Executive Summary
Artificial intelligence is rapidly transforming the financial services industry. Financial institutions are leveraging AI to improve customer experiences, strengthen fraud detection, enhance operational efficiency, support compliance activities, and inform business decisions. As adoption accelerates, executive leadership faces an equally important responsibility: establishing governance programs capable of overseeing these technologies responsibly.
An AI governance program is more than a collection of policies or isolated controls. It is an enterprise capability that establishes accountability, supports informed decision-making, manages risk, and enables organizations to innovate responsibly while adapting to an evolving regulatory landscape.
This article explores why organizations should begin building AI governance programs today, how the regulatory landscape is reshaping executive priorities, and why integrating AI governance into existing enterprise governance structures provides the strongest foundation for long-term success.
Introduction
Only a few years ago, many executive conversations focused on whether artificial intelligence would become a meaningful part of financial services.
Today, that question has largely been answered.
Across the industry, organizations are using AI to strengthen fraud detection, improve customer experiences, automate operational processes, enhance compliance monitoring, and support business decision-making. As adoption continues to accelerate, executive leadership must ensure governance evolves alongside innovation.
Many organizations begin by drafting an AI policy or forming an oversight committee. While those are important first steps, they do not constitute an AI governance program.
Effective governance requires far more than documentation. It requires a coordinated enterprise framework that establishes accountability, supports informed decision-making, manages risk, and enables responsible innovation.
This second article in the AI Governance Summer Series explores why organizations should begin building AI governance programs now and how existing enterprise governance capabilities can provide the foundation for long-term success.
The Regulatory Landscape Is No Longer Hypothetical
AI governance is no longer driven solely by voluntary frameworks and industry best practices. Around the world, governments are establishing legal and regulatory expectations governing how artificial intelligence should be developed, deployed, and overseen.
The European Union Artificial Intelligence Act (EU AI Act) represents the world's first comprehensive legal framework dedicated specifically to artificial intelligence. Built upon a risk-based approach, the Act establishes governance, transparency, documentation, human oversight, and risk management requirements based upon the level of risk presented by an AI system. Its influence extends well beyond Europe and has become an important reference point for organizations developing enterprise AI governance programs.
Within the United States, the regulatory landscape continues to evolve through state legislation. Although there is currently no comprehensive federal AI governance law, states are increasingly adopting laws addressing transparency, automated decision-making, consumer protections, employment, generative AI, and responsible AI development.
Notable examples include:
- Colorado, which enacted a broad framework governing automated decision-making technologies used in consequential decisions.
- Texas, through the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), established enterprise governance requirements while prohibiting certain harmful AI practices.
- California, which continues expanding AI regulation through targeted legislation addressing generative AI, transparency, disclosure, and public-sector use.
- Utah, which established an innovation-focused governance model through its Artificial Intelligence Policy Act and Office of Artificial Intelligence Policy.
- Illinois, which has integrated AI governance into employment and civil rights protections while continuing to consider broader AI legislation.
While these laws differ in scope and approach, they point toward the same conclusion: organizations should not build governance programs around a single law or jurisdiction. Instead, they should establish scalable governance frameworks capable of adapting as regulatory expectations continue to evolve.
Organizations that build governance capabilities today will be better positioned to adapt as AI regulation continues to mature.
Selected Official Resources
- European Commission – AI Act: commission.europa.eu
- EUR-Lex – Regulation (EU) 2024/1689 (AI Act text): eur-lex.europa.eu
- California SB 942 – AI Transparency Act: leginfo.legislature.ca.gov
- California AB 2013 – Generative AI Training Data Transparency: leginfo.legislature.ca.gov
- Colorado Attorney General – AI Governance Rulemaking: coag.gov
- Texas HB 149 – Responsible Artificial Intelligence Governance Act (TRAIGA): capitol.texas.gov
- Utah SB 149 – Artificial Intelligence Policy Act: le.utah.gov
- Illinois HB 3773 – AI in Employment (Illinois Human Rights Act): ilga.gov
Governance Is More Than Policy
One of the most common misconceptions surrounding AI governance is the belief that publishing an AI policy or establishing an oversight committee is sufficient to demonstrate governance.
While both are important, neither constitutes an AI governance program.
A policy establishes expectations. A governance program establishes accountability.
An effective AI governance program defines how decisions are made, how risks are identified and managed, how oversight is exercised, how issues are addressed, and how governance continues to evolve as technology and regulations change.
Without that structure, organizations often find themselves reacting to AI-related issues rather than proactively governing them.
Rather than creating separate governance structures, financial institutions should leverage the governance capabilities they have already established across enterprise risk management, compliance, operational risk, information security, privacy, third-party risk, model risk management, product governance, and internal audit.
The objective is not to govern artificial intelligence in isolation. The objective is to govern how artificial intelligence is designed, acquired, deployed, monitored, and used throughout the enterprise.
An AI policy may begin the conversation, but only an enterprise governance program can sustain responsible AI.
Build on Existing Governance Strengths
Many organizations approach AI governance as though they are starting from scratch. In reality, most financial institutions already possess many of the governance capabilities needed to oversee artificial intelligence effectively.
Rather than creating duplicate governance structures, organizations should evaluate how existing governance forums, reporting structures, committees, policies, controls, and oversight functions can be expanded to address AI-specific risks and responsibilities.
This integrated approach allows institutions to leverage existing governance investments while creating a scalable framework capable of evolving alongside emerging technologies and regulatory expectations.
The strongest AI governance programs are not built beside enterprise governance—they are built within it.
AI governance should become another enterprise capability, not another organizational silo.
Moving From Concept to Implementation
Understanding why AI governance matters is only the beginning. The more challenging question for many organizations is where to begin.
Should AI governance operate as a standalone function or be integrated into existing governance structures? Who should own the program? How should accountability be established? Which governance committees should provide oversight? What role should executive leadership, compliance, technology, information security, internal audit, and the business each play?
These are not questions with one-size-fits-all answers. Every organization must design a governance program that reflects its size, complexity, strategic objectives, risk profile, and regulatory environment.
Rather than adopting disconnected policies or isolated controls, executive leaders should focus on developing an enterprise governance program that aligns with existing governance capabilities while remaining flexible enough to evolve alongside technology and regulation.
These topics—and the practical considerations for designing, implementing, and maturing an AI governance program—are explored in greater detail in my guidebook, Building an AI Governance Program: A Practical Guide for Financial Institutions.
An article introduces the conversation. A governance program requires a roadmap.
Conclusion
Artificial intelligence will continue transforming the financial services industry. The organizations that realize its greatest value will not necessarily be those that adopt AI the fastest, but those that govern it the most effectively.
Building an AI governance program is not about slowing innovation. It is about creating the structure, accountability, and oversight necessary to innovate responsibly while maintaining the confidence of customers, employees, regulators, investors, and other stakeholders.
Organizations that begin building those governance capabilities today will be better prepared not only to comply with tomorrow's regulatory expectations, but to innovate with greater confidence, resilience, and trust.
Companion Resources
Continue exploring AI governance through the companion resources developed alongside the AI Governance Summer Series.
Executive AI Governance Maturity Assessment
Evaluate your organization's AI governance maturity across eleven core governance domains.
Download the AssessmentAI Governance White Paper
Explore additional executive insights that complement this article and the AI Governance Summer Series.
Download the White PaperGuidebook
Building an AI Governance Program: A Practical Guide for Financial Institutions. Expand beyond the concepts introduced in this article with a practical framework for designing, implementing, and maturing an enterprise AI governance program.
Coming Soon