
Flying blind? Here's how to clear the way forward for AI governance
Tom Owles· Risk & Security Solutions LeadMost organisations are deploying AI across business units without structured governance. The gap between AI adoption velocity and governance maturity creates regulatory, ethical, and operational exposures that compound over time.
This blog outlines why AI governance can't wait, what practical steps organisations should take now, and how ServiceNow's AI Control Tower provides the platform to make governance operational rather than theoretical.
Leadership is pushing AI adoption, teams are experimenting, everyone’s building something. But in the midst of all the excitement, guardrails become an afterthought.
The numbers back this up: a survey by SAP found that while 80% of companies are adopting AI, only 14% have visibility into how it’s being used internally. And just 15% feel confident they can meet emerging regulations.
The bottom line is organisations are flying blind, which makes running into headwinds inevitable.
How shadow AI takes root
It starts small and well-intentioned, like Finance deploying a forecasting model for instance. Departments are just trying to make work easier and faster, but these projects sit outside IT’s control – and that’s where the trouble starts.
Models drift over time as training data becomes outdated. Outputs then become harder to explain and bias creeps in that compounds with every prediction. Before long, you’ve got black-box systems making decisions nobody can defend and no incident response plan for when things go wrong.
More importantly you’re leaving gaps in compliance, and that’s where regulations raise the stakes. The upcoming EU AI Act requires high-risk systems to follow strict obligations around lifecycle risk management and documentation. Globally, standards like NIST’s AI RMF and ISO/IEC 42001 emphasise managing AI risks in line with broader organisational controls.
Even traditional security frameworks are being rewritten to account for AI governance. In NCSC’s latest Cyber Assessment Framework (CAF 4.0), organisations are expected to address AI in their risk management and ensure this technology can’t be exploited by attackers. The message is clear: AI needs governance, just like any other critical system.
Building a tower for AI control
ServiceNow launched AI Control Tower as a governance layer built into the Now Platform, designed to give you visibility and control over every AI asset you’re running – whether it’s ServiceNow’s AI features or models you’ve built yourself.
The foundation is a living inventory of your AI systems. Each asset gets tracked for ownership, business purpose, training data, deployment location, and risk classification. That inventory connects to your CMDB, so you can see business context alongside technical detail.
From there, the control tower handles the heavy lifting:
- Compliance gets embedded into the workflow rather than bolted on afterward. Assess each model against the EU AI Act or NIST AI RMF requirements, and the platform surfaces risk scores and required controls automatically to stay ahead of legal obligations.
- Monitoring runs continuously once models are in production. The platform tracks model drift, unusual usage patterns, and data quality signals. When something changes, you get alerted before it becomes a customer problem.
- Governance workflows trigger automatically when issues are detected. Create a risk record, notify the responsible owner, pause a model pending review. Everything gets logged in audit-ready format.
The platform is only half the answer however. Technology gives you visibility and automates workflows, but good governance requires you to use it properly.
Don’t forget the fundamentals
You need a cross-functional group that includes IT, risk, data science, compliance, and business stakeholders meeting regularly. Someone needs to own accountability for major systems – whether you call them an AI Product Owner or Responsible AI Lead doesn’t matter as much as making sure the role exists.
The process requires teeth. Higher-risk AI undergoes formal evaluation before launch and at regular intervals, with documented mitigations for bias or human-in-the-loop controls. Lower-risk systems get lighter-touch governance, but nothing runs unseen.
On the operational side, you need performance monitoring running in live production. Define your alerts for anomalies and set triggers for retraining when data starts to drift. Each AI system should map clearly to the relevant laws and internal policies it needs to comply with, with documentation stored alongside the asset so you can prove compliance when asked.
Incident response matters just as much. When something goes wrong, your team needs to know exactly who to notify, how to roll back changes, and how to switch to a safe state without scrambling. And none of this works if your people don’t understand what they’re dealing with – training on responsible AI, bias awareness, and how to interpret outputs gives your developers and users the confidence to flag problems when they see them.
The organisations getting this right bake governance into their operating model from the start rather than retrofitting later. Grasp these fundamentals, and the platform amplifies your capability. Miss them, and you’re just tracking AI in a spreadsheet.
AI governance isn’t purely defensive. It’s a competitive advantage. When you have visibility and control over your AI systems:
- You deploy AI faster because you’ve de-risked the implementation
- You scale with confidence because you know what’s working and what isn’t
- You earn trust from customers, regulators, and employees
- You make better investment decisions because you can see actual ROI instead of guessing
The organisations that govern AI well will innovate faster than those that don’t. They’ll avoid the costly missteps, the regulatory penalties, and the reputational damage. More importantly, they’ll build systems their people use with confidence.
Stop AI chaos, start controlling
At Pulsar, we integrate AI Control Tower with your broader operating model – connecting to IRM for unified risk management, SPM to align AI investment with strategic priorities, and SecOps to protect your AI.
We’ve developed a 12-week AI Control Tower Launchpad to help organisations get this right from the start. We stand up the platform, integrate it with your risk and security processes, onboard your first wave of AI use cases, and train your team to run it independently.
Get in touch to discuss how Pulsar can help implement AI governance on ServiceNow. Whether you’re just starting or scaling existing AI, we can help you do it right.
Facing something similar?
Talk to the practitioners behind this work — we'll tell you honestly what we'd do.