Fragmented ownership is a problem, according to Dickinson Wright’s Jodka. Legal-only ownership can set standards but can’t enforce controls in code. IT-only ownership fails because AI governance spans privacy, discrimination, IP, cybersecurity, and regulatory risk. Committee-only ownership “often becomes slow and performative,” Jodka says. She recommends a three-line model: builders own the systems they deploy; legal, security, and compliance set standards and review high-risk uses; and internal audit tests whether the program actually works.

The coordination challenge is real, agrees Aslam Rawoof, a partner at Benesch Law. “AI cuts across all facets of the organization. It can’t be owned by tech or legal alone,” he says. “You literally need a committee that meets regularly — legal, tech, finance — and reports up to the CEO if not the board.”

The back-end blind spot

Governance tends to focus on the front end: approving tools and writing acceptable-use policies. But the back end — knowing when to turn something off — gets far less attention. In fact, per CSA, only 21% of organizations have formal decommissioning processes for AI agents, and the associated risks compound over time.