Security and trust

Why AI governance is an operating discipline, not a policy

Kavita Patel

Kavita Patel

Director, Product Legal, Gong

Published on: August 27, 2026

AI adoption is moving faster than the governance needed to support it.

The Cisco 2026 Data and Privacy Benchmark Study found that 90 percent of organizations have expanded their privacy programs because of AI, yet only 12 percent describe their existing AI governance as mature and proactive.

That gap matters as AI moves deeper into every business. It’s no longer limited to employees asking a chatbot to summarize a document. AI systems and agents can access customer interactions, business records, emails, contracts, and other data (sometimes sensitive) across the business — and they’re increasingly taking action based on that data.

Simply evaluating AI based on what it can do today isn’t enough. It takes more than a policy document and a security review before deployment. You have to understand how AI will access your data, where that data may go, what happens when the technology changes, and who will be responsible for managing it over time.

Gong has a long history of developing AI, and we’ve found that the following four pillars are foundational to responsible deployment:

1. Govern access to data, not just AI

When you evaluate AI, one of the first questions you should ask is “What can it access?”

Access is no longer limited to employees opening an application. Agents, integrations, and automated workflows can all interact with information that may previously have been available only to a select group of individuals or applications.

The risk here is in giving an AI system significantly more access than it needs to accomplish its job. Good security architecture intentionally partitions information so that if one system is compromised, that access doesn’t cascade across the organization. The same principle needs to apply to AI.

Before deploying a system, understand exactly what data it can see, what it can do with that data, and where the information may go next. Look for least-privilege access, role-based permissions, scoped integrations, and controls that apply to both agents and people.

The fact that AI can access something doesn’t mean it should.

2. Build privacy into how the system works

“Privacy by design” has been part of the security and privacy vocabulary for years. The challenge is making it real at a functional level.

Consider something as straightforward as honoring an individual’s request not to have their information processed. That seemingly simple privacy requirement can quickly become a complex engineering problem if you aren’t asking yourself the right questions prior to deployment, such as: 

  • Can I honor consent, opt-outs, and deletions?
  • Can I prevent certain data from being used in AI prompts and training?
  • Can I configure retention periods and deletion rules by data element or source system?
  • Can I restrict specific data or data flows?
  • Can I accommodate different requirements across jurisdictions, use-cases, or customer populations?
  • Can I control the actions an AI model can trigger autonomously to prevent customer requests from being ignored?
  • Can I meaningfully audit and measure if the controls are operating as intended?

This matters even more as the regulatory landscape evolves. The GDPR, EU AI Act, U.S. state privacy laws, and industry-specific requirements can create different obligations depending on where an organization operates and what information its AI processes.

While you can’t predict every regulation that will emerge, you can build an architecture that gives you enough control to respond when the requirements change.

3. Treat AI governance as a lifecycle

One of the biggest mistakes organizations make is treating governance like something that happens only at deployment. AI changes so quickly that the system you evaluated six months ago may not be the same AI operating today.

Strong governance establishes how changes are managed as the technology, regulations, and your teams’ use of AI changes across its lifecycle. That means you need to have clear answers to some basic but important questions:

  • How are AI risks assessed and is it proportional to the risk?
  • Who approves new models or material changes in model behavior?
  • What testing happens before deployment?
  • How is performance monitored afterward?
  • How are systems retired or replaced? What happens to data that is decommissioned?

Benchmarking against frameworks, such as ISO/IEC 42001 or the NIST AI Operational Framework, provides a foundation, but operationalizing them requires a cross-functional AI governance committee. Bringing together legal, privacy, security, product, and engineering ensures that everyone is aligned with the high-level principles that translate into everyday functionality on your revenue teams.

4. Decide who owns AI after deployment

The final consideration is one that organizations can easily underestimate: Who owns this once it’s live?

Governance breaks down when AI ownership is fragmented. That’s why I recommend cross-functionality, such as having legal embedded within the product team. We do this at Gong to connect the dots across disparate AI initiatives, prevent silos, and build the use of consistent AI practices into products before deployment.

To identify how your organization approaches ownership, ask yourself:

  • Who is accountable when something doesn’t behave as expected?
  • Who will investigate any incidents that occur?
  • Who is responsible for all the ongoing documentation associated with AI?

These questions are particularly important in a build-versus-buy decision. An internal build may look less expensive when you compare development costs with a vendor contract. But that comparison misses a significant part of the investment: the people and processes required to operate the system responsibly over its entire lifecycle.

A low-risk productivity tool with no access to sensitive data requires minimal operational overhead. But as you move into end-to-end platforms and autonomous agents and systems that access deeper customer information, surface strategic recommendations, and act across your entire workflow, governance becomes an ongoing operational commitment.

Governance should expand what AI makes possible

Good governance shouldn’t keep organizations from using AI. It should give them the confidence to use it more broadly.

Gong research found that data and security concerns are the leading factors eroding trust in AI. Leaders also say that clear data guardrails, built-in security, and third-party audits or certifications would make them more confident in adopting it.

Governance and innovation aren’t opposing forces. Done well, governance creates the conditions for responsible innovation. Ultimately, that’s what makes responsible AI scalable, as it moves from individual productivity applications into agents and systems that can act on behalf of employees and businesses.

Want to go deeper? Read our guide to evaluating security, privacy, and governance when you’re deciding whether to build or buy AI.

Kavita
Kavita Patel

Director, Product Legal, Gong

Kavita Patel

Win more with Gong

Loading form...