Sam Mugel, Ph.D., is the CTO of Multiverse Computing, a leader in developing efficient value-driven AI & quantum solutions for businesses.
Enterprise AI deployment has matured considerably, but the governance infrastructure surrounding it has not kept pace. The consequences of this are materializing.
Per the Harvard Law School Forum on Corporate Governance, 72% of S&P 500 companies disclosed at least one material AI risk in 2025, up from just 12% in 2023. In that same year, 88% of organizations reported using AI in at least one business function. More than 80% of workers, including nearly 90% of security professionals, use unapproved AI tools in their jobs, and according to IBM’s 2025 report, 63% of organizations lack governance policies to manage AI.
The instinct is to address this through pre-deployment controls. But the more fundamental shift underway—from single-model deployments to multi-agent workflows, retrieval-augmented systems and orchestration layers—has made that approach structurally insufficient. Governing a model is a different problem than governing a workflow, and most organizations are still solving the wrong one.
The Limits Of Model-Centric Governance
Most organizations approach AI safety as a pre-deployment, model-centric problem. They evaluate models before release, run red-teaming exercises, implement prompt-level guardrails and establish usage policies. These steps matter, but they address a fundamentally different challenge than what happens when a model is actually running at scale, embedded in a live workflow and interacting with real data, real users and other AI systems.
Pre-deployment evaluation captures model behavior under test conditions. Production involves inputs and edge cases that no test environment anticipated, such as real users, unusual queries, adversarial inputs and combinations of context that no red-team exercise fully replicates. IBM’s 2026 report notes that the most pressing risks from AI may not come from the models themselves, but rather the complex systems companies build around them. Governance focused on model capability misses the category of risk that actually materializes in enterprise environments.
These are runtime attacks in which an AI system is manipulated by malicious or deceptive instructions to ignore its established rules or misappropriate data. Because they depend on adversarial inputs encountered only after a system is live, they are notoriously difficult to identify during evaluation. No amount of pre-deployment assessment eliminates them. What is needed is governance that operates within real-time production, where the risk actually lives.
From Model Governance To Workflow Governance
Another significant shift of note is that enterprise AI has moved beyond individual model deployments. The dominant architecture today is workflows: agents that retrieve, reason and act across multiple systems; RAG pipelines that connect models to internal knowledge bases; and orchestration layers that route queries between specialized models depending on task type. Each of these introduces a governance surface area that model-level controls cannot address. Similarly, in multi-agent workflows, an instruction passed between agents can carry context, permissions or data that no individual agent’s policy was designed to handle.
Data governance compounds this. As AI workflows increasingly consume structured and unstructured internal data, the question of what data AI is permitted to access, under what conditions and with what logging, becomes as important as what the model does with it. Most organizations have data governance frameworks for human access, but very few extend those frameworks to cover AI-mediated access, where access patterns are more opaque and harder to audit after the fact.
Agent governance introduces an additional layer to consider. Autonomous agents that take actions like querying APIs, updating records and triggering downstream workflows require governance that goes beyond classifying outputs. The action itself needs to be authorized, logged and attributable. In agentic systems, the failure modes are not just wrong answers, but wrong actions executed at machine speed, often without a human checkpoint.
What Runtime Governance Actually Requires
Effective runtime governance observes AI behavior as it happens across the full workflow, enforces controls at each point of interaction and generates continuous, structured evidence of what the system actually does. This requires inspection in both directions. Most AI safety tooling focuses on screening inputs for policy violations—filtering restricted topics and flagging sensitive keywords. Output inspection is significantly less common, which is where many failures actually occur. A user asking a reasonable question can still receive a hallucinated regulatory claim, a PII record surfaced from another session or a recommendation that contradicts internal compliance requirements. None of those failures would have been caught by any input-level control.
For workflows, governance needs to cover retrieval decisions, inter-agent communications and tool invocations, not just the final response. The request, the retrieval, the reasoning chain, the response, the user, the model, the policy decision and any subsequent action should be connected into a single auditable record.
This will soon become a legal requirement, as the EU AI Act reaches full enforcement in August 2026. Its documentation obligations will apply not to what organizations intended their AI systems to do, but to what those systems actually did. Organizations treating compliance as a future problem are running out of runway.
Guardrails Should Enable Scale
The cost of ungoverned systems is often framed in terms of risk exposure. But the equally important, affirmative case is that organizations that govern well move faster.
A 2025 BCG report found that “future-built” companies are five times more likely to have AI workflows already deployed or scaled and 2.5 times more likely to have governance or value-measuring systems in place. The organizations moving fastest are also governing the most rigorously. Effective guardrails can reduce the organizational friction that comes from ungoverned systems, such as compliance reviews, manual audits and incidents that consume leadership attention and delay future deployments.
Architecture that supports this mirrors what organizations already do with other sensitive production systems: a governance layer that sits across the full workflow, inspects traffic in both directions at every stage, enforces policy in real time and generates continuous structured logs. It should run inside the organization’s own infrastructure, cover agents, RAG systems and orchestration layers, work across whatever models the organization runs and remain independent of any single vendor. Guardrails should also be calibrated against actual use, tested against edge cases and revisited as models, workflows and threats evolve.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?










