AI Governance
Written by: Frank Gundlich | Global Head of SAP Data & AI, Capgemini
Updated 10:00 AM EDT, September 1, 2026

Most AI governance frameworks define what the agent is allowed to do.
Almost none define what the agent is allowed to trust — or whether it understands what it is reading.
That gap is not a detail. It is the difference between a governance framework that looks complete on a dashboard and one that can be relied upon when an AI agent makes a consequential decision about your business.
The stakes are not abstract. Gartner projects that through 2026, organizations will abandon 60% of AI projects unsupported by AI-ready data. Separately, MIT’s NANDA initiative found that 95% of organizations studied fail to produce any measurable impact on the P&L from their generative AI initiatives. Neither finding points primarily to model quality. Both raise questions about the layers beneath it.
After two decades running analytics, AI, and data programs across multiple industries, I have come to think of trusted data not as a single property but as a stack of four layers. Understanding where most organizations are building — and where they are not — is the most important governance question a CDO can ask right now.
Based on my experience, there are four layers to consider before an AI decision can be called trustworthy:
Did the record pass validation? Is it complete, consistent, and within range? Most organizations I work with have this or are well on their way to getting there.
How much should the AI trust what it is reading? This covers provenance, verification recency, resolution method, and gap history. Data quality tells you whether the data passed. Data confidence tells you whether it should be believed.
Does the AI understand what this data means for this specific decision-maker? The same number, with the same quality score and the same confidence score, can mean entirely different things depending on who is acting on it. Without ontologies, knowledge graphs, and persona-based KPI definitions, the AI does not know which lens to apply.
How certain is the model of its own output? Most mature AI programs have this in the form of probability scores and confidence thresholds.
Across the enterprise programs I have run, the pattern is consistent: almost every organization I have worked with has Layers 1 and 4 in some form. They may not be perfect, but they are off to a good start and ready to be used. In my experience, the gap is consistently in the middle. Layers 2 and 3 are where AI decisions are actually formed — and, among the organizations I have seen, almost none have explicitly designed the architecture for them.
A data element can pass every quality check and still not be trustworthy for a specific decision.
Consider a demand forecast feeding an inventory optimization model. The records may be complete and within range. But if several gaps were resolved by carrying forward prior-period values, and the last independent verification was fourteen months ago, the confidence basis for a capital decision is very different from what the quality score alone would suggest.
An AI agent operating without Layer 2 does not know any of this. It acts on the quality signal and produces a recommendation that may be technically coherent and organizationally dangerous.
In my experience, Layer 3 carries some of the highest practical risk for AI deployment at scale — and is often one of the least developed areas in AI governance frameworks.
The clearest example: intercompany sales. A regional finance manager sees them as a revenue-affecting contribution margin. The group CFO nets them out entirely. Same data element, same quality score, same confidence score. Two completely different governance implications for any AI recommendation built on top.
Without explicit semantic architecture, the agent optimizes for the wrong objective — not because the model is wrong, but because the meaning was never made explicit.
If the gap in Layers 2 and 3 is understood — and in most organizations, the data team understands it clearly — why is it not being built?
In most cases, the answer is cultural.
The person who surfaces a data gap creates work. They delay a project. They generate questions from stakeholders who expected a decision. The person who quietly resolves the gap — even if the confidence score is never updated — gets a completed task and a grateful project manager.
Multiply that pattern across a team and across months, and you have a governance framework that looks rigorous and is built on a foundation nobody has ever explicitly examined.
This is the CDO’s leverage point. It is not architectural. It is behavioral.
To assess where your organization sits on this framework, ask:
The first two questions reveal the gap. The third reveals whether your organization is capable of closing it.
Once a gap surfaces, closing it is not a platform purchase. It is making three things explicit that most organizations currently leave implicit:
Start with the one AI-driven decision with the highest consequence. Assign a single accountable owner for its Layer 2 and Layer 3 definitions, and require both data confidence and the appropriate semantic context before that decision is allowed to run unsupervised. A narrow scope with real architecture behind it will close the gap faster than a governance policy written for every use case at once.
Most governance conversations start with what the agent is allowed to do. The right second question — the one almost nobody asks explicitly — is what the agent is allowed to trust and whether it understands what it is reading.
Until that question has a deliberate answer, the foundation beneath your governance framework has two missing layers.