AI Risk Is Already Showing Up. Governance Cannot Wait.

By: Jennifer Gilligan, IntegraMSP President

The latest warning is aimed at technology providers, but every business using AI should be paying attention.

Dave Sobel recently published an important analysis for Business of Tech examining how insurance language, vendor contracts, liability law, and industry standards are beginning to change the allocation of AI risk. His article, “Software’s Liability Holiday Is a Choice, and You’re Paying for It,” was written primarily for managed service providers, but it does a lot of heavy lifting in assembling the reporting and explaining what these developments may mean for technology providers and their clients. I recommend reading his full piece for the deeper insurance and liability analysis.

But the crossover to every other business is important—and that is why I am sharing it.

Companies using AI also sign vendor agreements. They carry insurance policies. They answer customer security questionnaires. They are responsible for protecting employee, company, and client data. And when an AI system is granted access to information or allowed to take action, the business deploying it may carry responsibilities that cannot simply be transferred back to the software manufacturer or technology provider.

The risk is already beginning to appear in insurance renewals, contracts, compliance requirements, and customer expectations.

That is why AI governance matters now.

This Is the Drumbeat I Have Been Hammering

For roughly eight months, I have repeated some version of the same message:

AI is not the problem. Unmanaged operational complexity is.

I have written and spoken about shadow AI, data exposure, vendor accountability, human oversight, insurance, and the need for enforceable technical guardrails. I have also made it clear that I am an AI optimist. The opportunity is enormous. Businesses should be learning how to use this technology, identifying valuable applications and preparing their teams for what comes next.

But optimism cannot replace governance.

AI exposes the operational weaknesses already inside a business: undocumented workflows, excessive permissions, fragmented systems, inconsistent processes, unclear ownership, and employees using technology that leadership cannot see. It does not create every one of those problems. It can, however, accelerate them, connect them, and increase their consequences.

Buying AI is easy. Building an organization capable of using it responsibly is the hard part.

Sobel’s reporting matters because it demonstrates how quickly the external environment is beginning to reflect that reality. The discussion is no longer limited to hypothetical future regulations. Questions about accountability are already appearing in the documents businesses sign and the requirements they are expected to meet.

Adoption Is Moving Faster Than Accountability

Employees are already using AI. Departments are adopting new applications. Existing software platforms are adding AI features. Vendors are introducing agents that can access data, initiate workflows, and take action. In many organizations, that adoption is happening before anyone has clearly documented who approved the technology, what information it can reach, how its output will be verified, or how its activity will be monitored.

Among the research highlighted in Sobel’s reporting is OneTrust’s 2026 AI governance survey. OneTrust, which sells governance technology, surveyed 1,200 senior decision-makers at large organizations. It found that 87% encouraged the use of AI agents, while only 47% said that use was supported by clear governance, oversight, and controls. Only 5% reported clear coordination and accountability across the AI lifecycle. OneTrust provides its methodology and full findings here.

Although the survey focused on larger organizations, we see the same underlying gap across the broader business community. AI capability is expanding faster than organizational accountability. That gap is where the risk lives.

Our Clients Are Already Asking the Right Questions

At IntegraMSP, we are being asked more frequently about compliance and governance. Clients want to know which controls apply, how AI use should be documented, what their customers or insurers may require, and how they can demonstrate that appropriate safeguards are in place.

Those are no longer edge-case questions reserved for highly regulated enterprises. They are becoming normal business questions for any organization using AI to process information, support employees, communicate with customers, or automate work.

Every business should be able to answer:

  • Which AI tools and AI-enabled features are currently being used?
  • What company, employee, or client information can those systems access?
  • Which human and nonhuman identities can reach protected systems or take action?
  • Which outputs or actions require human review and approval?
  • What responsibilities have vendors accepted—or declined—in their agreements?
  • Can the organization produce evidence of approvals, access, activity, and periodic reviews?

If those answers are scattered across departments, individual employees, and vendor portals, the organization does not yet have AI governance. It has AI activity.

IntegraMSP Is Ready to Help Now

Businesses do not need another generic AI policy that gets saved to a folder and forgotten. They need help translating security, compliance, insurance, and governance expectations into practical decisions about identities, access, data, vendors, workflows, and accountability. At IntegraMSP, we are prepared to help organizations identify where AI is already being used, uncover shadow AI, evaluate access to systems and data, establish acceptable-use expectations, assign human oversight, and implement enforceable technical controls.

Our AI Readiness Assessment provides a practical starting point for understanding the current environment, identifying gaps and building a prioritized governance plan.

We are also going through our own SOC 2 journey, which continually reinforces an important lesson: A control is not real simply because an organization says it exists. It must be implemented, operated consistently, and supported by evidence.

The same principle applies to AI.

Businesses should not wait for one perfect law or universal standard before taking action. A customer questionnaire, insurance renewal, contract negotiation, or incident may arrive first.

You do not need to fear AI, and you do not need to stop innovating. You do need to know where it is operating, what it can reach, who is accountable, and how you will prove that appropriate controls exist.

Dave Sobel’s reporting shows where the risk is beginning to surface. The crossover for every business is clear.

AI governance is no longer a future conversation—and IntegraMSP is ready to help clients address it now.