Calculated on the $725 billion of 2026 CapEx declared by Microsoft, Amazon, Alphabet and Meta (+77% on the $410 billion of 2025), broken down to value per second. Source: Yahoo Finance, 2026.
AI Governance is the system through which an organisation sets the rules, responsibilities and measurement criteria for its use of artificial intelligence. It is not, therefore, merely an IT function; nor is it a policy document.
This is the mechanism that decides who can adopt a new AI tool, through which process, with which objectives and with which method for verifying results.
The discipline covers tool selection, assignment of responsibilities, data management, regulatory compliance and verification of results. The policy is just one component: the real value of AI governance emerges when rules become embedded in the company’s decision-making and operational processes.
KPMG’s Global AI Pulse Q1 2026, a survey of 2,110 senior executives across 20 countries, captured a still-wide gap between adoption and economic return: 95% of organisations say they have an AI strategy, while only 8% report an established ROI. Average planned investment over the following twelve months reaches $186 million. The central issue is therefore the ability to turn spend, processes, data and skills into an integrated system.
This guide covers the operational path: how to structure AI governance, which phases it involves, how return is measured and how the system is updated over time. The page dedicated to Bliss AI Governance describes the advisory method and the deliverables applied to each organisation’s specific context; here, by contrast, you will find all the information on the subject.
From AI CapEx to a control system
Before structuring governance, the object to be governed must be reconstructed. Investment in artificial intelligence includes CapEx (that is, infrastructure, hardware, data centres and capitalisable multi-year licences) and operating costs spread across subscriptions, tokens, cloud, integrations, training and human oversight. For a closer look at the accounting and strategic distinction, the guide CapEx: meaning, difference from OpEx and new expenses to watch analyses how AI is changing the way organisations interpret and allocate these investments.
AI-related CapEx and OpEx can be spread across different functions and cost centres, often below the thresholds that trigger centralised approval. In financial statements and public reporting, AI spend is rarely isolated; even within companies, it can be difficult to distinguish multi-year investments from experimentation costs and from those required to maintain processes already in operation.
Data quality is one of the first selection factors. Gartner predicts that, by 2026, organisations will abandon 60% of AI projects unsupported by AI-ready data. Governance therefore starts with visibility: which tools are in use, what data they process, what they cost, who governs them and what results they produce.
The 4-phase framework
The best method for managing artificial intelligence follows four phases. Each phase produces a verifiable output and assigns an internal owner, so that the system can continue even after the advisory engagement has ended.
| Phase | Strategic question | Concrete output | Indicative duration |
| 1. AI Audit | What do we use, what does it cost and what does it deliver? | Map of tools, data, costs and results | 2-3 weeks |
| 2. AI Strategy | Where does AI create value, and with what priorities? | Use-case portfolio and 12-month budget | 3-5 weeks |
| 3. AI Governance System | Who decides, which risks are accepted and what evidence is kept? | Adoption rules, responsibilities, classification and documentation | 4-8 weeks |
| 4. AI Monitoring | Does the system deliver the expected results and stay up to date? | Periodic reporting, KPI review and update of controls | Ongoing |
1. AI Audit: starting from what exists
The starting point often holds a surprise. There may be more AI tools in use than management imagines, real costs higher than those tracked, and some services producing no results of any kind.
One subscription leads to another, as we know only too well. And all too often, companies lose track entirely of the tools they use. The AI Audit maps the entire arsenal of artificial intelligence in use, in order to establish its purpose, data, cost, integrations, risks and actual results.
The review almost always uncovers duplications, abandoned tools or free trials that have turned into something more.
The final output is a decision inventory. For each tool, the organisation can choose whether to stop the spend, consolidate usage, integrate the process or launch a more in-depth assessment.
2. AI Strategy: deciding where to invest
McKinsey estimates that generative AI and automation technologies could act on activities that absorb 60-70% of working time. The technical potential is broad; economic viability depends on process volume, variability, data quality, integration costs and the level of oversight required.
The strategic phase selects use cases against shared criteria: expected economic value, technical feasibility, data availability, operational risk, impact on people and alignment with business priorities. The result is an ordered portfolio, with budget, sponsor, timelines, baseline and success thresholds defined before implementation.
3. AI Governance System: defining decisions, risk and compliance
The AI Governance System is the operational document that assigns authority and responsibility. It establishes who can propose a new tool, who assesses the use case, who approves the spend, who checks the data, who oversees risk and what evidence must be retained.
The regulatory component follows the phased timetable of the AI Act. According to the official European Union timeline, the transparency rules apply from 2 August 2026, when enforcement also begins for the provisions already applicable. Under the current timetable, obligations for Annex III high-risk systems apply from 2 December 2027, and those for systems embedded in Annex I regulated products from 2 August 2028.
The penalties set out in Article 99 vary by infringement and can reach 7% of worldwide turnover for prohibited practices and 3% for other breaches. The actual classification depends on the organisation’s role and the use case; the governance system must therefore be coordinated with legal assessment and with privacy and security safeguards.
4. AI Monitoring: measure and update
The AI market moves quickly: new models, tools, costs, risks and obligations alter decisions already taken. Monitoring selects the changes relevant to the business, updates controls where necessary and regularly reviews the performance of the KPIs defined in the strategic phase.
The periodic report should show at least actual spend, usage, results, variances against the baseline, incidents, human reviews and open decisions. In this way governance becomes a cycle of learning and reallocation, able to increase effective investments and close those that fail to reach the agreed thresholds.
How AI ROI is measured
Economic return requires a pre-adoption baseline and a complete cost perimeter. Beyond licences, tokens and cloud, the calculation must include integration, training, maintenance, security, human oversight and change management.
Operational formula: AI ROI = (net economic benefits – total costs) / total costs x 100. The formula becomes meaningful when benefits and costs are linked to a specific process and observed over a defined period.
| Dimension | Key KPIs | Required baseline | Frequency |
| Efficiency | Hours per task, cost per case, cycle time | Process performance before AI | Monthly |
| Quality | Error rate, rework, accuracy, human escalations | Errors and controls in the previous process | Monthly or quarterly |
| Revenue | Leads, conversion, incremental margin, retention | Commercial performance over the comparable period | Quarterly |
| Adoption and risk | Active users, approved use cases, incidents, shadow AI, completed audits | Initial map of tools and controls | Monthly |
A project can generate value even before producing direct revenue, for example by reducing errors or response times. Governance makes this choice explicit and prevents usage metrics, such as the number of prompts or active users, from being confused with economic return.
From policy to operating system
IBM’s Cost of a Data Breach Report 2025 finds that 63% of the organisations in the study had no AI governance policies or were still developing them. Even among organisations with policies, fewer than half applied rigorous approval procedures for new deployments.
The gap between document and practice narrows when every rule is linked to an owner, a process step and verifiable evidence.
| Criterion | Without structured oversight | With AI Governance |
| Adoption | Tools chosen by individual teams on the basis of demos, urgent needs or local initiatives | Assessment of problem, expected value, data, risk and integration |
| ROI | Usefulness assessed after adoption, with no shared baseline | KPIs and baseline defined before the pilot, with go/no-go thresholds |
| New technologies | Overlapping experiments and uncoordinated recurring costs | Selective scouting and explicit replacement of tools or processes |
| Responsibility | Ownership fragmented across IT, business functions and suppliers | Executive sponsor, operational owner and documented risk responsibilities |
| Compliance | Documentation reconstructed when a request or incident arises | Classification, registers, controls and oversight built into the adoption cycle |
The impact on brand identity
AI Governance affects communications.
Every tool used to produce content, sales responses or internal materials can influence positioning, tone of voice and the quality of the relationship with the audience. Brand Governance defines the criteria of identity; AI governance translates them into instructions, responsibilities, controls and review processes applicable to generative tools.
A language model without guidelines tends to reproduce general patterns from its training. A governed system, by contrast, provides context, authorised sources, examples, limits, approval criteria and escalation procedures.
The issue also concerns how generative systems represent the brand externally. Generative Engine Optimization works on the quality, consistency and verifiability of the sources that feed the answers. The guide to Semantic Authority explores the shift from occasional citation to an established presence in the sector, while the article on Brand Governance and GEO shows how governed identity and AI citability reinforce each other.
Trends for 2026: where AI governance is heading
The gap is decided by orchestration
In its Global AI Pulse Q1 2026, KPMG identifies a group of organisations, around 11% of the sample, that is pulling ahead of the rest by integrating AI into how the business operates. The distinguishing factor is the orchestration of data, processes, responsibilities and skills, rather than the number of tools or budget growth alone.
Agentic AI increases the need for control
McKinsey finds that 62% of organisations are at least experimenting with AI agents. These systems can plan sequences of tasks, use tools and take actions with a growing degree of autonomy.
Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027 owing to rising costs, unclear value or inadequate risk controls. Authority, permissions, logging, operational limits, oversight and shutdown procedures therefore become part of the project from the outset. The Bliss guide on how AI agents work in marketing explores the architecture and the main use cases in depth.
Governance becomes a recognisable function
Gartner estimates spending of $492 million on AI Governance platforms in 2026, with the market set to exceed $1 billion by 2030. In parallel, IBM finds that 76% of the organisations surveyed have a Chief AI Officer in 2026, compared with 26% the previous year. Titles and platforms vary from company to company; the common trend is the explicit assignment of authority, budget and accountability.
Building a system that creates value over time
AI changes every quarter (if not sooner) and requires an ongoing governance system. Organisations that achieve stable value can therefore answer three questions: how much are we spending? What does that spend deliver? And who is responsible for each decision?
When an answer remains vague, visibility, criteria and ownership need to be rebuilt. Bliss combines AI Governance and Brand Governance in a programme that connects investment, risk, compliance, identity and measurement Discover the AI Governance service to find out more.
New Connections (FAQ)
What is AI Governance and why is it needed?
AI Governance is the system through which an organisation defines rules, responsibilities, controls and measurement criteria for the use of artificial intelligence. It links technology adoption to business objectives, available data, risks and compliance. The Bliss AI Governance page describes the full advisory programme.
How is AI ROI calculated?
The calculation starts from the process baseline and considers net economic benefits and total costs. Benefits may come from hours freed up, fewer errors, shorter lead times, increased revenue or improved retention. Costs include technology, integration, training, security, maintenance and oversight. ROI is measured for each individual use case and then aggregated at portfolio level.
What does the AI Act require of Italian companies?
The AI Act imposes different obligations depending on the organisation’s role, the type of system and the risk of the use case. From 2 August 2026 the transparency rules apply and enforcement of the applicable provisions begins. The updated timetable is available in the official AI Act Service Desk timeline. Effective governance builds inventory, classification, documentation, accountability, oversight and traceability; legal assessment remains necessary for specific cases.
Do SMEs need AI Governance too?
Yes, with a level of complexity proportionate to the organisation and its use cases. An SME can adopt an essential system made up of a tool inventory, data rules, approval of new use cases, named responsibilities and measurement of results. How simple the model is depends on scale; visibility and accountability remain essential.
Who should be responsible for AI Governance?
Accountability requires a sponsor with decision-making authority and an operational owner. In more structured organisations the role may be assigned to a Chief AI Officer or to a cross-functional committee involving business, IT, data, legal, security, HR and communications. The decisive criterion is the ability to approve investment, assign responsibilities and stop a project when it exceeds risk thresholds or fails to produce value.
Does governance slow down innovation?
A well-designed system shortens decision times because it makes criteria, responsibilities and required documents known. Low-risk cases can follow fast-track routes, while those involving sensitive data, impacts on people or operational autonomy receive deeper scrutiny. Speed comes from clarity of process.
Sources and further reading
KPMG, Global AI Pulse Q1 2026. Strategy, ROI and average investment.
Gartner, Lack of AI-Ready Data Puts AI Projects at Risk. AI projects and data quality.
McKinsey, The economic potential of generative AI. Automation potential of work activities.
European Union, AI Act implementation timeline. Up-to-date application timetable.
European Union, AI Act Article 99. Penalties regime.
IBM, Cost of a Data Breach Report 2025. Governance, shadow AI and controls.
Gartner, Agentic AI projects forecast. Economic and operational risks of agentic projects.
IBM, CEOs are reshaping C-suite roles for the AI era. The spread of the Chief AI Officer role.

