The Question
Most enterprises are behind on AI governance. Not slightly behind — materially behind. Stackcurve research conducted for the 2026 AI Governance CURVE™ Report found that a significant portion of enterprise respondents had no formal AI governance program: no AI system inventory, no governance committee, no acceptable use policy grounded in current AI tool usage, no regulatory framework assessment. They have individual controls — some have CASB monitoring, some have acceptable use policies that predate the current generation of generative AI tools — but no integrated program.
For this cohort, the governance question is not which platform to buy or how to structure board reporting. The question is what to do in the first 90 days to build a foundation that is defensible, functional, and capable of supporting the more sophisticated controls that follow. The wrong answer to this question is common and predictable: spend the first 90 days evaluating governance platforms, conducting RFPs, and building business cases. Enterprises that follow this path typically reach 90 days with a vendor shortlist and no governance program. Enterprises that build the inventory and committee structure first — then select tooling to support what they have built — reach 90 days with a functional foundation.
The 90-day roadmap is not a complete AI governance program. It is the minimum viable governance structure that turns an ungoverned AI posture into a defensible one, and that provides the organizational and data foundation on which a mature program is built.
The AI governance programs that reach maturity in 18 months are the ones that built the inventory and committee in the first 30 days — not the ones that spent the first 90 days evaluating platforms.
Why This Matters Now
The EU AI Act's compliance deadlines have created a forcing function that was absent from enterprise AI governance discussions before 2024. The Act's prohibitions on certain AI practices took effect in February 2025. The requirements for high-risk AI systems — conformity assessments, technical documentation, human oversight, post-market monitoring — apply from August 2026. For enterprises that are starting AI governance from scratch in May 2026, the high-risk system compliance deadline is approximately 90 days away.
This creates a specific urgency: the 90-day roadmap is not just a best-practice framework for building AI governance — for enterprises with EU operations and high-risk AI system deployments, it is a near-term compliance necessity. The EU AI Act defines high-risk AI systems to include AI used in hiring and employment decisions, credit scoring and financial services, educational access, essential services, law enforcement, migration decisions, and AI as a safety component of regulated products. Many enterprises have unknowingly deployed AI systems that meet this classification through AI-enabled SaaS tools.
The FTC's ongoing enforcement posture on AI claims and the state-level AI legislation pipeline — Colorado, Utah, Texas, Illinois have all enacted or advanced AI governance requirements in 2024–2025 — add domestic regulatory urgency. Enterprises that have no AI governance program in place have no compliance defense against the first regulatory inquiry.
The SEC cybersecurity disclosure rules' expansion to include AI-related material risks means that public companies without AI governance programs face potential disclosure obligations they cannot fulfill accurately. Building the inventory and governance structure is the prerequisite for accurate material risk assessment.
What the CURVE™ Data Shows
The 2026 Stackcurve AI Governance CURVE™ Report evaluated which vendor categories are appropriate at each phase of AI governance program maturity — specifically distinguishing between what enterprises starting from zero need versus what mature programs need.
For the Days 1–30 inventory and assessment phase, the relevant vendor category is CASB and AI discovery — specifically Netskope, Zscaler, Lookout, and Microsoft Defender for Cloud Apps, which provide visibility into AI tool usage across the enterprise network. These tools are the fastest path to an AI system inventory that includes shadow AI. The report found that enterprises that started with a CASB-based discovery approach had significantly more complete inventories at 30 days than those that relied on IT asset records and engineering team surveys alone.
For the Days 31–60 foundation phase, the relevant vendor category is lightweight governance workflow tools — Credo AI and Fairly AI for AI-specific governance intake workflows, or extending existing GRC platforms (ServiceNow, OneTrust) if they are already deployed. The report found that enterprises should not invest in dedicated AI governance platforms in this phase; the investment should follow the operating model design, not precede it.
For the Days 61–90 controls phase, CASB policy enforcement (building on the discovery deployment from Phase 1), Microsoft Purview AI Hub for Microsoft 365 environments, and Nightfall AI for data loss prevention at the AI tool layer are the targeted investments for minimum viable technical controls.
The full vendor rankings are in the 2026 Stackcurve AI Governance CURVE™ Report — free to download.
The Gap Most Buyers Miss
The 90-day roadmap looks obvious in retrospect and is routinely executed out of sequence in practice. The most common sequencing failures are: starting with platform evaluation before the inventory is complete (producing a platform selection without the use case requirements the platform needs to support), forming the governance committee before designating an owner with dedicated capacity (producing a committee that meets once and goes dormant), and attempting EU AI Act conformity assessment before completing the inventory (assessing systems against high-risk criteria without knowing which systems exist).
Days 1–30: Inventory and Assessment
The objective of the first 30 days is singular: know what AI is deployed. Not a complete picture — a realistic starting inventory that identifies the highest-risk deployments and the largest unknown areas.
The four discovery mechanisms that must run in parallel:
IT asset discovery — Query the software asset management system for AI-related applications, browser extensions, and API integrations. This will find the formally procured AI tools. It will not find employee-adopted tools and shadow AI.
Engineering team survey — Direct survey of engineering and data science teams on AI models in development and production, including third-party models accessed via API, AI features embedded in approved SaaS tools, and experimental deployments. A structured survey with a two-week completion deadline produces better results than open-ended requests.
Vendor contract review — Review the top 20 vendor contracts for AI capability clauses. AI is now embedded in CRM, HRIS, ERP, and customer service platforms — many enterprises have significant AI deployments through existing vendor relationships that are not visible to the AI governance function.
CASB-based shadow AI discovery — Deploy or activate AI discovery capability in the existing CASB solution. This is the mechanism that surfaces the gap between approved tool usage and actual employee behavior. The delta between the CASB discovery results and the IT asset records is the shadow AI inventory.
The 30-day output is not a perfect inventory. It is an inventory that is honest about its completeness — which systems are confirmed, which categories are known unknowns, and what the estimated scale of ungoverned AI usage is. A spreadsheet is appropriate for this phase. The investment in governance tooling should follow the inventory, not precede it.
Days 31–60: Foundation
The objective of Days 31–60 is to establish the governance structure that will operate the program: committee, ownership, policy, and regulatory exposure assessment.
Form the AI governance committee — Using the membership model described in Brief 16 of this series. Executive sponsor, legal, compliance, business unit representatives, AI/ML engineering, HR, privacy/data governance, and risk management. Issue formal charters within this phase. Committees that do not have charters rarely survive the organizational pressures that arise in months two and three.
Designate an AI governance owner — A specific individual with dedicated capacity — not a shared responsibility between the CISO and CTO, not a committee chair by title without dedicated time. This person owns the intake process, the inventory maintenance, the committee agenda, and the regulatory monitoring function. Without a designated owner, governance programs diffuse into committee meeting minutes.
Write the initial AI acceptable use policy — Ground the policy in the existing data classification framework. The policy should specify which data classifications cannot be submitted to AI tools not on the approved list, what the approved tool list is (even if incomplete), the intake process for adding tools to the approved list, and the consequence framework for violations. Apply the drafting principles from Brief 17 of this series: specificity, approved alternatives for every prohibition, proximity delivery, consequence clarity.
Conduct EU AI Act high-risk classification assessment — Apply the EU AI Act Annex III high-risk AI system list to the top 10 AI systems from the inventory. This assessment does not need to be comprehensive — it needs to identify which systems are potentially in scope for high-risk requirements and what the conformity assessment gap is for each. Legal counsel with EU AI Act expertise should lead this assessment.
Days 61–90: Controls and Monitoring
The objective of Days 61–90 is to implement minimum viable technical controls and establish the operational processes that keep the governance program functioning.
Publish the approved AI tool register — Based on the inventory and the initial policy, publish the list of approved AI tools with use-case guidance. This is the practical output of the policy that employees actually interact with. The register needs a maintenance process — quarterly review is minimum.
Deploy CASB-based shadow AI monitoring and enforcement — Transition the CASB deployment from discovery mode to monitoring and enforcement mode. Establish alerting for high-risk data submission to unsanctioned AI tools. Shadow AI monitoring is the technical control that makes the acceptable use policy enforceable.
Implement the AI deployment intake process — Establish the formal process for reviewing and approving new AI deployments. Submission requirements, review timeline, committee approval workflow, approved deployment documentation. The intake process prevents the inventory from going stale the moment a new AI tool is deployed.
Establish board reporting cadence — Schedule the first board AI risk report for the end of month three. The report format should follow the model in Brief 18 of this series: inventory numbers, material risk items in financial terms, regulatory exposure with timeline, decisions requested. The first report does not need to be comprehensive — it needs to establish the reporting relationship and demonstrate that the governance program has an executive communication function.
Begin AI vendor due diligence — For the five AI vendors with the highest deployment footprint from the inventory, initiate vendor AI due diligence: request AI transparency documentation, review data processing agreements for AI training data clauses, assess EU AI Act compliance posture for high-risk system vendors.
Questions Your Buying Team Should Be Asking
1. Do we know — specifically — how many AI systems are deployed in our environment today, including AI embedded in SaaS tools and employee-adopted tools?
If the honest answer is "no" or "we have a partial picture," the inventory is your first 30 days. Not the committee, not the policy, not the platform evaluation. The inventory is the foundation on which everything else is built. An AI governance committee that does not have an inventory is governing a system it cannot see.
2. Who is the designated AI governance owner with dedicated capacity — not a shared responsibility, not a committee role, but a specific individual whose primary job function includes AI governance?
The absence of a dedicated owner is the single most reliable predictor of AI governance program failure. Shared ownership diffuses accountability. Committee ownership without a designated operational lead produces governance by meeting minutes. The investment in a dedicated governance owner — even at 0.5 FTE in the first 90 days — is the investment that determines whether the program persists through organizational pressure.
3. Have we assessed our top-10 AI deployments against the EU AI Act Annex III high-risk AI system list, and do we have legal counsel with EU AI Act expertise involved in that assessment?
For enterprises with EU operations, this assessment should have happened already. For enterprises beginning from scratch in 2026, it is a Days 31–60 priority. High-risk AI system classification under the EU AI Act is not self-evident — the Annex III definitions require legal interpretation, and the European AI Office's guidance documents have evolved since the Act entered into force. In-house counsel without EU AI Act expertise should not conduct this assessment unassisted.
4. What is our plan for getting from the 90-day foundation to a mature AI governance program, and who owns the roadmap beyond day 90?
The 90-day roadmap produces a defensible foundation. It does not produce a mature program. Year-one goals — EU AI Act conformity assessments for confirmed high-risk systems, a systematic bias audit program, mature AI incident response, full vendor AI due diligence coverage — require a roadmap beyond 90 days with designated ownership and committed investment. The governance owner designated in Days 31–60 should own the year-one roadmap; the AI governance committee should approve and resource it.
5. Are we treating AI governance as a program with a designated owner and committed budget, or as a project with a completion date?
AI governance programs that are structured as projects — with a defined deliverable, a completion date, and no ongoing operational ownership — consistently fail to maintain their controls after the initial project closes. AI capabilities change quarterly. Regulatory requirements are actively evolving. Employee AI tool usage patterns shift continuously. AI governance is an operational function, not a project, and the enterprises that build durable programs staff and fund it accordingly.
The Stackcurve Take
The 90-day roadmap is deliberately modest in its ambitions. It does not promise EU AI Act conformity, a mature bias audit program, or full vendor coverage. It promises a defensible foundation: an inventory that is honest about what it contains and what it does not, a governance structure with the right membership and a designated owner, a policy that employees can actually follow, and minimum technical controls that make the policy enforceable.
That foundation matters disproportionately because the governance controls built in months four through eighteen depend on it. An inventory you trust informs vendor due diligence. A committee with the right membership produces policies that get followed. A designated owner sustains the program through organizational change and competing priorities. Enterprises that skip the foundation and start with platform evaluation or regulatory assessment are building on sand — and they find out when the first incident tests their incident response capability, or the first regulatory inquiry asks for documentation of their governance program.
The sequence matters as much as the activities. Inventory before committee. Committee before policy. Policy before technical controls. Controls before board reporting. The enterprises that invert this sequence spend months building governance controls for AI systems they have not fully inventoried, enforced by policies that do not reflect actual workflows, reported to boards that have not been given the context they need to engage.
The 2026 Stackcurve AI Governance CURVE™ Report covers the full AI governance program maturity model — from the 90-day foundation through the 18-month mature program — including the vendor categories, regulatory frameworks, and operating models appropriate at each stage. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.