Your message has been sent.
We’ll process your request and contact you back as soon as possible.
The form has been successfully submitted.
Please find further information in your mailbox.
Sep 3, 2026

Head of GRC, Cybersecurity & Sustainability

FOR PRESS USE: Feel free to use excerpts, statistics, or quotes from this material for your reporting.
Ask a company if it has a responsible AI policy and nearly everyone says yes, usually with some relief, like they’ve just been asked if they have a fire extinguisher. Ask what happens when the model starts hallucinating at 2 a.m. on a Tuesday, or a chatbot gets sweet-talked into handing over a customer’s order history, and the room gets quieter. Somebody usually says “legal is on it.” But it is not on it. Legal was on it 18 months ago, when someone wrote the policy. The problem is nobody has touched it since.
That’s the joke sitting inside most responsible AI programs right now. The principles exist and the slide deck does. What’s missing is the part where any of it actually runs inside the software, the way a fire extinguisher is only useful if it’s charged, mounted somewhere findable, and not expired. A policy that lives in a PDF doesn’t stop a production system from doing something dumb at scale. As I see it, engineering does that, or nothing does.
People say “responsible AI” like it’s a single thing you either have or don’t, the way you either have a logo or you don’t. It’s actually three separate jobs, and mixing them up is how a company ends up with a beautiful AI ethics statement and a chatbot that just leaked somebody’s medical history.
Principles are just the beliefs. Fairness, transparency, the works. They’re nice to have being framed on a wall, but they don’t stop anything from happening at 2 a.m (see the intro part).
Governance is who’s supposed to notice. Committees, sign-offs, an org chart that says whose problem this is when it breaks. Useful for assigning blame afterward. Less useful in the moment, unless that committee happens to be awake and staring at a dashboard when it happens, which it never is.
Engineering controls are the only one of the three that work when something goes wrong. Logging, versioning, a kill switch that’s been tested. This is the layer that turns transparency into a system that can actually be inspected.
A company can win an award for its AI principles and still not know which team owns the chatbot that just went off script. Both things are true at the same time, constantly, everywhere.
Here’s the part that doesn’t photograph well for a press release. Somebody needs an actual inventory of every AI system running in the company, including the one a team spun up over a long weekend to solve a problem nobody approved solving. A survey of 307 senior tech and security leaders found only 5% were very confident they had full visibility into what was live in their own production environment. 43% weren’t confident at all, which is a very polite way of saying they had no idea.
Beyond the inventory, the list gets long fast:
All of it is exactly what a good ops team already does for anything else that matters. AI just gets treated like a special case that’s above all that, right up until it isn’t.
The teams that get this right treat an AI system the same way they'd treat a payments system, with an owner, a change log, and an audit trail from day one. The teams that struggle are usually the ones that shipped a model the way they'd ship a feature flag, and only built the controls after something went wrong.
There’s a comforting fiction that a model gets tested once, passes, ships, and behaves forever after, like a bridge that’s been inspected and can now be forgotten. Real life doesn’t work that way, because the world the model has to deal with keeps quietly shifting under its feet. Accuracy that looks great in the test environment drifts once real, messy, unpredictable customers start typing things a test set never imagined. Hallucinations don’t go away just because the model got smarter, either: Stanford HAI’s 2026 AI Index found hallucination rates swinging anywhere from 22% to 94% across 26 of the leading models (in a benchmark testing whether models cave to a claim framed as the user’s own belief), which is a wide enough range that “leading” starts to feel like a relative term.
Then there’s the stuff that doesn’t seem important until it happens to your company: prompt injection, where a hidden instruction buried in something the model reads gets treated as a command from you, or plain old data leakage. Neither is hypothetical anymore. A 2026 survey of 750 IT leaders across finance, healthcare, and government found 88.4% had already had at least one AI agent related security breach, and data leakage was the most common culprit, in just over half of those cases, with manipulation via malicious or untrusted inputs close behind. Documented AI incidents overall hit 362 in 2025, up from 233 the year before, per the same Stanford index.
The fix is the boring habit of watching the system the way you’d watch anything else you cared about staying up: evaluation running in the background, red team exercises, guardrails between the model and whatever it’s about to do, and alerts that treat a weird behavioral shift with the same seriousness as a server falling over.
Every AI policy has a line about human oversight, usually right next to a stock photo of someone thoughtfully touching a laptop. It sounds solid until you ask three follow-up questions: which human, reviewing what, with what actual power to stop the thing. Most policies fall apart around question two. Done properly, it means:
A human in the loop that's never been tested is a policy statement, not a control. We ask clients the same question we'd ask about any incident response plan: when was the last time you actually ran it, and did it work the way you assumed it would?
The companies actually pulling this off aren’t running a parallel responsible AI universe alongside their real engineering work, with its own meetings and its own binder. They’ve folded it into the same pipeline everything else already goes through:
Do that, and compliance stops being a once-a-year fire drill where everyone scrambles to find evidence they were doing the right thing. The evidence is just sitting there, in the same logs and version history engineering was already keeping for its own reasons.
A prototype three engineers are poking at internally, with no customer data anywhere near it, does not need the same level of scrutiny as a system deciding who gets a loan or an interview. Treating both the same way is how a company ends up either negligent where it actually matters or so bogged down in the process that nobody can ship anything, which is its own kind of failure.
The EU AI Act is built around this exact idea, sorting systems into low, limited, or high risk. It isn’t pretending every use of AI deserves the same paperwork. The same logic holds even outside the regulation: healthcare, finance, HR, and public sector systems earn the heavy engineering investment in traceability and oversight, while the low-stakes internal experiment gets to move fast and not drown in review cycles. That’s already what we’re seeing in practice: regulated, data-heavy industries move faster on governance, mostly because they’ve already felt what it costs to get it wrong.
The compliance calendars have been circling August 2026 for a couple of years now, which made it sound like the whole Act flips on at once, like a light switch. It didn’t work that way. Here’s the actual sequence:
What didn’t happen is the full switch-on of the heavier high-risk obligations. A later legislative package pushed a good chunk of that further down the road.
None of this is an argument for slowing AI down, whatever the compliance-averse crowd wants to believe. The actual slow-down happens later, when a system nobody can explain gets pulled apart in public, usually by a regulator, a journalist, or an unhappy customer who found the problem before anyone internally did. Treat the inventory, the ownership, the monitoring, and the human override the way you’d treat security or uptime, as ordinary engineering work, and the whole thing scales without anyone losing track of what it’s actually doing.
Innowise’s AI consulting practice spends most of its time on exactly that handoff, ensuring stated principle is something that runs and gets checked in production. Leave responsible AI as a document nobody rereads after launch, and eventually the system tells you what it’s been doing the entire time, just not on your schedule, and rarely at a convenient hour.
FOR PRESS USE: Excerpts, statistics, and quotes from this material may be used for reporting, with attribution to Innowise.
Your message has been sent.
We’ll process your request and contact you back as soon as possible.
Your message has been sent.
We’ll process your request and contact you back as soon as possible.