Enterprise Governance
Who is accountable for AI — and for which AI?
The operating model above every AI system: named accountability, an inventory of everything AI in the enterprise, risk-tiered intake, policy that maps to regulation, and the councils and escalation paths that make decisions stick. Every framework — NIST AI RMF, ISO/IEC 42001, the EU AI Act — starts here, because none of the other layers can work if nobody owns them.
Without named accountability and a live inventory, every other governance layer is theater.
Why leadership should care
- Regulators now regulate AI users, not just AI builders: EU deployer duties, Korea's AI Basic Act, and US state transparency laws all attach obligations to enterprises that merely deploy AI.
- Only 28% of organizations report CEO-level oversight of AI governance (McKinsey, 2025) — accountability gaps are the norm, and they surface in court: Air Canada was held liable for its own chatbot's invented policy.
- Ungoverned adoption burns money as well as trust: 95% of GenAI pilots produced no measurable P&L impact (MIT, 2025), and Gartner expects over 40% of agentic projects canceled by end-2027.
- Who is the single accountable executive for AI, and what does the board see quarterly?
- What is our AI risk appetite — which uses are encouraged, tolerated, and prohibited?
- How fast must the governed path be, so teams choose it over going around it?
Security Command Center AI Protection
GASecurity Command Center
AI inventory discovery, virtual red teaming, AI/agent threat detection.
AI security posture management — including shadow AI inside your cloud.
Model allowlisting (org policy)
GAOrganization Policy
vertexai.allowedGenAIModels restricts which models any project may call.
Central model approval enforced preventively across the resource hierarchy.
Audit Manager
GACompliance
Automated control assessment and evidence collection for AI workloads.
Continuous compliance evidence against ISO 42001, NIST AI RMF, EU AI Act.
ISO/IEC 42001 certification
GACompliance
Accredited AI-management-system certification covering the platform.
Independent attestation your vendor governs AI the way it claims.
Cloud Audit Logs + request-response logging
GAObservability
Immutable admin logs; opt-in data-access and prompt/response logging.
Forensic trail for AI usage — with content logging as a deliberate choice.
Generative AI indemnification
GAContractual
Two-pronged IP indemnity: training data and generated output.
Shifts copyright-infringement risk for covered services to Google.
Cards link to official documentation. Status is a snapshot (August 2026) — verify per component before contractual commitments. Full mapping and honest gaps: 08 · Google Cloud.
You cannot govern what you have not inventoried, and you have not governed what nobody owns.
- Most AI governance programs fail at step zero: nobody can list their AI systems. Discovery plus a registry is the honest starting point.
- Regulation now reaches deployers. Even if you build nothing, EU deployer duties, Korea's act, and US state laws already name you.
- The fastest governed path wins. If review takes six weeks, your real AI estate is whatever shadow tools your teams adopted in week one.
- Ask any vendor — including Google — where policy is enforced, not where it is written.
- Who is your single accountable executive for AI today?
- Could you produce a complete list of AI systems — including agents and AI embedded in SaaS — this week?
- How long does it take a low-risk AI use case to get approved?
- Which of your AI uses would the EU AI Act or your sector regulator call high-risk?
- What evidence could you hand an auditor tomorrow that your controls actually ran?
Highmark Health
Google CloudHealthcare
Centralize access and measure usage first — governance data is what lets you expand safely.
State of Nevada (DETR)
Google CloudGovernment
Public-sector AI needs constrained corpora, human decision-makers, and a standing review committee — and a plan to defend all three publicly.
Macquarie Bank
Google CloudFinancial Services
The number to quote is 99% training completion — workforce readiness is a governance control.