Share with your CISO
AI governance has outgrown data protection frameworks, and the gap is becoming a liability. A recent panel convened by Lewis Silkin brought together the ICO’s Head of AI, Microsoft’s Responsible AI Director, and Holistic AI’s co-CEO to map where enterprise governance actually stands. The headlines: the EU AI Act is not becoming the GDPR-equivalent global baseline, over 2,000 AI-related bills are active at US state level alone, and Microsoft has 500,000 AI agents in production requiring identity management and human approval workflows just to maintain basic containment.
What this means for your business
The organisations most exposed here are the ones that bolted AI governance onto their existing data protection programs and called it done. If your current posture treats a DPIA (a structured assessment of privacy risks before data processing begins) as the finish line rather than the starting block, the ICO’s expectations have already moved past you. Shadow AI, where employees use unapproved AI tools outside sanctioned systems, is creating accountability gaps that static compliance checklists simply cannot see, let alone close.
The regionalisation argument is the sharpest claim from this panel, and it holds. The assumption that the EU AI Act would export a single compliance template globally, the way GDPR did for data privacy, has not materialised. The US is moving in the opposite direction, treating AI capability as a strategic asset rather than a systemic risk. For any organisation operating across jurisdictions, this means your compliance architecture cannot be a single document with regional appendices. It has to be modular by design, with different risk tolerances and different disclosure requirements mapped to different markets. The companies that built GDPR compliance as a monolith in 2018 spent years retrofitting it. That playbook is already discredited.
Microsoft’s model points to where the competitive separation actually forms. A dedicated testing team, a formal responsible AI standard functioning as a product-team rulebook, and a partnership with the UK AI Safety Institute for external governance review are not defensive moves. They are what allows you to deploy at scale, 500,000 agents, without losing control of what those agents are authorised to do. The C2PA standard (a technical specification that embeds cryptographically verifiable credentials into digital content to prove its origin and integrity) and third-party assurance aren’t compliance theatre. They’re the infrastructure that makes autonomous AI systems auditable. The question your renewal cycle with any AI vendor should now include is whether their governance stack is independently verified or self-attested, because that distinction is about to matter to regulators and customers alike.
The ICO’s forthcoming call for evidence on agentic AI, expected in early October alongside conclusions on foundational models, is the leading indicator to watch. Guidance on automated decision-making follows by year-end. Organisations that have already invested in cross-functional governance, legal, risk, technical, and finance working together rather than in sequence, will be positioned to respond to that guidance rather than scramble to meet it. Those still running governance as a legal department side project will find the next regulatory cycle compresses their runway considerably.
Based on reporting from AI governance: beyond compliance to competitive advantage, originally published 2026-10-01 12:17:00.

