Key takeaways
- The Digital Omnibus deferred the EU AI Act’s standalone high-risk obligations to 2 December 2027, but AI literacy, prohibited practices, transparency and general-purpose AI duties are already enforceable.
- Most AI governance challenges are organisational rather than technical: unassigned ownership, an incomplete inventory, and evidence nobody can produce on demand.
- 78 percent of business leaders lack confidence they could pass an independent AI governance audit within 90 days.
- Accountability collapses because duties split across model provider, system provider and deployer, and few organisations record who holds which.
- Every one of the seven AI governance challenges below resolves to a named obligation, one control, and one artefact an auditor will ask to see.

What changed in 2026: the deadline moved, the duties did not
The most consequential of the current AI governance challenges is a calendar problem that most published advice has not caught up with. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, nine days before the original high-risk deadline. The European Parliament endorsed it on 16 June 2026 by 423 votes to 57 with 174 abstentions, and the Council gave final approval on 29 June 2026. What moved: obligations for standalone high-risk systems under Annex III now apply from 2 December 2027, and AI embedded in regulated products under Annex I from 2 August 2028. What did not move: the prohibitions on unacceptable AI practices, applicable since 2 February 2025. The AI literacy duty in Article 4, applicable from the same date. The general-purpose AI obligations in Chapter V, applicable since 2 August 2025. The transparency duties in Article 50. That asymmetry is the first trap. A 16-month deferral reads, inside a budget meeting, as permission to stand a programme down. It is not. The duties that bite today are the ones that need an operating model rather than a product change, and they are the ones most organisations have not started. The EU AI Act operator’s guide sets out the full obligation map by role and date.
Challenge 1: nobody owns AI governance
Ask who is accountable and you will usually get a committee, not a name. This is the first of the AI governance challenges because every other control depends on it. The 2026 Grant Thornton AI Impact Survey of 950 business leaders found that only 48 percent of boards have set AI governance expectations and 46 percent have integrated AI risk into ongoing oversight, while 73 percent of executives identify governance as the area needing most focus. The Kiteworks 2026 Annual Survey of 459 security, compliance and technology professionals puts it more bluntly: 39 percent treat AI governance as an add-on responsibility rather than a dedicated role. A committee cannot be held accountable. It can only be convened. When an incident lands, the regulator asks who authorised the deployment, and a steering group charter is not an answer. The control: one named accountable owner per AI system, a decision forum with documented authority to stop or suspend a deployment, and a RACI that survives a personnel change. The owner does not need to be technical. They need the authority to say no and the budget to act on it. This is the load-bearing element of any AI governance operating model, and it is the cheapest of the seven fixes. The artefact: a signed authorisation record per system, naming the accountable owner and the date the deployment was approved.
Challenge 2: you cannot inventory what you cannot see
Every obligation in the EU AI Act attaches to a system. If you cannot list your systems, no other control can be applied, because there is nothing to apply it to. That dependency puts inventory near the root of most AI governance challenges. The scale of the gap is now measured. Kiteworks found that 65 percent of organisations discovered shadow AI usage in the past year. A Gartner survey of 302 cybersecurity leaders conducted between March and May 2025 found 69 percent either suspect or have direct evidence that employees are using prohibited public generative AI tools. Almost none of those tools passed a governance review. The difficulty is structural. AI arrives embedded in tools you already bought, through third-party APIs, and through individual purchases that never cross a procurement desk. Agentic systems make it worse, because an agent that calls other models and acts across systems has no single point of registration. Our guide to shadow AI covers the discovery techniques in detail. The control: continuous discovery paired with a registry keyed to use case, business owner, regulatory role, risk classification and lifecycle stage. Procurement and expense data are better first sources than a network scan, because most shadow AI is bought, not installed. The artefact: a dated inventory export you can hand over unedited.
Challenge 3: accountability splits across the value chain
This is the mechanism behind Challenge 1, and among the AI governance challenges it is the one almost no published guidance addresses. Obligations do not sit with a single company. They distribute across the general-purpose model provider, the system provider who builds on that model, and the deployer who runs it in a specific context. The Future Society calls this the many hands problem: accountability is obscured precisely because the three actors differ in resources, expertise and context-specific information, and no single one of them holds enough of any to discharge the duty alone. The Regulation is explicit about who is who. Article 3(4) defines a deployer as a natural or legal person using an AI system under its authority, other than for a personal non-professional activity. Article 2(1)(a) reaches providers placing systems on the Union market irrespective of where they are established, and Article 2(1)(b) reaches deployers established or located in the Union. Article 25 then flips a deployer into a provider if it puts its own name or trademark on a high-risk system, or substantially modifies it. That last point is where organisations get caught. Fine-tuning a model, changing its intended purpose, or wrapping it in your own brand can convert you from deployer to provider, and the provider obligation set is far heavier. Teams building on general-purpose AI models frequently cross that line without recording that they have. The control: a written role determination per system, re-run on every material change, with the upstream allocation of duties written into the contract rather than assumed. The artefact: the role determination record, with the reasoning and the date.
Challenge 4: human oversight is designed, not declared
Most AI governance programmes claim a human in the loop. Few can describe what that person is able to do, which makes oversight one of the AI governance challenges that only surfaces during an audit. The Regulation does not accept the claim at face value. Article 14(1) requires that high-risk AI systems “shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use”. The operative word is effectively. Article 14(3) then splits the duty: oversight measures are either built into the system by the provider before it is placed on the market, or identified by the provider and implemented by the deployer. Programmes routinely assume the first branch and never execute the second. The provider ships an override button, the deployer never assigns anyone the authority to press it, and the oversight exists only on the architecture diagram. The distinction between human-in-the-loop and human-on-the-loop matters here, because the two carry different competence and staffing implications. The control: an oversight design record naming the individual role, the competence required, the authority to override or halt, the latency within which they must be able to act, and the log that captures each intervention. The artefact: intervention logs showing that the override was used at least once, or a documented explanation of why it never needed to be.
Challenge 5: AI literacy is already an obligation
Of all the AI governance challenges, this is the one most often filed under “next year”. It is not. Article 4 has applied since 2 February 2025 and the Digital Omnibus did not touch it. The text is short and the scope is wide. Providers and deployers “shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”, taking account of their technical knowledge, experience, education and training, the context of use, and the people the systems are used on. Article 3(56) defines AI literacy as the skills, knowledge and understanding that allow informed deployment and awareness of opportunities, risks and possible harm. Note what the obligation does not say. It does not apply only to high-risk systems, and it does not apply only to technical staff. It reaches anyone operating or using AI on your behalf, including contractors. The funding does not match. Grant Thornton found that 34 percent of finance leaders say training receives insufficient funding, and that frontline employees (37 percent) and middle managers (30 percent) are the groups needing most support, which is exactly the population the Article covers. The control: role-based training mapped to the systems each role actually touches, refreshed when the system changes rather than annually. The artefact: attendance and comprehension records tied to named individuals and named systems.
Challenge 6: the evidence is not retrievable
An organisation can hold every control and still fail an audit, because holding a control and proving it are different activities. Evidence retrieval is the least discussed of the seven AI governance challenges and the most likely to be tested first. The 2026 numbers are stark. 78 percent of business leaders lack strong confidence they could pass an independent AI governance audit within 90 days. Half of the organisations Kiteworks surveyed cannot retrieve a complete AI access record within one business day of a request. Only 33 percent maintain tamper-evident audit trails, and 63 percent experienced compliance consequences tied to AI governance gaps within a 12-month window. There is a related pattern worth naming: 61 percent rank data sovereignty as their single biggest compliance challenge, yet only 29 percent enforce it with a technical mechanism. A stated policy with no enforcement point produces no evidence. Retrieval time is the metric that matters. Evidence that takes three weeks to assemble is, for the purposes of a supervisory request, evidence you do not have. Our guides to AI audit and AI system documentation cover what supervisory authorities actually ask for. The control: bind each piece of evidence to the specific control it proves at the moment it is generated, and snapshot system configuration immutably whenever a material parameter changes. Evidence collected retrospectively is weaker and slower. The artefact: a control-to-evidence register with a measured retrieval time.
Challenge 7: governance runs slower than adoption
The last of the seven AI governance challenges is the one that quietly causes the other six. When the governance path takes eight weeks and the business needs an answer in five days, teams route around it, and every routed-around deployment becomes tomorrow’s shadow AI. This is not a soft cost. Grant Thornton found that 46 percent of organisations cite governance and compliance failures as a leading cause of AI underperformance or outright failure, ahead of insufficient training at 31 percent and insufficient data readiness at 23 percent. Governance friction is the single largest named contributor to AI not working. The usual response, adding reviewers, makes it worse. The fix is proportionality. The control: a tiered intake where a documented low-risk use case clears in days against a short standard set, and only systems that trip a classification threshold enter full assessment. Pair it with a reusable control library so the tenth system inherits the work done on the first. Our AI risk management guide sets out how to calibrate the tiers. The artefact: intake-to-decision cycle time, tracked per tier and reported alongside compliance metrics.
Fixing the seven AI governance challenges in 90 days
Attempting all seven AI governance challenges at once is how programmes stall. The dependencies run in one direction. Days 1 to 30. See it. Build the inventory and complete role determinations for the systems already in production. Nothing downstream is possible without these two, and both are mostly desk research against procurement and expense data. Days 31 to 60. Own it. Assign a named accountable owner per system, stand up the decision forum with stop authority, and close the two obligations that are already live: AI literacy training for the roles that touch each system, and oversight design records for anything making or shaping a decision about a person. Days 61 to 90. Prove it. Map controls to evidence, measure retrieval time against a one-business-day target, and rehearse an audit on your three highest-exposure systems. Then set the intake tiers using what the rehearsal taught you about where the real friction is. Frameworks help at this point rather than at the start. ISO/IEC 42001 gives the management system shape and NIST AI RMF gives the risk vocabulary, but neither substitutes for knowing what you run and who owns it.
FAQ
What is one of the main challenges of AI in governance? Unassigned ownership sits at the root of most AI governance challenges. Most organisations have an AI steering committee but no named individual accountable for a given system, so no one holds the authority to stop a deployment. The 2026 Grant Thornton survey found only 48 percent of boards have set AI governance expectations. A committee can be convened but it cannot be held accountable, which is why ownership is the first fix in any sequence. Did the EU AI Act high-risk deadline actually move? Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and deferred standalone Annex III high-risk obligations to 2 December 2027, and Annex I embedded AI to 2 August 2028. Prohibited practices, AI literacy under Article 4, general-purpose AI duties and Article 50 transparency obligations were not deferred and are enforceable now. What are the six pillars of AI governance? There is no single canonical list, and treating one vendor’s six as authoritative is itself a governance risk. The recurring elements across ISO/IEC 42001, the NIST AI RMF and the EU AI Act are accountability, transparency, fairness, human oversight, security and lifecycle risk management. What matters is not the count but whether each element resolves to a control with an owner and an evidence trail. Who is responsible for AI governance, the provider or the deployer? Both, with different duties. The provider carries design-time obligations such as building in oversight capability and supplying instructions for use. The deployer carries operational duties. Article 25 flips a deployer into a provider if it rebrands a high-risk system or substantially modifies it, which fine-tuning can trigger. A written role determination per system is the only reliable way to know which set applies. How do you build an AI inventory when nobody declares their tools? Start with money rather than the network. Procurement records, expense claims and SaaS subscription data surface more shadow AI than a scan, because most of it is bought rather than installed. Combine that with identity and gateway logs, then make registration a condition of continued access. Kiteworks found 65 percent of organisations discovered shadow AI in the past year, so assume the gap exists rather than testing whether it does. Which AI governance challenges should you tackle first? Inventory and ownership, in that order, because the other five depend on them. You cannot assign an owner to a system you have not listed, you cannot determine a regulatory role without an owner to decide it, and you cannot produce evidence for a control that was never assigned. Bias, explainability and model performance matter, but they are downstream problems. Organisations that start there tend to produce excellent documentation for the small subset of systems they already knew about. Is AI literacy training really mandatory? Yes, under Article 4 of the EU AI Act, applicable since 2 February 2025. It applies to providers and deployers, is not limited to high-risk systems, and covers staff and anyone else operating AI on your behalf, contractors included. The measure is proportionate to role, technical knowledge and context of use, so a uniform annual e-learning module for all staff is unlikely to satisfy it.
Conclusion
The AI governance challenges that stall programmes in 2026 are not the ones the market talks about. They are not model accuracy or algorithmic bias in the abstract. They are an unowned decision, an unlisted system, an undocumented role, an oversight function nobody can exercise, a training duty already in force, evidence that takes three weeks to assemble, and a process slow enough that the business avoids it. Each of these AI governance challenges has a control, and each control has an artefact. The Digital Omnibus bought most organisations 16 months on high-risk obligations, and nothing at all on the duties that already apply. Treating that window as preparation time rather than a pause is the whole difference. Start with what you run and who owns it, then build the AI compliance evidence chain outward from there.