AI Governance

AI Governance Has a Foundation Problem: Two Layers Down

Written by: Frank Gundlich | Global Head of SAP Data & AI, Capgemini

Updated 10:00 AM EDT, September 1, 2026

post detail image
Frank Gundlich | Global Head of SAP Data & AI, Capgemini Frank Gundlich is Global Head of SAP Data & AI at Capgemini, specializing in AI governance and trusted data. He is the author of "The Supply Chain Reckoning."

Most AI governance frameworks define what the agent is allowed to do.

Almost none define what the agent is allowed to trust — or whether it understands what it is reading.

That gap is not a detail. It is the difference between a governance framework that looks complete on a dashboard and one that can be relied upon when an AI agent makes a consequential decision about your business.

The stakes are not abstract. Gartner projects that through 2026, organizations will abandon 60% of AI projects unsupported by AI-ready data. Separately, MIT’s NANDA initiative found that 95% of organizations studied fail to produce any measurable impact on the P&L from their generative AI initiatives. Neither finding points primarily to model quality. Both raise questions about the layers beneath it. 

After two decades running analytics, AI, and data programs across multiple industries, I have come to think of trusted data not as a single property but as a stack of four layers. Understanding where most organizations are building — and where they are not — is the most important governance question a CDO can ask right now.

The four layers — and where the gap is

Based on my experience, there are four layers to consider before an AI decision can be called trustworthy: 

Layer 1: Data quality

Did the record pass validation? Is it complete, consistent, and within range? Most organizations I work with have this or are well on their way to getting there.

Layer 2: Data confidence

How much should the AI trust what it is reading? This covers provenance, verification recency, resolution method, and gap history. Data quality tells you whether the data passed. Data confidence tells you whether it should be believed.

Layer 3: Semantic context

Does the AI understand what this data means for this specific decision-maker? The same number, with the same quality score and the same confidence score, can mean entirely different things depending on who is acting on it. Without ontologies, knowledge graphs, and persona-based KPI definitions, the AI does not know which lens to apply.

Layer 4: Model confidence

How certain is the model of its own output? Most mature AI programs have this in the form of probability scores and confidence thresholds.

Across the enterprise programs I have run, the pattern is consistent: almost every organization I have worked with has Layers 1 and 4 in some form. They may not be perfect, but they are off to a good start and ready to be used. In my experience, the gap is consistently in the middle. Layers 2 and 3 are where AI decisions are actually formed — and, among the organizations I have seen, almost none have explicitly designed the architecture for them.

Why “valid” does not mean “trustworthy”

A data element can pass every quality check and still not be trustworthy for a specific decision.

Consider a demand forecast feeding an inventory optimization model. The records may be complete and within range. But if several gaps were resolved by carrying forward prior-period values, and the last independent verification was fourteen months ago, the confidence basis for a capital decision is very different from what the quality score alone would suggest.

An AI agent operating without Layer 2 does not know any of this. It acts on the quality signal and produces a recommendation that may be technically coherent and organizationally dangerous.

Why semantic context is often the missing layer 

In my experience, Layer 3 carries some of the highest practical risk for AI deployment at scale — and is often one of the least developed areas in AI governance frameworks

The clearest example: intercompany sales. A regional finance manager sees them as a revenue-affecting contribution margin. The group CFO nets them out entirely. Same data element, same quality score, same confidence score. Two completely different governance implications for any AI recommendation built on top.

Without explicit semantic architecture, the agent optimizes for the wrong objective — not because the model is wrong, but because the meaning was never made explicit.

Why the gap persists — and why it is not a technical problem

If the gap in Layers 2 and 3 is understood — and in most organizations, the data team understands it clearly — why is it not being built?

In most cases, the answer is cultural.

The person who surfaces a data gap creates work. They delay a project. They generate questions from stakeholders who expected a decision. The person who quietly resolves the gap — even if the confidence score is never updated — gets a completed task and a grateful project manager.

Multiply that pattern across a team and across months, and you have a governance framework that looks rigorous and is built on a foundation nobody has ever explicitly examined.

This is the CDO’s leverage point. It is not architectural. It is behavioral.

Three questions to ask in your next governance review

To assess where your organization sits on this framework, ask:

  1. Can you produce a data confidence score — reflecting provenance, verification recency, and resolution method — for any data element feeding a consequential AI decision? Or do you have only a quality flag?
  2. Is your AI operating with the right KPI definition for the specific decision-maker it is supposed to serve? Or is it applying a single definition to contexts that require different ones?
  3. What happened the last time someone said “I don’t know” about a data element in a governance meeting? Was it treated as a risk that needed managing, or a problem that needed to disappear?

The first two questions reveal the gap. The third reveals whether your organization is capable of closing it.

Once a gap surfaces, closing it is not a platform purchase. It is making three things explicit that most organizations currently leave implicit:

  • Provenance and lineage tracking: Capture where each data element originated, how it was verified, and when it was last independently checked — the raw material a Layer 2 confidence score is built from.
  • A confidence-scoring layer: Attach a machine-readable score for provenance, recency, and resolution method to the data itself, so the AI consumes the score alongside the number — not the number alone.
  • A semantic or ontology layer: Encode persona-based KPI definitions so the same data element carries the right meaning for whichever decision-maker — or agent acting on their behalf — is reading it.

Start with the one AI-driven decision with the highest consequence. Assign a single accountable owner for its Layer 2 and Layer 3 definitions, and require both data confidence and the appropriate semantic context before that decision is allowed to run unsupervised. A narrow scope with real architecture behind it will close the gap faster than a governance policy written for every use case at once.

Most governance conversations start with what the agent is allowed to do. The right second question — the one almost nobody asks explicitly — is what the agent is allowed to trust and whether it understands what it is reading.

Until that question has a deliberate answer, the foundation beneath your governance framework has two missing layers.

Related Stories

September 17, 2026  |  In Person

Chicago Leadership Summit

Renaissance Chicago Downtown Hotel

Similar Topics
Artificial Intelligence
Data Management
Diversity
Testimonials
background imagebackground image
Community Network

Join Our Community

starElevate Your Personal Brand

starShape the Data Leadership Agenda

starBuild a Lasting Network

starExchange Knowledge & Experience

starStay Updated & Future-Ready

logo
Social media icon
Social media icon
Social media icon
Social media icon
About