By Sergei Zhmako, Executive Vice President, IBA Group.
AI adoption is accelerating in almost every organization. Employees use AI tools to summarize documents, analyze information, draft communications, and automate routine work. For many enterprises, this is already happening regardless of whether formal AI initiatives have been launched.
The challenge is that AI adoption often moves faster than governance, while many leadership teams still have limited visibility into how AI is being adopted across the business. They often cannot confidently determine which tools employees use, what information is being shared externally, which business processes increasingly depend on third-party models, or under whose jurisdiction corporate information may ultimately fall.
Without this visibility, it becomes significantly more difficult to assess risk, establish meaningful policies, or make informed governance decisions. The issue, therefore, is often not AI adoption itself but the lack of organizational awareness surrounding it.
AI adoption has become increasingly decentralized, with employees experimenting independently and departments establishing their own practices. Employees experiment with different tools independently, individual departments establish their own practices, and productivity gains often emerge faster than organizational controls can adapt. As a result, leadership teams may find themselves managing a technology that has already become embedded in everyday operations before clear policies, accountability structures, or risk frameworks have been established.
AI Adoption Is Already Happening: With or Without Policy
Shadow AI is rapidly becoming a normal part of organizational life, often emerging long before formal policies or governance structures are established. Employees frequently paste contracts into public AI tools to summarize key clauses. Finance teams use AI to refine presentations and analyze forecasts. Product teams upload internal documentation to generate specifications or reports.
Most of these actions are not malicious. They are often driven by a desire to improve productivity. However, every interaction raises important governance questions around data location, jurisdiction, access rights, and organizational visibility. Many companies still lack clear answers to these issues, turning AI adoption into a governance challenge rather than merely a technology initiative.
Public AI Introduces New Data Exposure Risks
Public AI platforms undoubtedly create significant productivity opportunities. At the same time, they introduce governance questions that leadership is only beginning to recognize.
When information leaves an organization’s controlled environment, leadership teams need to consider issues that traditionally belonged to cloud governance and third-party risk management.
Public AI also introduces a new layer of jurisdictional complexity. Information may be processed under legal regimes that differ from those governing the organization itself, creating additional obligations around data residency, disclosure requirements, and cross-border compliance. For multinational companies, understanding where data ultimately resides is becoming increasingly important. This issue extends beyond compliance requirements alone.
Questions surrounding data sovereignty, extraterritorial legislation, and cross-border access to information are increasingly becoming strategic concerns for multinational organizations. The same discussions that previously surrounded cloud infrastructure are now emerging in the context of AI. Leadership teams are beginning to recognize that decisions regarding AI deployment models may have long-term implications for governance, resilience, and regulatory exposure.
However, many existing compliance frameworks were not designed with generative AI in mind. Organizations are now being forced to reconsider whether their current governance models adequately address AI-driven data flows and third-party processing.
Another important consideration is intellectual property. Employees increasingly use AI tools to work with internal documents, strategies, customer information, and operational knowledge. Without clear oversight mechanisms, organizations may inadvertently expose some of their most valuable assets.
AI Is Becoming a Board-Level Discussion
One of the biggest misconceptions surrounding AI is that it remains primarily an IT responsibility.
In practice, AI raises familiar executive questions around acceptable risk, external processing of information, employee behavior, and accountability. These discussions increasingly sit at the intersection of legal, compliance, security, and executive leadership.
Technical teams may implement controls, but risk appetite and governance frameworks remain leadership responsibilities.
Organizations that already have mature approaches to cloud governance, data classification, and third-party risk management are generally in a stronger position to extend these principles to AI.
AI does not create entirely new governance risks. Most organizations have long struggled with questions around data ownership, information flows, third-party access, and whether internal policies truly reflect how employees work in practice. Generative AI simply accelerates and amplifies these existing weaknesses.
Leadership teams are discovering that the challenge is not AI itself, but rather the limited visibility they already had into how knowledge moves across the organization. In this sense, AI behaves less like a new category of risk and more like an organizational stress test, exposing governance gaps that may have existed for years but remained largely invisible.
Fragmented ownership of information, inconsistent data classification practices, and limited visibility into knowledge flows existed long before generative AI emerged. Generative AI has simply made these weaknesses more visible and, in some cases, more consequential. In this sense, AI adoption often reveals organizational maturity issues that extend far beyond technology itself.
When Private AI Becomes Relevant
Private AI deployment is not necessary for every use case. For many organizations working primarily with public information and lower-risk workloads, public AI tools may represent a reasonable balance between productivity and risk.
Additional controls become increasingly relevant when organizations operate in regulated environments, handle sensitive customer information, depend heavily on proprietary intellectual property, or face strict data residency requirements. In such cases, the discussion shifts from productivity toward governance, auditability, and risk management.
The key question is not whether private AI is universally better. The question is whether an organization’s risk profile justifies additional levels of control.
Building Governance Before Regulation Forces It
Regulatory expectations around AI are evolving rapidly, often creating uncertainty for organizations attempting to define long-term governance approaches.
Waiting for complete regulatory clarity may prove challenging.
Organizations that postpone governance decisions often find themselves implementing policies under external pressure rather than as part of a deliberate strategy.
A more practical approach is to begin by understanding what types of information employees currently use with AI tools, which activities create meaningful legal or competitive exposure, and whether existing governance frameworks provide sufficient visibility into AI usage patterns. Organizations that answer these questions early will have significantly greater flexibility as regulatory expectations continue to mature.
From Technology Question to Governance Priority
The most important realization for many organizations is that AI adoption is no longer purely a technology initiative.
It is becoming a governance issue.
The central challenge is not whether AI should be used. Most organizations have already crossed that threshold.
The challenge is maintaining control over where corporate knowledge resides, who governs access to it, and how associated risks are managed.
Organizations that treat AI purely as a technology initiative may eventually discover that their biggest challenges are not technical at all.
They are questions of governance, accountability, and control. The organizations that benefit most from AI over the coming years may not be the fastest adopters, but those that approach AI deliberately – building governance, accountability, and visibility before regulation, compliance requirements, or security incidents force their hand.





