AI Security Governance:
From EU AI Act to Shadow AI - What Your Organization Must Get Right Before AI Becomes a Liability

Most organizations are deploying AI faster than they can govern it. The EU AI Act is in force. Shadow AI is already inside your network. The board is asking questions no one can answer. This is what getting it right actually looks like.

Executive Answer

AI governance is not an IT problem - it's a board accountability problem. 78% of organizations are unready for EU AI Act enforcement that began August 2026. The CISO's job is to build an AI inventory, classify systems by risk tier, implement access controls on AI tool usage, and ensure the board understands which AI deployments create regulatory exposure. Most don't know where to start.

Asaf's Perspective

Every organization I work with has the same problem: AI adoption is happening at the speed of individual employee decisions, and governance is happening at the speed of committee approvals. That gap is where the risk lives. The EU AI Act didn't create a new compliance framework - it created a regulatory forcing function for something organizations should have done in 2023. An AI inventory. A risk classification. An acceptable-use policy with teeth. A board that understands which AI deployments are inside the regulatory perimeter and which ones are creating exposure they don't know about. The organizations that will navigate this well are not the ones with the most sophisticated AI programs. They're the ones that built governance infrastructure before the regulator arrived.

What AI Governance Actually Requires

Governance is not a policy document. It is a set of operational controls with ownership, monitoring, and enforcement. These are the six components that matter.

AI System Inventory

A complete register of every AI and ML system in use - including AI embedded in SaaS tools. Without knowing what you have, you cannot govern it, classify it, or report on it to regulators.

Risk Classification (EU AI Act Tiers)

Map each system against EU AI Act risk categories: unacceptable risk (prohibited), high-risk (Annex III), limited risk, and minimal risk. Classification determines the compliance obligations that apply.

Shadow AI Detection

Use DLP and network monitoring to identify unapproved AI tool usage. Most organizations have significant shadow AI activity before they look. Detection is the prerequisite for governance.

Data Governance for AI Inputs

Classify what data categories are permitted as inputs to which AI systems. Confidential data, customer PII, and source code require explicit policy - employees will not self-regulate without it.

Board & Regulatory Reporting

The board needs a clear view of which AI deployments create regulatory exposure, what the organization's EU AI Act compliance posture is, and what incidents have occurred. This is a board governance obligation, not an IT report.

Incident Response for AI Failures

AI systems fail in novel ways: hallucinations, prompt injection, model poisoning, output manipulation. IR plans that don't account for AI-specific failure modes are incomplete.

The EU AI Act Timeline

The EU AI Act entered into force in August 2024. Enforcement is phased - knowing which deadline applies to your organization is the first step.

1
February 2025 - Prohibited AI practices

AI systems classified as unacceptable risk are prohibited. This includes social scoring systems, real-time biometric surveillance in public spaces (with narrow exceptions), and AI that exploits psychological vulnerabilities.

2
August 2025 - GPAI model obligations

General-purpose AI models (like those powering enterprise AI tools) must comply with transparency, copyright, and systemic-risk obligations. Providers of GPAI models with systemic risk face additional requirements.

3
August 2026 - High-risk AI systems (Annex III)

Full obligations apply to high-risk AI systems. This is the deadline that most enterprise organizations are racing toward - or ignoring. Conformity assessments, technical documentation, human oversight, and registration in the EU AI Act database are required before deployment.

4
2027 - Regulated sector AI

AI systems embedded in products already covered by EU safety legislation (medical devices, machinery, vehicles) face compliance requirements by 2027 under the product-specific timelines.

Three AI Governance Failures I See Most Often

These are not edge cases. They appear in the majority of organizations I assess, regardless of size or sector.

  1. 01
    No AI inventory - at all

    Organizations have a security asset inventory for servers and endpoints. They have no equivalent for AI systems. When I ask "what AI is running in your environment?", the answer is almost always a list of three or four tools the security team knows about - not a comprehensive register. Shadow AI tools, AI features embedded in SaaS products, and AI used by departments without IT involvement are invisible. You cannot govern what you cannot see.

  2. 02
    Acceptable-use policy that no one reads

    Many organizations produced an AI policy in 2023 or 2024 and considered governance complete. The policy prohibits entering confidential data into external AI. Employees continue to do exactly that, because there is no monitoring, no enforcement, and no approved alternative provided. A policy without detection and consequence is a document, not a control.

  3. 03
    Board that does not know its EU AI Act exposure

    The EU AI Act creates personal liability for board members at organizations operating high-risk AI systems without required controls. Most boards have not received a briefing that maps the organization's AI systems to the Act's risk tiers, identifies which deployments are non-compliant, and quantifies the regulatory exposure. The CISO's job is to put that briefing in front of the board before a regulator does.

Frequently Asked Questions

Which AI systems are considered high-risk under the EU AI Act?

EU AI Act Annex III defines 8 categories of high-risk AI: biometric identification, critical infrastructure management, education/training, employment/HR, essential services, law enforcement, migration/border control, and administration of justice. Most enterprise AI - especially HR tools that score candidates, credit scoring systems, and AI used in regulated sectors - falls into these categories. Organizations must conduct a conformity assessment before deployment.

How should a company build an AI inventory?

An AI inventory should capture every system that uses AI or ML, including third-party tools embedded in SaaS products. For each system: the vendor, the data inputs, the outputs and decisions it influences, whether it falls under EU AI Act high-risk categories, who owns it, and what monitoring is in place. The inventory is a living document - new AI deployments must be registered before going live.

Who should own AI governance in an organization?

AI governance ownership typically sits between the CISO and the DPO, with executive sponsorship from the CEO or CTO. The CISO owns the security and risk components - access controls, data leakage prevention, adversarial testing. The DPO owns the privacy and regulatory compliance components. Where an AI ethics or AI governance function exists, it coordinates policy. Without explicit ownership, AI governance remains a document no one enforces.

What should an AI acceptable-use policy contain?

An AI acceptable-use policy should define: approved tools (and the approval process for new ones), prohibited use cases (entering confidential data, customer PII, or source code into external AI), classification rules for AI inputs, exceptions and escalation paths, and consequences for policy violations. It should be reviewed annually and updated as the tool landscape changes - the tools available in 2026 are fundamentally different from 2023.

How should Shadow AI be managed?

Shadow AI - employees using unapproved AI tools - cannot be eliminated, only governed. The practical approach is: detect (use DLP and network monitoring to identify AI tool usage), assess (classify detected tools by data risk), legitimize (create a fast-track approval process for low-risk tools), and train (security awareness that addresses AI risk specifically). Blocking tools without an alternative typically drives usage further underground.

Does Your Organization Know Its AI Governance Exposure?

If you don't have an AI inventory, a board-ready EU AI Act briefing, or a working shadow AI detection program - let's fix that before a regulator does it for you.

Start a Conversation