Editor’s note: The following is a guest post by Michael Meehan, global VP of partners and alliances at Exterro, a data security software vendor.
I've had some version of the same conversation with a dozen different partners over the last few months. A customer got excited about AI, moved fast and is now quietly asking whether anyone actually knows what it's doing inside their environment. Usually the answer is no, and usually nobody wants to say that out loud in a steering committee meeting.
The disconnect between AI deployment and governance isn’t something enterprises will grow out of on their own. It's shaping up to be the defining risk of the current AI cycle and might be the best services opportunity for the channel in a decade.
For a while, this AI control gap was mostly anecdotal — something partners and IT leaders mentioned in passing, usually with a shrug. Now there's data behind it. IBM recently surveyed 2,000 CIOs and CTOs and found that 70% believe AI is being deployed faster than their teams can track it, and 77% say adoption is already outpacing their governance capacity. Leaders in most enterprise IT organizations admit they've lost track of their own AI footprint.
Cisco's 2025 AI Readiness Index adds another relevant data point from a survey of more than 8,000 senior business leaders. Only 13% of organizations qualified as AI "pacesetters," the small group with the infrastructure, skills, and governance maturity to actually scale AI responsibly. Governance wasn't a footnote in that research. It was one of the core pillars Cisco used to assess AI readiness.
The two studies seem to suggest that the constraint on enterprise AI right now isn't model quality, compute or even budget. It's control. Nobody's struggling to find AI tools to deploy. They're struggling to know what they've already deployed.
How we got here
None of this necessarily happened because organizations were being reckless. It was the predictable outcome from individual teams solving individual problems faster than governance could keep up.
A marketing team starts using a generative AI tool for content drafts. A finance analyst pastes numbers into a chatbot to save time. An engineer starts using an AI coding assistant that nobody in security has vetted. None of these people think they're doing anything wrong, and in isolation, maybe they aren't. But multiply that across a few thousand employees and a dozen departments, and you end up with an AI footprint that nobody in IT, legal or compliance could accurately describe if you asked them.
Some customers describe this as "AI fatigue," which may be the right term. In general, people aren’t against AI, but a gap exists between the top-down pressure to adopt it quickly and the reality on the ground. Approval cycles take three to six months in regulated industries. Existing governance frameworks often predate generative AI. And employees are being told to move fast with tools nobody's fully explained to them. Poor alignment pushes a big chunk of AI use into the shadows, where nobody's watching.
That approach is getting expensive. EY's 2025 responsible AI research found that 99% of the organizations it surveyed had already experienced financial losses tied to AI-related risk, 64% of them over a million dollars, with an average loss north of $4 million. The professional services firm surveyed nearly 1,000 C-suite leaders in June of last year.
Courts are starting to treat AI prompts and outputs as discoverable evidence in litigation, which means the informal, ungoverned way most employees are using AI today is creating a legal record nobody's managing. Add regulatory frameworks like the EU AI Act, and the risks are no longer hypothetical.
The channel's role
Enterprises know AI governance is a problem, but most don't have the internal expertise or bandwidth to fix it on their own. That's where the channel comes in.
For most of the last two decades, partners made their money selling and managing infrastructure — servers, cloud, storage, licensing. That business isn't going away, but it is evolving. Customers aren't short on AI tools, but they lack someone who can walk into the room and answer the harder questions: What data is this actually touching? Who's accountable if it gets something wrong? If a regulator or opposing counsel comes asking, can we prove what happened?
Partners who can answer those questions stop looking like vendors and start looking like the people a customer calls before the next rollout, instead of after something's gone wrong.
It doesn't require a new business model. But it does mean expanding a conversation most partners are already having.
Start with an honest inventory. Most organizations have never mapped where AI is running across their environment against their existing data classification standards. That's an assessment practice, and it's usually the easiest door in. Customers are far more willing to pay for a diagnostic than a solution they don't yet understand they need.
Policy work is a natural next step. Telling employees to use AI responsibly isn't policy. Partners can help build something with teeth: specific approved platforms, clear rules about what data can and can't go into a prompt, defined escalation paths when something goes wrong. Then, help enforce it, which is something customers struggle with on their own.
There's also a growing need around investigation readiness. Organizations need to reconstruct what an AI tool did, when, and why, with a human able to explain and defend the outcome after the fact. This is a fairly short walk for partners working adjacent to security and compliance.
Governance has to be ongoing. It requires periodic reviews, human-in-the-loop checks and a shared resource that gives legal, compliance and IT a common view. That's where the AI business model lives. Unlike deployment, which is a one-time project, governance is ongoing. AI keeps evolving faster than the policies around it, so the need for oversight keeps renewing itself.
The first mover advantage
It’s not quite a land grab yet, but it's close. Most enterprises don't currently have a go-to partner for AI governance. Whoever earns the trust to to fill the control gap will become the advisor customers keep coming back to.
Waiting for governance frameworks to standardize, or for customers to explicitly ask for this, is the wrong play. The IBM and Cisco numbers aren't forecasting a future risk. They describe where most enterprises are today.
You don't need to become a compliance shop overnight. Assessment and policy work builds directly on skills most partners already have in security and data management. You can shift those capabilities to AI work, and you probably have a few accounts where a CIO, a GC, or someone in compliance has raised AI risk in passing without quite knowing what to do about it. Those deals are easier to close because the customer already knows they have a problem.
Boards and executives have stopped being impressed by AI activity for its own sake. They want to know it's generating value without quietly creating risk they'll have to answer for later.
The enterprises that scale AI successfully won't necessarily be the ones running the most advanced models. They'll be the ones who can explain to a board, a regulator, or their own leadership what their AI is doing and why they can stand behind it. That kind of capability doesn't ship with any platform. Somebody has to build it, and increasingly, that somebody will be a partner.
The control gap IBM and Cisco are describing isn't a passing side effect of fast adoption; it's the shape of the next decade of this market, forming right now while most of the industry is still focused on deployment speed. The partners who recognize that early and start building governance into their service stack before it becomes table stakes will do more than add a new revenue line. They'll change the nature of the relationship they have with their customers, from vendor to advisor, in a way that's very hard for anyone else to undo once it's set.
That's the opportunity sitting in front of the channel right now. The next question is: Who moves on it first?