Olivier Le Moal - stock.adobe.co
Shift-left governance brings data controls upstream for AI
AI systems move too fast for data governance that waits until the end. Enterprises are replacing outdated review methods with earlier oversight and automated controls.
The worst time to discover an AI data governance gap is after a system reaches production and turns a hidden data problem into a critical business risk.
By executing tasks and making decisions with less -- or no -- human intervention, agentic AI can improve operational efficiency, but it also raises new questions about data quality, access and accountability. Those considerations, along with AI's transition from experimentation to production, are pushing enterprises to adopt shift-left governance, also known as upstream governance.
Putting it into practice requires organizations to revise their governance oversight structure, implement it at the start of the application development process and deploy new technologies that automate repetitive governance tasks, according to industry executives.
Why AI governance needs to start earlier in the process
Enterprises have become more receptive to shift-left governance as AI initiatives have exposed the shortcomings in existing data management and governance practices.
"AI introduces an opportunity for organizations to start fresh -- new data, new systems, new processes, a new way of valuing data," said Jes Gonzalez, a principal consultant at ePlus, a consulting, advisory and managed services company.
Anant Adya, executive vice president and head of services delivery in the Americas at IT services provider Infosys, noted that data governance must evolve as organizations move from AI experimentation to production.
"Traditional governance models were designed around centralized reviews and periodic oversight, but AI operates at a new speed and scale," he said. "Organizations need metadata, lineage, data quality and policy controls embedded into data products and engineering workflows from the outset."
According to Balazs Fejes, president and CEO of IT consultancy EPAM Systems, most organizations are still building a foundational framework for data governance that lacks the processes required to handle the more complicated governance issues AI introduces.
"They start facing the reality that they don't have the basics right [and] they need to put together something much more robust, much more programmatic," Fejes said.
Start with an inventory of AI risks
IT leaders reconsidering their governance approach should start by taking inventory of which parts of the business will fall within an AI deployment's scope, according to Gonzalez. This task encompasses three main components: systems and data, identities and obligations, he said.
Systems and data include internal sources and platforms. Identities should cover human users and AI agents, while obligations should span external compliance duties and internal business requirements.
"If you continuously focus on those three buckets, you are covering 90% of your risk and threat landscape," Gonzalez said.
For global enterprises, the inventory should also account for geopolitical factors, such as competing regulatory regimes across jurisdictions and physical threats to technology infrastructure, according to Phil Budden, a senior lecturer at the MIT Sloan School of Management.
He said organizations can get lost in the excitement over the latest version of generative or agentic AI technology and "forget what's going on in the background."
"It turns out that the fancy AI model at the top of the stack is based on [data stored in] some traditional data centers, and those data centers happen to be in places, and it matters where those data centers are," Budden said. "If you have a data center in the Emirates and somebody starts a war in the Gulf, that may become a target."
Organizations should assess any potential geopolitical risks associated with their data partners before incorporating their services into AI systems, Gonzalez advised.
"Geopolitics is not a common topic in data governance, but it should be," he said.
Revise the governance oversight structure
Shift-left governance breaks from centralized, review-based governance, although organizations pursuing a data mesh architecture might already use a similar approach.
"One of the core principles of data mesh is federated computational governance," Fejes said.
Under that model, domain representatives agree on governance rules that are implemented in the organization's data platform for automated enforcement.
Fejes said this model replaces committee-based governance with an approach with governance controls that travel with the data, such as ownership information, quality metrics and contracts.
Governance rules and ownership are attached to data assets and AI models when they are created, placing accountability on the teams responsible for them throughout their lifecycles, Fejes added.
Develop the foundation for embedded governance
Shift-left governance depends on a data architecture that enables policies and controls to be embedded in data products and AI workflows. Fejes said the key parts of this foundation are the data platform, data products, data contracts, ontologies and semantic layers.
Semantic models are especially important in providing the business context that helps agents interpret enterprise data consistently, he said.
Use automation for enforcement
Automation makes governance controls continuous, measurable and scalable instead of relying on periodic, manual processes, Gonzalez said. It enables governance teams to focus on exceptions, oversight and strategic decisions instead of repetitive administrative tasks, he added.
Tasks that are ideal for automation include data discovery, inventory management, data classification, policy enforcement, configuration monitoring and audit evidence collection, Gonzalez said.
Gonzalez cited the Databricks and Snowflake platforms for their native governance capabilities for data and AI assets using Unity Catalog and Snowflake Horizon Catalog, respectively.
These tools can create a data control layer that translates the organization's governance policies into technical enforcement mechanisms, Gonzalez said.
"That data control layer in the middle is often a missing function," he said.
John Moore is a freelance writer who has covered business and technology topics for 40 years. He focuses on enterprise IT strategy, AI adoption, data management and partner ecosystems.