CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running

Boards want AI returns. Employees want access. Compliance teams want guardrails. The CIO is caught between all three.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
CIOs Are Running AI Governance Without a Playbook — and the Clock Is Running
Share

Key points

  • Nearly two-thirds of senior leaders report more pressure to prove AI ROI than a year ago, per Kyndryl's 2025 Readiness Report.
  • AI's indeterminate behaviour breaks traditional IT control models built for deterministic systems.
  • Employees across sales, finance and marketing are routing around IT to access AI tools, creating shadow-use exposure.
  • Formal risk registers and contract scrutiny with AI providers are concrete governance steps most organisations are skipping.
  • Hi Marley's "conflict by design" structure keeps innovation and compliance teams deliberately separate, with unresolved disputes going to the CEO.

Why is AI governance so hard to get right?

The pressure isn't subtle. Nearly two-thirds of senior leaders say they face more scrutiny to prove ROI on AI investments than a year ago, according to Kyndryl's 2025 Readiness Report. CEOs are naming AI capitalisation as the top mandate for their IT chiefs. And employees across sales, finance and marketing want in.

Jonathan Tushman, CAIO and CTO at Hi Marley, a conversational platform for the property and casualty insurance sector, added the CAIO title to his remit eighteen months ago. Urgency has sharpened considerably in the last six.

What makes AI risk different from ordinary IT risk?

Tushman identifies two features that break traditional IT governance. First, AI is indeterminate. Most enterprise technology is deterministic: you can set controls and verify behaviour. AI doesn't work that way. "You can't prove an AI system will or won't do X," he told CIO.com, "so the traditional 'put controls around it and verify' model breaks down." Second, users won't wait. If IT takes its usual evaluation timeline, employees route around it. Shadow use, Tushman argues, creates more exposure than a controlled rollout ever would. Our June piece "Shadow AI Is the Governance Gap Nobody Wants to Admit" made the same point before most organisations had a policy to address it.

Should you worry about third-party AI contracts?

Tony Vizza, founder of advisory firm Novera, names the failure mode plainly: staff pasting sensitive data into public tools, or copying AI output directly into customer deliverables without checking it. Both flow from the same root cause, adoption without governance architecture.

Vizza recommends anchoring AI decisions to a formal risk register. Define expected outcomes and investment size before any deployment. Third-party accountability is a specific gap he flags: contracts with AI providers need scrutiny on who bears liability in a data breach. "Some organisations build that into their risk management process," he told CSO Online. "Others are quite flippant or don't even know they should be asking those questions."

How should organisations structure AI oversight?

At Hi Marley, the answer is structural. AI adopters in product and technical teams are kept separate from oversight functions in compliance and legal. Compliance owns audits. Legal owns boundary documentation. Disagreements go to a senior leadership forum; unresolved ones escalate to the CEO. Tushman calls it "conflict by design," and it is not a committee built for consensus.

Karthik Chakkarapani, SVP and CIO at Zuora, three years into its AI programme, frames it similarly. "You have to build the highway with enough guardrails and fewer speed breakers," he told CSO Online.

The organisational design choices made now will compound. Getting the structure right early, Tushman believes, is itself a durable competitive advantage. The companies that don't won't just face compliance problems. They'll be slower when the models improve again.

© 2026 Threat Vectr