Key takeaways
- On August 5, 2026, SC Media published a commentary by Larry Marks arguing that AI governance is the missing enterprise security control, treated as a compliance exercise rather than a control category.
- Most AI risk enters through governance decisions (vendor selection, data exposure, deployment approval) before traditional security controls such as encryption and logging become relevant.
- The EU AI Act remains the reference framework, with obligations under Article 50 and high-risk categories in Annex III, while a coherent US federal statute is unlikely before 2028 to 2030.
- Effective AI governance requires a named role accountable for each AI outcome, in writing, before deployment; documentation without a named owner produces paper rather than governance.
- Boards face three decisions: classify governance as a control, assign a named owner per use case, and determine what governance posture requires disclosure.
What SC Media published on August 5, 2026
On August 5, 2026, SC Media published a commentary by Larry Marks arguing that AI governance compliance operates as the missing security control inside enterprise programs.
The piece reframes a familiar debate. Much of today's discussion centers on securing models, defending against prompt injection, and evaluating emerging threats.
Marks treats those topics as legitimate. He then locates a deeper gap: organizations treat governance as a documentation exercise rather than an essential security capability.
His career observation frames the thesis. Organizations rarely fail for lack of technology; they fail because governance lags the technology they adopt.
The delta: governance as a control category
Security teams have long sorted controls into three categories: preventive, detective, and corrective.
Marks argues that AI governance belongs in that same taxonomy. The claim carries weight because it relocates governance from the audit binder into the control stack.
The distinction matters for a precise reason. Governance shapes risk before technology reaches production. A vendor selection, a data-sharing decision, an approval to deploy an AI-enabled application: each precedes the moment traditional controls activate.
Consider the sequence. A business unit adopts a generative tool, feeds it customer records, and ships an output into a client-facing workflow. Every consequential choice occurred before a single security control engaged.
A compliance posture calibrated for documentation is now overcalibrated for a domain where the decisive choices happen upstream. The audit remains required; the scope has changed.
Where the risk actually enters
The commentary lists the decisions that introduce AI risk long before firewalls, encryption, or logging become relevant.
- Allowing employees to use public generative AI
- Selecting a third-party AI provider
- Approving an AI-enabled business application
- Exposing information to an AI model
- Assigning accountability for decisions influenced by AI
Each item is a governance decision rather than a technical one. That is the mechanism Marks identifies.
Today's programs protect networks, endpoints, identities, applications, and data well. Those controls remain essential. Yet many AI risks arrive upstream of the point where such controls operate, which leaves security teams inheriting exposures that technical controls have no mandate to resolve.
Building on governance that already exists
The commentary offers a measured path. Most organizations require no entirely new AI governance program.
The stronger approach expands disciplines that already function. Architecture review boards, enterprise risk management, and vendor risk management each evaluate technology risk today.
Internal audit, secure development practices, and operational resilience complete the existing scaffolding. AI expands the questions these bodies ask rather than replacing them.
The expansion is incremental by design. Each forum already owns a decision right, a cadence, and an escalation path.
Instead of reviewing authentication, encryption, and logging alone, review boards add questions about training data, model provenance, and accountability for outputs. Organizations that extend proven processes reach coverage faster than those that construct parallel machinery from scratch.
The governance signal: accountability needs a name
Here the analysis meets a standing position of this desk. Accountability that lacks a name is compliance theater.
Frameworks that produce documentation, yet assign no owner, generate paper rather than governance. The SC Media commentary makes the same point in security language: someone must own the associated business risks.
The operative question is concrete. Which named role within the organization is accountable for AI outcomes, by name, in writing, before deployment?
When that answer exists, governance functions as a preventive control. When it is absent, security teams absorb the residual risk after the fact. Organizations that name the owner early convert governance from a reporting ritual into a working control.
The counter-argument worth stating
A reasonable objection exists. Treating governance as a control risks bureaucratizing decisions that demand speed.
Teams under delivery pressure read every new review gate as friction. The commentary anticipates this by rejecting the parallel-program model and favoring extension of existing bodies.
The evidence supports the measured view. Governance that duplicates enterprise risk management adds cost and confusion. Governance that expands the questions asked by boards already in place adds coverage at marginal expense.
The resolution is proportionality. High-impact AI use cases warrant deeper review; low-impact experimentation warrants a lighter touch. A single classification step routes each case to the appropriate depth, which preserves velocity where stakes are modest and concentrates scrutiny where consequences are material.
Three decisions for the board
The commentary is a security argument. The board implication is a governance one. Three decisions follow directly.
- Classification. The General Counsel and Chief Compliance Officer confirm whether governance sits in the control inventory, with preventive, detective, and corrective functions defined.
- Ownership. The Chief Risk Officer identifies the named owner for each AI use case before deployment, recorded in writing.
- Disclosure. The Board Audit and Risk Committee determines what governance posture requires disclosure, and to whom.
Each decision maps to an accountable officer. The CEO carries the strategic constraint: deployment velocity is bound by the maturity of these controls.
The timeline is compressed by adoption rather than by any statute. AI enters workflows faster than governance forums convene, which widens the gap the board must close.
Organizations that answer all three questions in writing retain a defensible audit trail. Those that defer them accumulate exposure that surfaces during incident response, when reconstruction is expensive.
Regulatory horizon
The SC Media commentary is analysis rather than regulation. It carries no statutory force and imposes no deadline of its own.
The enforcement backdrop supplies the deadlines. The EU AI Act remains the reference framework, with obligations under Article 50 and the high-risk categories in Annex III phasing in across the European Union.
US regulation follows a fragmented trajectory. State-level activity signals political position rather than legal certainty, and a coherent federal statute is unlikely before 2028 to 2030.
Three jurisdictions frame the near term: the European Union under the AI Act, the United States under fragmented state law, and the United Kingdom under a principles-based approach.
The question of whether governance is a security control has been answered. A second question has opened: which named role owns each AI outcome, in writing, before deployment? Read more analysis on the Agora blog.
This article was produced by an AI editorial author with human editorial supervision, in accordance with the transparency requirements of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS