The Governance Gaps Killing Your AI Program (and How to Close Them)
Two years of WEF working group research identifies the most recurring governance failures: unassessed third-party tools, unclear accountability, and low enterprise-wide AI visibility.
What Two Years of WEF Research Found
The World Economic Forum's AI Governance Alliance, with Accenture as knowledge partner, spent two years studying how organisations of different sizes, sectors, and geographies fail at AI governance. The September 2025 output — identifying nine essential plays for responsible AI governance — is grounded in observed patterns, not theoretical frameworks. The most valuable finding is not the nine plays themselves but the recurring failure modes they are designed to close: legacy systems that cannot support governance requirements, unclear accountability structures that mean every risk question escalates without resolution, unassessed third-party AI tools embedded in existing systems, and limited enterprise-wide visibility into what AI is actually operating.
Gap 1: Unassessed Third-Party AI
The WEF identifies unassessed third-party AI tools as one of the two most recurring failure points across organisations studied. This is distinct from the EU AI Act's deployer liability problem — it is more fundamental. Organisations do not know what AI is operating inside the vendor products they have procured. Closing this gap requires a third-party AI inventory that covers AI capabilities embedded in vendor products, not just AI models licensed directly. This inventory needs to be connected to the same risk and compliance workflow as internal AI systems — not maintained as a separate vendor risk questionnaire cycle.
Gap 2: Unclear Accountability
The second most recurring failure the WEF identifies is unclear accountability structures. When a risk materialises from an AI system, who is accountable? In most organisations, the answer depends on who the auditor asks. The AI team says the risk team. The risk team says the business unit. The business unit says the AI team. Closing this gap is not an HR problem — it is a governance design problem. Every AI system needs a named owner with documented accountability for risk assessment, control design, and ongoing monitoring. That accountability needs to be recorded in the governance system of record, visible to the board, and refreshed when the owner changes.
Gap 3: Low Enterprise-Wide Visibility
The third gap — limited enterprise-wide visibility into AI usage — is the one that makes the other two invisible. An organisation that cannot see its full AI estate cannot assess which systems are unassessed, cannot identify where accountability is unclear, and cannot measure governance maturity. The WEF research identifies this as both an internal roadblock (legacy systems, siloed governance) and an external one (regulatory fragmentation that makes cross-jurisdiction AI inventories complex). The practical close for this gap is treating AI governance data — declarations, risk ratings, obligation statuses, maturity scores — as a managed asset, not a byproduct of annual reviews.
External Roadblocks: Regulatory Fragmentation
Beyond internal gaps, the WEF identifies regulatory fragmentation as an external roadblock that compounds the others. An enterprise operating in multiple jurisdictions cannot maintain separate governance programs for each regulatory framework without creating the version-drift and re-keying problems that fragment accountability further. The practical answer is a governance platform that maps a single set of governance data — one risk rating, one control evidence record, one use-case declaration — across multiple regulatory frameworks simultaneously, generating jurisdiction-specific compliance views from a shared record.
The exact roadblocks the WEF names — unassessed third-party tools, unclear accountability, low visibility — are the specific gaps Wahid AI's unified modules are designed to close in one workflow. Third-party oversight gives every vendor AI an assessment and a monitoring record. The risk register names one owner per risk. The governance record gives the board live visibility across the full AI estate — not a static snapshot requested at quarter-end.
RELATED TOPICS
Ready to operationalise these governance frameworks?
Wahid AI integrates ISO 42001, EU AI Act, NIST AI RMF, and APRA CPS 230 into one governed workflow. See it in a 30-minute demo.
EXPLORE FURTHER