Every large company now claims to govern its AI. The governance industry has kept them busy: model registries, risk classification systems, responsible AI teams, ethics policies, board presentations. Surveys confirm the effort. A recent study of 300 senior Fortune 500 leaders found that 70% say their companies have AI risk committees and 41% have a dedicated AI governance team. Only 14% say they are fully ready for actual AI deployment.
That gap is the whole story.
Building oversight infrastructure is not the same as having oversight. The person who can flag a problem is not the same as the person who can stop it. In most large companies, the authority to actually shut down a misbehaving AI system sits with someone whose main job is shipping products and hitting revenue targets. Governance teams can advise. They can escalate. They cannot override.
This is a structural problem, not a personnel one. The people running these programs are not incompetent. They have simply been given advisory roles inside organizations where the incentives all point in the opposite direction. A product leader who misses a launch date faces consequences. A product leader who ignores a governance flag usually does not.
The stakes of this gap are rising. AI tools are now running inside companies across customer service, hiring, pricing, fraud detection, and back-office operations, often deployed quickly by well-meaning teams looking to get things done faster. Research suggests that roughly 91% of organizations are already using AI agents of some kind, while only 10% have a clear strategy to manage them. That means a large share of companies are running systems they do not fully understand, with no clear answer for who would act if one of those systems started causing real harm.
Real harm is not hypothetical. AI used in hiring can replicate the biases in the historical data it was trained on. AI used in customer service fails to resolve problems at a rate nearly four times higher than other AI applications, with over half of consumers now worried about how their data is being used in those interactions. An AI coding tool deployed inside Amazon caused a 13-hour disruption to its cloud services in December 2025. In each case, the question is the same: who had the authority to act, and did they use it?
Regulators are asking that question explicitly. The EU's AI law, now in active enforcement, does not ask companies whether they have dashboards. It asks who made consequential decisions about AI systems and whether those decisions are documented. The penalties for violations are steep: up to 35 million euros or 7% of global annual revenue, whichever is higher, exceeding even the EU's own data protection fines. Those are not theoretical numbers. Market surveillance is already underway.
For companies operating in or selling into the EU, and for any company anticipating that domestic regulators will eventually ask similar questions, the structural question is urgent: does someone in your organization have the formal authority to say no to an AI deployment, and do they have enough independence from the teams shipping that AI to actually use it?
Adobe built its governance program with this in mind, placing AI oversight under its trust and security function rather than under the product teams. The logic is simple: the person with authority to stop an AI system should not report to the person who benefits from that system running. Named owners for each AI system, a steering committee with real escalation authority, and a reporting line independent of product delivery.
Most companies have not made that design choice. They have governance programs that look complete on paper and are missing the one element that makes them real: a person with the standing and the authority to act when something goes wrong. Until that changes, the risk does not sit in the AI. It sits in the org chart.