Picture this: it's 3 a.m., an AI agent is behaving strangely in production, and the on-call engineer opens the governance policy to find a beautifully written document that answers exactly none of the questions that matter right now. Who shuts it down? Who signs off? Where are the logs? That gap, between what the policy says and what the systems actually do, is where most AI programs quietly break.
Governance on paper is the policy document, the committee charter, and the annual review cycle. Governance in practice is the logging, approval, and evidence layer that proves those policies actually run. Most organizations have the first. Fewer than one in five have the second.
This article maps that gap using 2026 research from Arctera, ISACA, IBM, Forrester, NIST, and the EU AI Act's deployer obligations, which took effect on August 2, 2026. It covers where policies stall before enforcement, why shared responsibility collapses without a named owner, and how decision rights, inventory, and continuous workflows bridge the gap between documentation and daily operations.
Why written AI policies fail to govern in practice
The 2026 survey data continue to find AI security policies increasingly common on paper, while enforcement and auditability still lag in practice. Most organizations require disclosure when AI helps produce a work product, but far fewer enforce it, and a majority of digital trust professionals surveyed this year admitted they could not say how quickly they could halt an AI system after a security incident.
Samsung's 2023 ChatGPT episode shows the mechanics of the paper-versus-practice failure. After the company lifted a prior ban on the tool, engineers pasted proprietary semiconductor source code and confidential meeting transcripts into ChatGPT on several occasions over a few weeks. The policy defined permitted use on paper. Network and endpoint controls left prohibited use unblocked in practice. A policy without network or endpoint enforcement leaves only a preference.
The paper-practice disconnect is easy to recognize when business teams deploy AI faster than IT can track it, leaving technology executives accountable for systems they do not fully control. Teams that close that distance run the controls a policy describes on an intelligent workflow platform, and the gap surfaces first in ownership.
Ownership and decision rights: from shared responsibility on paper to named authority in practice
One named person with decision authority must own each AI system in practice, even when committees coordinate governance on paper.
Rehan Kausar, Chief AI Officer at AI Advantages, writing in CDO Magazine, describes institutions with strong "responsible" structures and weak "accountable" ones, in which coordination is confused with control.
Forrester frames the circular version: AI has landed everywhere in the enterprise, and accountability diffuses until an incident forces it into the light unless roles and escalation paths carry explicit decision authorities. Anyone who has filed an AI exception request knows the shape of this: opinions accumulate for weeks, then the ticket closes with a note asking the requester to name the risk owner. Nobody signs it because nobody can.
An AI system owner also needs written authority, not just a paper title. Accountability without authority is just a name in a spreadsheet. Ownership carries decision rights over monitoring, exceptions, vendor coordination, and incident escalation, and four authorities in particular need named holders before governance operates in practice.
The table below shows what each looks like on paper versus in practice:
Without these assignments, responsibility fragments while AI systems influence approvals and prioritization decisions across teams. At scale, teams route qualifying use cases through formal triage and review before deployment, and Security Operations Center (SOC) practice offers a portable tiering model.
Practitioner guidance also treats autonomy as something teams grant by action type, not something a policy declares once on paper. Under a tiered autonomy model, approval comes before high-impact actions such as isolating hosts or disabling accounts. Teams keep a human on the loop for enrichment queries and ticket creation. Only after accuracy testing do they let lower-risk log queries run autonomously.
Regulation now demands the same specificity in practice, not just on paper. Article 26 of the EU AI Act applies to deployers of high-risk AI systems from August 2, 2026, and requires deployers to assign human oversight to trained natural persons with authority to act, and to retain automatically generated logs for at least six months.
Decision-rights specificity survives as steps in a workflow, which makes designing AI workflows for safety and control a build decision rather than a drafting one — and teams cannot build that specificity against systems nobody has counted.
AI inventory: the bridge from written policy to operational governance
NIST AI RMF requires mechanisms to inventory AI systems (GOVERN 1.6). ISO/IEC 42001 requires named AI system owners; practical implementations focus on a consolidated AI inventory, and the EU AI Act's deployer obligations presume knowledge of which systems are running.
A policy on paper cannot govern what teams have not inventoried in practice. In most enterprise environments, most AI tools fall outside direct IT control, with shadow AI applications proliferating faster than procurement and security teams can catalog. Unauthorized AI use ties directly to breach exposure, customer data risk, and inventory gaps that persist for months.
Approved SaaS platforms now ship embedded AI features, and those features don't trigger a fresh procurement review. Once the inventory surfaces misclassified access, the correction work is where volume kills teams. Unowned artifacts create the harder problems: an OAuth grant to an AI summarizer sits in the identity logs, and no application owner claims it, and an agent keeps its access token months after the engineer who created it moved teams.
Detection takes layered telemetry because no single control sees everything. Text pasted into a prompt slips past file-centric data loss prevention (DLP). Inventory extends past tools to identities and access paths. Telemetry findings govern only when approval can trigger revocation or when scoped grants are in effect.
Daily operating workflows: turning AI policy into practice
Workflows execute the rules on paper against the assets found in the inventory. Anyone who has rebuilt a quarterly access review by hand knows what that costs: scrolling through Slack threads and screenshots for approvals, with no system recording. A policy moves from paper to practice when its rules run as steps inside the systems doing the work.
Intake gates route a new AI vendor to legal and compliance review before deployment. Approval steps run before high-impact actions, and workflow audit logs capture evidence rather than requiring teams to reconstruct it afterward. Approval gates are what turn a written policy into an enforceable one. Logging has to come before enforcement, because a control cannot act on activity without records.
An intelligent workflow platform gives teams a single place to execute those controls, running deterministic automation, AI agents, and human approvals inside the same workflow under a consistent governance model. Every step is recorded as it executes. In the paper version, an OAuth grant surfaces weeks later in a log export, is chased over Slack, is approved verbally, and is never recorded. In practice, teams build workflows that turn a paper governance policy into a running control:
Deterministic: a scheduled poll checks identity provider logs for new OAuth grants to AI services; an HTTP request retrieves the grant details; and the workflow logs each finding as a case assigned to the application owner.
Agentic: an AI step reads the access request from the ticketing system and the vendor's data-handling terms fetched via an HTTP request, scores the risk against the team's policy tiers, and drafts a recommendation within the guardrails the team configures.
Human-in-the-loop: the workflow posts the recommendation to chat with Approve and Deny buttons for the named resource owner; on approval, an HTTP request provisions scoped access in the identity provider, and the workflow writes the approver and decision rationale to the audit log.
Those execution styles turn governance from a paper reconstruction exercise into a running control system, which is why the operating model has to stay continuous.
Continuous AI governance: why point-in-time reviews fall short in practice
AI systems change faster than review cycles, so paper reviews at fixed intervals miss risk. Policies establish expectations on paper, but enforcement during real-time AI operations requires controls that operate in practice as risks emerge.
NIST's AI RMF treats GOVERN as a cross-cutting function infused throughout risk management across the lifecycle, and requires continuous monitoring of AI-generated content and provenance after deployment. The EU AI Act's post-market monitoring requirements treat continuous monitoring and post-deployment intervention as standing requirements.
Agents force the shift from paper to practice. Enterprises are on track to run tens or hundreds of thousands of AI agents in the coming years, up from a handful today, and internal usage of LLMs is growing several times over year on year. Quarterly review cadence leaves that surface uncovered.
Continuous governance depends on the connective layer between tools. Without orchestration, AI stays fragmented across disconnected tools, and most IT and security leaders say that fragmentation is the norm today. Live telemetry keeps inventory current, while workflows surface enforcement drift during team reviews and agent permission retirements. Teams still stuck at the paper stage will eventually have to answer for that drift.
Closing the gap between paper and practice
The frameworks are published on paper, and the regulatory dates are set. Programs that close the gap between paper and practice give governance a named owner with real authority and encoded decision rights against an inventory fed by live telemetry.
Teams close that last gap by making policy execution observable. With Tines 3B, teams turn paper policy promises into practice through workflows that review, approve, log, and manage exceptions on every access request, alert, and agent action. The policy document becomes the specification the workflows implement.
The teams furthest along started before their AI footprint outgrew their visibility. Start building in Tines 3B Explore Edition, with unlimited users, spaces, and connectors included.
Frequently asked questions
What's the difference between AI governance on paper and AI governance in practice?
AI governance, on paper, documents rules: acceptable use, plus review and disclosure obligations. AI governance in practice runs those rules through operating mechanisms: inventory tied to live telemetry, approval gates before high-impact actions, enforcement at the network and interaction layers, and audit logs that can prove what happened. Paper describes controls; practice runs them.
What do EU AI Act deployer obligations require as of August 2026?
From August 2, 2026, deployers of high-risk AI systems must assign human oversight to named, trained persons with authority to act, monitor system operation, report incidents to providers and authorities, retain automatically generated logs for at least six months, and inform workers before deploying high-risk AI in the workplace. The proposed delay remains unenacted, so August 2026 stands.
How do organizations detect shadow AI in practice?
Unapproved tools often surface as OAuth grants to AI services in identity provider logs, made with corporate credentials. That view misses personal accounts that never touch corporate SSO. Endpoint agents and CASB coverage pick up desktop apps, browser extensions, and browser-based access. Text pasted into an AI tool bypasses file-centric DLP, which is why interaction-layer logging comes first.
Who should own AI governance?
AI governance needs a single named individual with decision-making authority in practice, not just a title on paper. Committees coordinate and advise. A single accountable owner makes decisions, holds decision rights over monitoring, exceptions, and escalation, and is accountable for outcomes. When no one can name that person, exception requests stall because no one has the authority to sign.
