
Without structured controls, AI risks accumulate quietly. Shadow AI deployments, unmonitored model drift, and gaps between what AI is registered and what's actually in use are more common that most realise in practice. Grant Thornton's Alex Hunt outlines how to build strong AI governance, oversight and monitoring.
AI is being deployed faster than organisations can govern it, and regulation is tightening and converging worldwide.
The EU AI Act, with fines of up to 7% of global annual turnover, has a shifting timetable: transparency obligations apply from August 2026, while high-risk deadlines may move to December 2027 and August 2028 under the proposed Digital Omnibus. Because the Omnibus isn't yet formally enacted, organisations are advised to keep preparing against the original dates. Alongside NIST's AI Risk Management Framework, ISO/IEC 42001 and new laws emerging in South Korea and Vietnam, a common global standard is taking shape.
The challenge is meeting these obligations without slowing innovation.
Grant Thornton's article explores how a modular, risk-based framework can give innovators clear lanes to work in, and sets out the non-negotiables of effective oversight: a centralised AI inventory, continuous performance monitoring, immutable audit logs, portfolio-level risk dashboards, automated escalation, and integration with existing GRC frameworks.
Learn More:
Read the full article here to find out how to build governance that delivers visibility, accountability and the ability to act quickly when something changes.