Nobody Owns the Risk: Why AI Governance Keeps Falling Through the Gap
by Amber Williams
RiverSafe in conversation with Sapna Patel, Technology and Cyber Leader, Board Advisor
Ask a CISO who owns AI risk in their organisation and you will often get a complicated answer, or a silence that says more than any answer could. Sapna Patel, technology and cyber leader and board advisor, thinks that ambiguity is one of the most pressing problems in security right now and it is getting worse as adoption accelerates.
“It depends on the organisation,” she says, “but I think it is a combination of teams. It is the business operations that implemented or switched on the AI, and it is data protection, whoever is responsible for data governance in the organisation. But that is a collaborative responsibility. The main thing is: you cannot be responsible for the risk, or your share of that risk, if you are unaware of it.”
If there is shadow AI in use, tools adopted by teams without formal approval or any security review, the risk is effectively unowned. Nobody is watching it, nobody is accounting for it, and nobody will be ready when something goes wrong.
FOMO is driving decisions that security cannot keep up with
When asked what is really driving the pace of AI adoption, Patel rejects the obvious answer.
“I don’t think it is quite speed to market. I think it is more FOMO. AI FOMO. It is like organisations saying: we don’t want to be making our own coffee in the morning while everyone else is doing things with AI. Let’s hurry up and match the Joneses.”
The problem with FOMO as a driver is that it bypasses the question of genuine use case. “AI is intelligent little decision makers, not traditional automation. The question should be: what is the actual use case, and what efficiency and return on investment will this provide? FOMO itself should not be a driver.”
This has a direct impact on governance. When AI tools are introduced to tick a box or keep up with competitors, the security questions come later, often much later, and often after something has already gone wrong.
“No one I have spoken to doesn’t understand the need for safety. Maybe some don’t understand the breadth and depth of that safety and those guardrails, but that is on us to make sure it is understood and explained, just as we explain technology and cybersecurity in non-technical terms.”
The problem then is less about wilful ignorance and more about the gap between a surface-level understanding of “we need governance” and a working grasp of what governance actually involves. When leaders sign off on an AI tool because it passed a vendor security review, they may believe they have done their due diligence. In practice, that might cover five percent of what sound governance requires.
Trust cannot do the job you are asking it to do
One of the more striking observations from Patel is on the question of trust. Can you trust an AI system to stay within its boundaries once it has been set up correctly?
“With AI, because it is autonomous and works on its own and makes decisions, you cannot trust it. You cannot know it can be trusted. You put in the guardrails, and then it carries on. Whether it behaves in the way you would like it to, without causing problems, you cannot know.”
This has obvious implications for how AI systems should be treated from a security architecture standpoint. Systems you cannot trust should not be given access they do not need. Their outputs should be checked. Their interactions with other systems should be logged. None of this is new thinking, it is standard practice for any untrusted third-party system. The question is whether AI is actually being treated that way inside your organisation.
Will regulation fix it?
Patel is measured on this. She believes frameworks like the EU AI Act will push corporate behaviour where they apply, but only if enforcement looks like GDPR. “What will stop it being a tick-box exercise is if the fines come in place. That is what made GDPR beyond just a tick-box exercise.”
The wider problem is regulatory geography. AI development continues at pace in regions with lighter oversight, and organisations buy technology globally. “We live in a world where we buy our tech products from outside the EU and UK. That disparity will be a problem if we want to have consistent AI governance.”
The honest conclusion is that external regulation will help at the margins, but it will not substitute for the internal decisions that organisations have been deferring. Knowing who owns the risk, building a responsibility matrix that actually works and treating AI systems the way you would treat any other system that makes consequential decisions with your data. That work cannot be outsourced to a regulator. It has to happen inside the building.
This is part two of a three-part series drawn from RiverSafe’s Secure in the Knowledge podcast. Part one covers real-world AI incidents and the limits of human oversight. Part three looks at what good AI governance actually looks like in practice.