New governance challenges arise as AI enters UC workflows

AI agents are now acting in UC and CX workflows. Governance policies must provide visibility, define accountability and support ongoing evaluation.

Enterprises spent the last two years racing to put generative AI into production. Now many CIOs are confronting a less obvious challenge: building the governance structures needed to manage AI systems that are becoming increasingly embedded in business operations.

AI-powered collaboration tools are moving quickly into enterprise workflows, helping employees summarize meetings, draft content, analyze information and automate routine tasks. At the same time, AI agents are beginning to take on more autonomous roles, interacting with business systems and influencing decisions across departments.

But governance frameworks have struggled to keep pace. Many organizations have deployed GenAI faster than they can develop the policies, ownership models and operational processes needed for effective management.  

For CIOs, the challenge is whether their organizations are designed to manage AI-driven work. Enterprise AI conversations have shifted from evaluating what AI can do to understanding how organizations can govern it once it is in production, according to Rob Hilsen, founder and principal consultant at LookNow Agency.

"The first wave of AI projects was about proving AI could create value," he said. "The next wave is about proving organizations can operate AI reliably at enterprise scale."

When AI moves faster than policy

The first phase of enterprise AI adoption focused largely on experimentation. Organizations launched pilots to explore how GenAI could improve productivity, customer experience and software development.

Now, technology leaders are asking different questions. They want to understand who owns AI systems after deployment, how performance is measured, how changes are evaluated and how systems improve over time.

The first wave of AI projects was about proving AI could create value. The next wave is about proving organizations can operate AI reliably at enterprise scale.
Rob HilsenFounder and principal consultant, LookNow Agency

Security, privacy and regulatory compliance remain essential, but they are no longer the entire governance conversation. As AI becomes part of customer interactions and business-critical workflows, organizations need ways to measure performance, assign accountability and continuously improve outcomes.

Governance is, too, becoming more of an ongoing operational discipline rather than a one-time approval process.

What true AI readiness means

Many organizations define AI readiness through technology capabilities, such as infrastructure, data access and security controls. Those capabilities matter, but they do not determine whether an organization can successfully operate AI at scale.

True AI readiness requires clear ownership, measurable objectives and processes for monitoring AI performance after deployment. Organizations need to understand if AI systems are delivering expected outcomes, what changes improve performance and when human oversight is required.

That requires organizations to move beyond simply approving AI tools and toward managing AI as an ongoing business capability. CIOs need visibility into where AI is being used, which systems are making decisions and whether those systems continue to perform as expected over time. 

Without that operational view, organizations risk creating disconnected AI deployments that are difficult to monitor, measure or improve.

Structural governance challenges facing CIOs

The rise of AI agents introduces new governance challenges. Traditional application governance has focused primarily on access: who can use a system, what information they can access and what actions they are permitted to take.

AI agents change that model.

"They don't just retrieve information," Hilsen said. "They interpret information, make recommendations and, in some cases, take action."

An AI agent that can update customer records, approve transactions or initiate workflows requires a different level of oversight than a system that simply displays information.

For CIOs, governance must expand beyond access controls. They also need to understand what decisions an AI agent is authorized to make, how those decisions are evaluated and when human review should be required.

That responsibility extends beyond IT. Security, legal, risk, product teams and business leaders all play a role in ensuring AI delivers reliable outcomes.

Building unified AI oversight

One of the biggest mistakes organizations make is treating AI governance primarily as a compliance initiative. While compliance requirements are important, they do not guarantee that AI systems will consistently deliver reliable business outcomes.

Organizations also need practical capabilities for managing AI operations, including maintaining an inventory of AI systems, assigning ownership, monitoring performance and creating processes for evaluating changes before deployment.

"Policies alone aren't enough," Hilsen said. "They need ways to monitor performance, measure business impact, test changes before deployment and continuously improve AI over time."

A fragmented approach can create AI blind spots, with different teams adopting tools independently and creating inconsistent oversight.

As AI adoption expands, governance will increasingly become an enterprise operating model that connects security, IT, business leaders and other stakeholders around shared accountability.

The next phase of enterprise AI adoption will depend on how effectively organizations can establish the processes, ownership models and oversight needed to manage AI in production.

For CIOs, that means building governance frameworks that provide visibility into AI systems, define accountability and support ongoing evaluation as these technologies become part of everyday business operations.

Moshe Beauford is a writer with more than a decade of experience covering enterprise technology, including AI, unified communications and customer experience.