Navigating CMMC and FedRAMP Together: From Assessment-Ready to Authorized | July 22nd

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

AI Governance Programs: What CISOs Say vs. What They Actually Do

Artificial Intelligence

Published: Jul 22, 2026

Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they're doing about it and what's actually happening inside their organizations.

I got to test this disconnect at a recent private CISO summit in Chicago as the closing keynote alongside Dr. Fred Kwong, VP and CISO for DeVry University.

5 Key AI Governance Program Takeaways

  1. AI deployment has far outpaced AI governance and security. The U.S. spent $700 billion on AI infrastructure in a single year. For comparison, the entire federal highway system cost roughly $630 billion, spread across 36 years.
  2. There's a real gap between survey data and reality. 74% of organizations believe they could pass an AI compliance audit today. Only 27% have a fully mature AI governance program. That 47-point gap is where the risk lives.
  3. Governance is not the brake on AI. It is the accelerant. Organizations with mature AI governance deploy AI agents at 3.5 times the rate of those without it.
  4. AI governance often has no clear owner. It gets assigned to a committee instead of a person. 54% of organizations can't say who owns AI governance at their company. It's hard to pass an audit nobody owns.
  5. Strong AI governance starts with strong data governance. This is something CISOs have been shouting from the rooftops for years.

The Gap Between What CISOs Say and What AI Governance Programs Actually Do

At a private CISO conference in June 2026, 82% of security leaders said they plan to build more of their own AI tooling. Yet most have no plan in place to maintain what they build. The tooling is sprawling faster than governance can keep up.

The same disconnect shows up in vendor strategy. 86% expect major AI platforms to become part of their security stack, but only 6% are actually consolidating onto them today.

The pattern continues with agents in production. 86% of organizations have AI agents live, but fewer than half have controls to match. Meanwhile, 44% have written AI-specific incident response procedures, even though 65% have already had an AI incident or near-miss.

The AI Governance Program Fingerprints Test

One of the sharpest moments from the session was a simple diagnostic for whether a governance program is real or just paperwork. You should consider where your governance program has:

  • Changed a decision
  • Killed a feature
  • Forced a retrain
  • Made someone wait

If your governance program can't point to a specific moment where it did one of these things, you don't have a program. You have paperwork.

Where CISOs Go from Here

The session closed with a practical set of next steps for closing the gap:

  1. Visibility first. You can't govern AI you can't see.
  2. Risk-tier it. Govern the payroll agent, not the meeting summarizer.
  3. Validate behavior, not policies - for both first-party and third-party AI.
  4. Remember mature governance is the accelerant, not the brake.
  5. Run the fingerprints test.

Writing the AI policy is the easy part. The harder work is proving that your first- and third-party agents actually behave the way it says they do. The good news: we are all playing catch-up with the speed of AI deployment.

About Sachin Bansal

Sachin Bansal is the Chief Operating Officer of Schellman, and he is based out of New York City. Prior to joining Schellman in 2026, Sachin was a cyber operating advisor at TPG Capital. Before that, he was President of SecurityScorecard, where he scaled the business by 6X and built its public sector practice. Sachin is proudly a 2X Schellman customer (FedRAMP). A recovering attorney, he earned both his undergraduate and law degrees from Duke University and is admitted to the New York and New Jersey bars. With nearly 20 years spanning law, GTM, M&A, and operations, Sachin has worked across cybersecurity, government, and financial services. He is now focused on scaling Schellman for its next chapter via the strategic partnership with Goldman Sachs, and helping its clients build trust through security and compliance. Outside of work, Sachin performs stand-up comedy across New York City. He also drinks decaf because he likes to live dangerously.