Closing the Governance Gap: GRC Strategies for the Frontier AI Era

Free the CISO, a podcast series that attempts to free CISOs from their shackles so they can focus on securing their organization, is produced by CIO.com in partnership with DataBee®, from Comcast Technology Solutions.
In each episode, Robin Das, Executive Director at Comcast under the DataBee team, explores the CISO’s role through the position’s relationship with other security stakeholders, from regulators and the Board of Directors to internal personnel and outside vendors.
Here's the uncomfortable truth most security and GRC leaders already know but don't say out loud: AI is running in production whether governance caught up or not. Pilots got greenlit. Agents got permissions. In a lot of cases, the guardrails came later — if they came at all.
That was the starting point for a recent panel discussion, "Get Schooled on AI Governance," featuring Erin Hamm (Field Chief Data Officer, DataBee), Yasmine Abdillahi (Executive Director, Security Risk and Compliance / BISO, Comcast), and Chad Barr (Director of Risk Advisory Services, AccessIT Group), moderated by former Gartner analyst Alicia Booker-Carney. The conversation didn't stay theoretical for long. Here's what came out of it — and what to do with it.
Why last year's playbook doesn't work anymore
Governing AI a year ago meant governing tools with humans in the loop at every step. That's not what most organizations are running today. As Chad Barr put it, agentic systems are fundamentally more autonomous — "you give them a task and they will just do it for you." That shift changes the entire governance question, from is this tool configured correctly to how do we manage autonomous, unpredictable action at scale.
Yasmine Abdillahi framed the scale problem bluntly: organizations went from evaluating a handful of AI initiatives to governing thousands of agents, almost overnight. And the regulatory backdrop shifted with it; from voluntary, principle-based guidance to enforceable frameworks like the EU AI Act. The conversation isn't the same conversation it was twelve months ago and treating it that way is the first mistake.
The gaps aren't new. The blast radius is.
Erin Hamm's framing here is worth sitting with: governance has long been treated as a tax organizations pay to stay out of trouble — reactive, minimal, just enough to satisfy the auditor's request when it lands. AI didn't invent the lineage and ownership problems every mature compliance program has been chasing for a decade. It just removed the slack that let organizations skirt them.
Her comparison to Log4j is the one to remember: one vulnerable dependency, buried deep, that nobody had inventoried, took down incident response teams globally for weeks. AI ecosystems have the same shape — an MCP server, an agent framework, a fine-tuned model, an LLM, stacked on top of each other, often adopted without going through procurement. "The gap around lineage and ownership is no longer abstract," Hamm said. "It's the same blind spot you saw with Log4j, just one layer up on the stack. And a lot bigger of a problem."
Abdillahi added a related gap: too many organizations are still treating AI governance as a feature they bolt onto their security stack, rather than a discipline that requires engineering and cross-stakeholder alignment. That mismatch, she noted, can be detrimental.
You can’t govern what you can’t see
Chad Barr cited data from a BlackFog survey putting unsanctioned AI use at roughly 49% of employees — using AI tools outside official channels, the way BYOD played out a decade earlier. His take: assume you're running AI somewhere in your environment right now, sanctioned or not, and build from there.
Abdillahi's addition matters just as much: even organizations with an inventory don't have a complete one, because discovery tooling for AI still isn't fully mature. Visibility has to extend past the model itself — to the agents, the tool servers, the datasets, and the extensions layered on top. And per Hamm, this can't be a survey teams fill out once a year. It requires the same engineering discipline as any other infrastructure: instrumented, automated, continuous.
Ownership is a team sport, not an org chart problem
Who owns AI governance? Hamm's answer cuts through a debate a lot of organizations are still stuck in. Compliance can write the policy but doesn't have visibility into the data pipelines AI actually touches. Data engineering has that visibility but no governance mandate. Security controls access but can't see what an agent does after it's authorized to be there. Each function alone is incomplete.
"It's not an org chart problem," Hamm said. "It is a team sport." The fix isn't assigning a single owner — it's making sure risk-visibility, mandate, and infrastructure control are looking at the same data at the same time.
That matters for how governance gets built, too. Hamm's advice: stop building governance as a gate people have to ask permission to pass through; that's what creates bottlenecks and workarounds. Build it into the infrastructure and the software development life cycle pipeline instead, so the guardrails are there by default. Abdillahi's point reinforces it from the user side: friction is what breaks adoption of the process in the first place.
Continuous controls monitoring is the difference between compliant and actually compliant
Point-in-time governance — quarterly reviews, scheduled audits — can't keep pace with agents that drift. Hamm's example: this summer's release, brief suspension, and restoration of Claude's Mythos-tier models played out start to finish in about a month. A program checking vendor status quarterly would never have caught the gap. That's precisely what continuous controls monitoring (CCM) is built to close.
Abdillahi added an important reframe: CCM isn't automated box-checking. It's measuring your actual compliance posture against the policies your organization has already decided are non-negotiable — and scaling that measurement as your inventory, discovery, and assessments scale with AI adoption.
Want the Full Conversation?
Watch the on-demand webinar: Get Schooled on AI Governance
A realistic 30-60-90 day plan
Asked for a practical roadmap, Chad Barr laid out a three-phase plan:
Days 1–30: See what you have.
- Build a real inventory — systems, shadow IT, shadow AI, everything you're actually running
- Stand up a cross-functional AI governance committee so no single person or team is making the calls alone
- Run a baseline risk assessment: where you are, where you need to be
- Draft acceptable-use policy and procedures — framed as enablement, not restriction
- Identify and prioritize the key controls for your next deployment
Days 31–60: Automate and integrate.
- Deploy CCM tooling against the controls identified in phase one
- Automate evidence collection — no more spreadsheets
- Integrate CCM data feeds into your existing GRC platform
- Activate continuous monitoring on your critical AI pathways
- Deliver targeted AI governance training by team, based on how each team actually uses AI
Days 61–90: Tune and mature.
- Expand CCM coverage to higher-priority controls
- Refine what's not working from the first 60 days; fully automate policy enforcement
- Plan for ongoing GRC maturity and log analysis as regulations and internal systems evolve
Abdillahi's addition to the plan: use this window to build the muscle of connecting the dots — identity, observability, and governance — and to actively solicit input from stakeholder groups rather than waiting for them to come to you.
When do you actually pause a project?
Hamm's rule of thumb, pulled from a recent ISACA GRC conference: the deciding factor isn't severity, it's reversibility. Ask: if this agent does exactly the wrong thing, can we undo it, and how fast? If you can roll it back in an hour, monitor and move on. If undoing it takes weeks of manual cleanup — or can't be undone at all — that's a pause, regardless of how unlikely the failure seems. An agent that drafts a summary with a wrong number is annoying but recoverable. An agent with write access to customer records or the authority to trigger a payment is a different category entirely, even at lower odds of failure.
Key takeaways
- Governance debt compounds under agentic AI. The lineage and ownership gaps aren't new — but autonomous systems remove the slack that let organizations defer them.
- Inventory is the unlock, not a checkbox. Automated, continuous discovery beats an annual survey every time — for shadow AI and for everything downstream of it.
- Ownership is shared by design. Risk visibility, governance mandate, and infrastructure control have to sit at the same table — not under one function.
- Build guardrails into the pipeline, not in front of it. Governance-as-gate creates bottlenecks and workarounds; governance-as-infrastructure doesn't.
- Point-in-time compliance is a false sense of security. Continuous controls monitoring is what catches drift between audits, and agentic systems drift fast.
- Reversibility, not severity, is the pause trigger. If you can't undo it quickly, that's your line.
- A 30-60-90 day plan is realistic, not aspirational. Inventory and committee first, automation and integration second, tuning and maturity third.
Watch the webinar here, and please reach out to a DataBee or AccessIT expert with any questions or to learn more.
More posts


Continuous controls monitoring fails without unified, contextualized data. Discover how a security data fabric enables real-time compliance, framework alignment, and defensible reporting.


Discover how DataBee® builds on the Open Cybersecurity Schema Framework (OCSF) to normalize, enrich, and correlate security data—enabling scalable, intelligent threat detection and analytics across your enterprise.


Learn how Agentic AI for Security and Compliance enables continuous monitoring, defensible decisions, and context-aware security insights powered by unified security data.
Get the clarity you need to manage cyber risk.
Schedule your 30-minute demo to see how DataBee's AI-powered technology turns your data into fast, clear, defensible control and cyber risk clarity.
