Companies across industries and sizes are eagerly adopting artificial intelligence (AI) to gain advantages in operational excellence, employee engagement and cost efficiency. These benefits, however, depend on identifying and managing AI‑related risks; without proper governance organisations can face severe consequences such as loss of shareholder trust, declining customer satisfaction and financial or reputational harm from non‑compliance with applicable laws.
Risks of siloed AI adoption
During the initial ‘gold rush’ phase of AI adoption, organisations encounter significant challenges when different business units deploy AI in silos. Key problems include:
- the absence of consistent, organisation‑wide assessment of risks at the application and portfolio levels;
- lack of role‑specific AI knowledge among employees;
- weakened coordination between critical functions involved in AI risk management, such as data, security and compliance teams.
These gaps can leave organisations operating blindly and unprepared when AI incidents occur, with potentially far‑reaching consequences.
Questions organisations should ask themselves
Decision‑makers and leaders should frankly consider questions such as:
- Is there a function or role that has visibility over existing and planned AI initiatives and can detect unauthorized AI usage?
- Have we treated compliance with the EU AI Act and other interdisciplinary regulations as a priority when identifying AI use cases and planning deployments across the AI business value chain?
- Do employees understand the rules and risks of AI use as they relate to their roles?
Honest answers to these questions may require rethinking governance and oversight structures for AI system development, deployment and operation, and reallocating responsibilities accordingly.
What good AI governance looks like
Building an effective AI governance framework is a substantial task. Important elements include:
- comprehensive knowledge of legal, technical, ethical and other risk frameworks and methodologies;
- maturity in data‑asset management and information security;
- a coordination model that fosters close links among stakeholders, enables effective communication, incident management and information sharing;
- well‑documented processes so the organisation has near‑real‑time awareness of risks across its AI portfolio.
Available guidance and practical considerations
Guidance for implementing good practices is widely available: on regulators’ websites, AI model providers’ platforms, the NIST AI risk management guides, ISO/IEC standards on AI management and AI risk management, and the OECD AI principles, among others. However, the abundance of guidance can itself complicate implementation, and many organisations end up adopting overly complex, disproportionately bureaucratic processes.
PwC experts caution that AI governance design must reflect corporate specifics: organisational culture, customer characteristics, the risks of deployed models and planned use cases, as well as sectoral regulations and expectations under the EU AI Act for supervising AI systems at different risk levels.
Finding the right balance
While AI adoption is highly visible, governance structures often lag. The biggest challenge is finding the middle ground: regulating AI without stifling organisational innovation. Clear guidance for employees about permitted and prohibited uses of the technology is essential; without it, individuals experiment with ad‑hoc solutions that tend to operate in isolation rather than building on each other.
Which teams should lead?
Many organisations rely on data governance or data protection teams, adopting or integrating their established practices when building AI governance — the oversight for AI systems. The PwC Responsible AI Insights series provides practical perspectives from technology experts to help shape AI governance and understand related risks.
Leaders accountable for AI governance can use these practical recommendations to develop risk management and governance processes tailored to their organisations’ circumstances and complexity, enabling AI use that is ethical, sustainable and delivers real business value.


