introduces a risk-based model for AI systems, placing greater obligations on organizations deploying high-risk AI applications. Requirements around transparency, human oversight, risk management, technical documentation, and monitoring are becoming central governance expectations. While implementation timelines continue to evolve, with aspects of the Act now extending into 2027, organizations are already feeling its influence through procurement requirements, board scrutiny, and customer expectations.
NIS2 reinforces management accountability for cybersecurity risk management measures and raises expectations around governance oversight and training. DORA extends operational resilience obligations across the financial sector, placing strong emphasis on ICT risk management and third-party oversight. The Cyber Resilience Act pushes secure-by-design principles further into products with digital components.
These frameworks are often discussed separately. In practice, they overlap continuously. An organization cannot effectively manage cyber resilience while ignoring the governance risks introduced by AI systems. Equally, AI governance disconnected from cybersecurity processes quickly becomes ineffective.
This is where implementation standards such as ISO/IEC 42001 become increasingly important. Many organizations still view standards primarily as compliance exercises. In reality, a formal AI management system provides structure, accountability, and repeatability around how AI is governed operationally. It creates mechanisms for oversight, risk assessment, continuous improvement, and role clarity. These are foundational operational controls.
For many organizations, especially SMEs, implementation remains the difficult part.
When Governance Fails in Practice
AI governance failures are often discussed in abstract language. Their consequences are deeply practical and sometimes harmful.
One of the most widely cited examples involved Amazon’s experimental AI recruiting tool, which was ultimately scrapped after researchers discovered it systematically downgraded CVs from women. The system had been trained on historical recruitment data that reflected existing gender imbalances within the technology sector. The issue was not malicious intent. It was a governance failure involving oversight, testing, and accountability.
Healthcare has faced similar problems. Research examining AI skin cancer diagnostic tools found significantly lower accuracy rates for patients with darker skin tones because training datasets were heavily skewed toward lighter skin. The implications extend beyond technical performance. In regulated sectors, failures like these create legal exposure, reputational damage, and potential harm to individuals.
Most organizations do not intentionally create governance gaps. They emerge gradually through convenience, speed, and lack of visibility. This is particularly true with generative AI.
Many organizations are now dealing with “shadow AI” environments where employees independently adopt AI tools without formal approval, governance review, or security assessment. Staff may upload sensitive information into public AI platforms, use AI-generated outputs within decision-making processes, or automate workflows without fully understanding how data is being processed or retained.
For cybersecurity professionals, this creates familiar concerns around data leakage, access control, third-party risk, and incident response. The challenge becomes more complicated when accountability is unclear. If an employee uses an unsanctioned AI tool that contributes to a security incident or regulatory breach, who is responsible? The employee? The manager? The organization? Governance frameworks increasingly place that responsibility at organizational level.
This is why AI governance cannot remain siloed within innovation teams or legal departments. It must become part of operational resilience strategy.
What AI Accountability Looks Like in Practice?
Many organizations assume AI governance requires complex structures or large compliance programs. In practice, accountability often begins with relatively straightforward operational steps.
The first requirement is visibility. Organizations need to understand where AI is already being used. Most are further along in AI adoption than they realize. Conducting a simple inventory of AI systems, use cases, and data flows often reveals shadow AI activity that leadership was previously unaware of.
The second requirement is ownership. Someone within the organization must be accountable for overseeing AI governance activities. This does not necessarily require a dedicated AI department. Smaller organizations may integrate responsibility into existing cybersecurity, compliance, or risk functions. The important factor is clarity.
The third requirement is integration. AI risk should sit within existing cybersecurity and enterprise risk management processes rather than operate separately. AI systems interact directly with data governance, access management, incident response, supplier management, and business continuity. Governance structures work far better when AI becomes part of existing resilience processes rather than a parallel initiative.
The fourth requirement is usability. This is where many organizations struggle. Governance frameworks and standards are often interpreted as overly technical or resource intensive, particularly within SMEs. Organizations need practical implementation pathways that scale according to operational size and maturity.
This is another reason implementation standards matter. ISO/IEC 42001 helps translate broad governance expectations into manageable operational activities. It provides a structured management system approach that organizations can adapt to their own context rather than forcing them into rigid one-size-fits-all controls.
Culture also matters significantly. Employees need to understand that AI use carries responsibilities alongside benefits. Awareness programs should focus not only on compliance obligations but also on practical risks, ethical considerations, and operational accountability. Governance becomes far more effective when staff understand why controls exist rather than viewing them purely as restrictions.
Start Somewhere: The Governance Gap Assessment
Many organizations delay AI governance initiatives because the problem feels too large or too complex. The most effective starting point is often a simple governance gap assessment.
Organizations should begin by asking practical questions. Do we know which AI tools are already being used internally? Do we have an AI policy? Have we assessed how AI systems interact with sensitive information? Who oversees AI-related risks? Are suppliers using AI within services we rely upon?
These conversations alone often reveal important governance blind spots.
For SMEs especially, progress matters more than perfection. Many organizations are still early in their governance maturity journey. Building visibility, accountability, and basic operational controls provides a much stronger foundation than waiting for complete regulatory certainty.
Cybersecurity and Information Security professionals are well positioned to lead these conversations because many underlying governance principles are already familiar. Risk management, accountability, continuous improvement, supplier oversight, and resilience are longstanding cybersecurity disciplines. AI governance extends these concepts into a rapidly evolving technological environment.
Building Expertise and Capability
Technology governance always depends on people. Organizations need professionals who can interpret evolving obligations, translate governance requirements into operational processes, and guide leadership through implementation challenges.
This is where training and professional development become increasingly valuable. Certifications such as the PECB ISO/IEC 42001 Foundation and Lead Implementer programs help professionals understand how AI management systems can be implemented in practice. Programs such as Certified AI Risk Manager, Certified AI Manager, and Certified AI Professional also help bridge the gap between technical understanding and operational governance capability.
Professional communities matter as well. Many organizations are facing similar implementation questions around AI governance, accountability, and operational resilience. Engaging with industry groups, professional associations, regulators, and local cybersecurity communities helps organizations avoid solving these challenges in isolation.
The reality is that everyone is learning in real time. The regulatory environment continues to evolve, technologies continue to mature, and organizational use cases continue to expand. That uncertainty can feel uncomfortable, but cybersecurity professionals have navigated similar transitions before.
We Are All Building This Together
The European Union has established a strong foundation for AI governance and cyber resilience. The next phase is operational maturity.
Policies, regulations, and standards only become effective when they are translated into everyday organizational practice. Accountability must move beyond documentation and become embedded into operational decision-making, governance structures, and organizational culture.
For SMEs, this challenge is especially important because they form such a large part of the European economy while often operating with fewer resources and limited specialist expertise. They cannot be left behind in the governance conversation.
The encouraging reality is that organizations do not need to solve everything immediately. Progress begins with visibility, ownership, practical controls, and a willingness to engage with the problem honestly.
Cybersecurity and information security professionals already understand resilience, governance, accountability, and risk. AI governance builds upon those foundations rather than replacing them. The challenge now is making those principles operational within environments increasingly shaped by artificial intelligence.
The organizations that succeed will not necessarily be the ones with the largest budgets or the most advanced technology. They will be the ones that embed accountability early, treat governance as an operational capability, and recognize that trustworthy AI depends as much on people and processes as it does on technology itself.







