The New Reality of AI Risk & Governance
Summer is shaping up to be a critical period. Four things are converging: the EU AI Act takes effect on August 2nd with real penalties (up to €35M or 7% of global revenue), agentic AI is moving from pilot to production faster than our governance can keep up, data quality remains the biggest blocker to meaningful AI deployment, and ransomware is up 58% year-over-year.
The pattern is clear. Organizations that have invested in data quality and governance are getting real results from their AI initiatives. Those who haven’t are falling behind. At the same time, the threat landscape is shifting — ransomware gangs are using AI-powered tactics, and autonomous agents are creating an attack surface our current tools can’t see. The EU AI Act deadline is the immediate driver, but the underlying issues are structural.
EU AI Act: The Sprint
SANS Institute and Gartner confirm what legal has been telling us: the August 2 deadline is firm. To properly address it, an AI inventory is necessary. Convene a cross-functional task force – including legal, GRC, data engineering, and security. AI systems need to be classified by risk level before technical documentation can be produced.
Microsoft’s AI Compliance Tools and Responsible AI Toolbox could help here. It assesses compliance across multiple regulatory frameworks simultaneously, which matters since we’re dealing with both EU AI Act and US privacy requirements.
AI Agent Security: The Execution Layer Gap
80.9% of technical teams have deployed AI agents, but only about half have addressed the security exposure. The execution layer — tool invocations, API calls, autonomous actions — is running with minimal governance. Microsoft’s Agent Framework announcement and AGAT Software’s security analysis both confirm this is a real gap.
I’m evaluating Microsoft’s open-source Agent Governance Toolkit. It addresses all 10 OWASP Agentic AI risks with sub-0.1ms p99 governance latency. It needs to integrate with our EU AI Act documentation requirements. The dual purpose is important: security controls that also serve compliance.
Ransomware: The Numbers
BreachSense documented 772 ransomware victims across 70 groups in April alone. DeepStrike shows an average total breach cost of $5.0M per incident. The ransomware-as-a-service model is thriving, and the payment rate has dropped to 28% — victims are fighting back, but the cost per incident continues to rise. AI-assisted phishing is also becoming more effective, making traditional email filters less useful.
It’s time to focus on reviewing backup integrity, recovery procedures, and communication protocols. The NSA’s Zero Trust Guidelines provide the framework, but we need to operationalize it, starting with identity as our primary security boundary.
Data Quality: The Hidden Bottleneck
IBM and Gartner agree: data quality and fragmentation, not model capability, are the primary blockers to AI production deployment. Databricks specifically confirms this for agentic AI. This matters for EU AI Act compliance too — the regulation requires documented risk assessments that depend on clean, traceable data.
Data quality reviews will be critical. You’ll need to identify the top critical data pipelines and deploy AI-driven observability to detect, diagnose, and resolve anomalies in real-time. This serves dual purposes: improving AI readiness and supporting EU AI Act documentation.
Next on the lookout:
- EU AI Act implementation guidance from regulators and any enforcement actions
- New TTPs from AI-powered threat actors
- Vendor responses to OWASP Agentic AI risks
- Progress on multi-jurisdictional privacy law harmonization
- Early ISO 42001 certification cases as benchmarks
Don’t miss out on our latest news, tips and tricks by subscribing to our blog!
Ready to move fast into AI data governance? We’ll help you get your data AI-ready – quickly and effectively.
Discovered Intelligence Inc., 2026. Unauthorized use and/or duplication of this material without express and written permission from this site’s owner is strictly prohibited. Excerpts and links may be used, provided that full and clear credit is given to Discovered Intelligence, with appropriate and specific direction (i.e. a linked URL) to this original content.









