Blog - nuwacom

Why companies need AI governance

AI has arrived in everyday work, and most companies now know they stand to benefit from it. Where things stall is in steering it: bringing structure to how AI is used across the organization instead of leaving it to chance.

In Cisco’s AI Readiness Index from late 2025, only 12 percent of the companies surveyed said they had mature governance structures in place.

By now the number is probably a little higher. Even so, the bar remains high, and many still see the topic as a compliance question and a bureaucratic burden. Set up correctly, it is the opposite. It is the precondition for companies to use AI productively and to bring their people along in the process.

Without Governance, Individuals Decide How AI Gets Used

When clear structures are missing, one symptom shows up first: shadow AI. That is, the use of AI tools by individual employees without the company knowing about it. There is rarely bad intent behind it. Quite the opposite: usually it is the drive to get one’s own work done better and faster.

According to Bitkom, four in ten companies assume that private AI tools are already in use. Reliable measurement is difficult. The first reflex, banning AI, backfires here: usage simply shifts further into the private sphere, and the company increasingly loses control over data and permissions.

A ban only works once the officially approved offering is good enough that employees have no reason left to reach for private tools.

Sascha Scheffler, AI Act Webinar

The loss of control is one thing, the legal risk another. If sensitive data or trade secrets end up in private AI tools, violations of the GDPR or of obligations under the AI Act can quickly follow. And even when individual employees trigger these violations, it is usually the company that is liable as the responsible party.

The risk of shadow AI therefore lands above all on the leadership level. Gartner expects that by 2030, four in ten companies will experience a compliance incident related to shadow AI. Governance is, first of all, an answer to legal requirements.

Compliance and the AI Act: The Legal Obligations

The first step toward governance is an honest inventory: which AI tools are being used, in which use cases, with which data, with which responsibilities, and with which risks.

The AI Act requires that every company deploying AI knows its role, in most cases that of the deployer.

Depending on the application, usage falls into different risk classes that call for corresponding safeguards. Anyone who also processes personal data with AI must comply with the GDPR in doing so.

Governance therefore also covers data flows, access rights, the choice of providers, storage, deletion concepts, and auditability.

The AI Act does not prescribe a specific organizational structure. What matters are clear responsibilities and the clean classification of high-risk applications.

Compliance is a good reason for governance. But the potential reaches far beyond the question of whether a company is acting in a legally correct way.

Acceptance and Culture: Why Adoption Fails on People, Not Technology

The best tool is of little use if no one uses it. An underestimated reason for AI governance is therefore to create a structure that takes fears seriously and enables teams to work well with AI.

Whether and how AI is adopted depends less on the technology than on the culture and the offering around it. A central factor here is transparency about the goals. In most companies, deploying AI is not about shrinking teams, but about preserving knowledge, responding to demographic change, and making work better for everyone.

That does not make individual employees’ fears of being displaced unfounded, but it shows how much depends on clear communication.

At its core, resistance is a trust problem, and it slows down every attempt to introduce AI across the organization. Those who communicate clearly create room and trust, and with it the foundation on which adoption can work at all.

The second lever is training. While some employees have been working intensively with AI for months, others are still at the very beginning. Reducing these gaps is also a task of governance.

The more people are enabled to work with the tools themselves, the sooner they gather their own moments of success, which in turn sustains adoption. Basic knowledge supports responsible use and ultimately benefits everyone.

Who Owns AI Governance?

Governance is often thought of as a pure compliance topic. In reality it reaches far beyond that and should be carried by people responsible across different areas: IT, data protection, legal, HR, the business units, and leadership.

Leadership should be actively involved, not least because companies with leadership-driven governance achieve more business value. But top-down alone is not enough for AI to truly land in every area.

It also needs bottom-up approaches such as AI champions in the individual departments. They prevent the introduction of tools that are generally useful but designed past the realities of daily work.

A purely bottom-up approach, however, tips into the other extreme: there is a lot of experimentation, many different tools come into play, but hardly any is rolled out broadly. Only the combination of both directions ensures that AI usage is oriented toward the actual day-to-day business and creates real value.

Room to Experiment

On the subject of value. One of the biggest mistakes when introducing AI is to apply rigid ROI criteria right away. That raises the pressure and overlooks the fact that most teams first have to change how they work in order to use AI with any fluency.

With general-purpose AI, there is always a learning curve at the start, and there has to be time for it, otherwise people give up before any solid results even emerge. ROI matters in the long run, but it can only be calculated realistically once everyone understands what the tools can be used for and how to use them well.

One way to create this space safely is to test AI in controlled environments with smaller teams and to involve employees early. Good governance creates exactly such spaces: places where things can be tested on a small scale before big decisions are made. This turns governance into an enabler rather than an obstacle to sustainable AI use.

Collaboration as Part of Governance

Governance can also foster a culture in which knowledge is not hoarded but shared, and becomes the basis of shared success. Sharing is also a question of architecture, and architecture is set by governance.

One proven method is a central knowledge base with rights and roles that ensures users never see answers that lie outside their authorization.

The right architecture and culture ensures security and compliance while at the same time increasing the acceptance of AI.

Conclusion: Governance as a Driving Force for AI Success

AI governance creates the framework within which AI usage takes place. It not only protects against compliance and security risks, but also makes visible what is possible with AI, determines which applications come into use, and defines responsibilities. Through enablement and training, it strengthens acceptance and helps employees use AI responsibly and productively.

Governance is often understood as a brake. In reality it is more like the foundation from which you can accelerate. Companies need it because it is the only way they can truly tap the benefits of AI: by reaching everyone on the team and bringing them along.

In the end, the greatest success will not go to the companies where the use of AI was stubbornly dictated from the top. It will go to those that have set clear processes and responsibilities and that live a culture allowing experiments in a safe space, and that make sure AI is not bought in a way that bypasses everyday work.