Observed Signal · May 4, 2026 · Policy Update · Source: AdExchanger · Impact: 3/5 · Sentiment: Neutral

Who Owns AI Governance?

Executive Signal Summary

AdExchanger published an interview (May 4, 2026) with Ashley Casovan, managing director of the IAPP AI Governance Center, exploring how organizations assign responsibility for AI governance. IAPP survey data show many companies lack resources for governance (48%) and that 67% report the privacy function as the primary owner of AI governance. Casovan describes wide variance in organizational models — from privacy teams absorbing AI governance to dedicated AI governance roles — and stresses that work spans policy, technical evaluations (bias, security), ethics, assurance and compliance (including using frameworks like NIST’s AI Risk Management Framework). The interview highlights California’s automated decision‑making rules as influential for U.S. policy, urges organizations to inventory AI use, define standards and oversight, and frames the moment as an opportunity for privacy, cybersecurity and data-governance professionals to shape practical implementation.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Clarifies who within organizations is being tasked with AI governance, highlights resource gaps and regulatory pressure (e.g., California automated decision‑making), and signals operational and compliance implications for privacy, security and data teams across the ad ecosystem.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • IAPP research: 48% of companies say they lack sufficient budget and resources for governance professionals.
  • IAPP research: 67% of companies say primary responsibility for AI governance rests with the privacy function.
  • Ashley Casovan, managing director of the IAPP AI Governance Center, was interviewed by AdExchanger about how AI governance is being structured.
  • AI governance work includes policy translation, governance committees, technical evaluations (bias and cybersecurity), ethics and assurance.
  • The NIST AI Risk Management Framework and California automated decision‑making rules were cited as important reference points for governance and regulation.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: AdExchanger•Published: May 4, 2026
Original Coverage Title: “Who Actually Owns AI Governance?”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

AI Governance / TransformationAug 18, 2026

AI Governance Is Becoming a Transformation Problem

The article argues that AI governance is no longer just a policy task but a transformation challenge: governance processes that are too slow drive employees to adopt unsanctioned 'shadow AI' workarounds, while insufficient controls leave organizations exposed when AI systems take actions (agentic systems). The author distinguishes passive LLM outputs from agentic systems that can act across systems, calls for consequence-driven processes (high/medium/low), faster review SLAs, automated controls for low-risk work, and clarity on decision rights. The piece references regulatory frameworks (NIST, EU AI Act) and real-world incidents (Samsung/ChatGPT) to illustrate why governance must be redesigned as part of organizational decision-making rather than only as policy language.

Read assessment
Large Language Models & AIApr 3, 2026

AI governance gaps threaten brand, privacy, quality

The article argues that AI governance is an immediate operational risk rather than a future concern, urging leaders to assume AI is already used across their organizations. It recommends surveying teams to identify which LLMs and specialized AI tools (e.g., AI agents) are in use, then implementing an evolving governance policy that lists approved and prohibited tools, data-handling guardrails, QA processes for AI-generated content, and regular reviews. The piece highlights specific risks — privacy leaks from LLM training, security vulnerabilities, legal exposure from third-party terms, and retained chat histories — and calls for clear, practical guidance (examples: anonymization requirements, prohibited prompt data categories, sign-off authority) especially for regulated industries. The article emphasizes governance should be iterative, include employee feedback, and be revisited regularly.

Read assessment
AI Governance in AdvertisingJun 2, 2026

Digital Advertising Needs AI Guardrails

An AdExchanger opinion piece argues the biggest AI risk in digital advertising is autonomous decision-making without clear ownership, governance or accountability. The author warns that AI can reduce operational friction while increasing systemic, high-impact failures when autonomous systems make pricing, targeting, optimization or creative decisions at machine speed. Citing examples from other industries — Air Canada’s chatbot liability, Zillow’s iBuying losses, and Microsoft’s Tay chatbot — the article outlines a plausible algorithmic pricing-collusion risk and other failure modes (illegal creative, privacy violations, autonomous contracting). It recommends a formal control layer with three core components: configuration authority (clear human ownership), predefined acceptable risk thresholds, and reversibility/auditability (logs, rollback). The piece calls for two operational tracks — bounded experimentation and gated production — and emphasizes retaining experienced human operators to govern AI systems.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.