One Founder's Prediction Becomes Fact
In May 2026, Patrick Ryan, founder of Mobius Consulting, stood before a closed room of more than thirty senior C-suite executives, technology directors, and risk officers in London. When he asked how many of their organizations were actively running corporate AI tools in production, almost every hand in the room shot up. But when the conversation turned to foundational controls, the room fell quiet.
Only 31 percent of those senior leaders had a formal AI strategy in place. Official policy sat at a meager 28.9 percent, while data governance lagged at 28.6 percent.
"I do not want to say we are getting ahead of ourselves," Ryan said. "The ship has sailed, and we are where we are. All we can do now is ask ‘what is the next best thing we can do?’."
Enterprise leaders had effectively jumped into generative AI feet first, driven by board-level FOMO and competitive panic, leaving their security and governance teams scrambling behind them.
The Multi-Million-Dollar Bill Arrives
Fast forward to late July 2026, and the bill for that headlong rush arrived in full. According to IBM's 2026 Cost of a Data Breach Report, the global average cost of a corporate data breach spiked 12 percent to a record $4.99 million, driven largely by unmonitored artificial intelligence infrastructure.
IBM found that 68 percent of breached organizations possessed no formal AI governance policy whatsoever. Incidents involving shadow AI more than doubled year over year, while an eye-watering 92 percent of AI-related breaches occurred at companies with zero access controls placed on their models.
Then came August 2, 2026, when the EU AI Act officially triggered its binding obligations under Article 50. Overnight, transparency rules, mandatory audit logging, strict model access controls, and demonstrable workforce AI literacy transformed from optional corporate social responsibility topics into hard legal mandates backed by severe financial penalties.
What Ryan’s roundtable captured in May was the reality baseline of an industry running on blind optimism. The IBM breach statistics published in July delivered the economic consequence, and the EU AI Act in August established the legal deadline.
Why Cars Have Brakes
During the May session, Patrick introduced an analogy that perfectly encapsulates where enterprise leadership went wrong.
He asked the room why we put brakes on a car, noting that the usual response is simply to be able to stop. "If we didn't have brakes on a car, we would all be driving around at two miles an hour and then bumping into a tree to slowly stop," Ryan said. "So the brakes on the car can actually help us go faster. We trust the brakes, and that is why we drive down the freeway at 60 miles an hour, because we know if we need to stop, we can stop, and we are going to be safe."
He urged the executives to apply that exact same logic to technology governance.
Controls are not built to halt innovation or park the business, but to give leadership the trust and confidence required to scale AI rapidly without careening off a cliff. The governance deficit revealed in May demonstrated that most enterprise deployments were running at full throttle without any brakes at all. Employees were uploading sensitive financial models, customer records, and proprietary source code into external large language models without realizing that once data leaves the building, pulling it back is virtually impossible.
Reframing the Executive AI Question
Patrick urged executives to fundamentally reframe their primary line of inquiry as systems gain autonomous capabilities.
"I think executives need to shift from a mindset of what can AI do for us to under what conditions can this become unsafe," Ryan said. "The train has left the station and there is no stopping it. AI can do everything you want it to do, so looking at the same problem from the other end, under what conditions will this become unsafe, I think that mindset shift is important."
"How do we stay relevant as humans?," Ryan asked the room while addressing assurance and controls. "How do we provide direction, and how do we make sure that what agents and models are doing is what we intended? Once it is gone, it is so difficult to pull back."
This distinction between reversible and irreversible actions is where modern risk management must draw the line. Internal summarization tools, creative brainstorming sessions, and sandboxed code helpers carry low stakes and high reversibility, making them ideal for rapid, AI-first experimentation.
Conversely, customer-facing workflows, medical processing, automated credit scoring, and live financial transactions are entirely irreversible. For these high-stakes deployments, process-first controls and strict human-in-the-loop oversight are non-negotiable.
Building Sustainable AI Governance
Organizations must also confront the hidden economics of ungoverned AI. While initial model API calls seemed cheap, runaway token budgets, model drift, and unmonitored agentic loops are creating unexpected financial drains that frequently exceed human developer costs. When paired with the multi-million-dollar average cost of an AI-fueled data breach, the illusion of frictionless, cheap AI vanishes entirely.
To navigate this landscape, enterprises are beginning to align their operations with international frameworks like ISO 42001 for AI management systems. They are categorizing systems into clear risk tiers, establishing technical mediation layers to redact sensitive prompts, and distributing accountability across executive, legal, IT, and business units rather than dumping the entire burden onto an isolated Chief AI Officer.
As Ryan noted during his presentation, ethical foresight will ultimately define long-term commercial success.
"The winners out of this AI wave are going to be the companies that apply good ethics in their AI journeys and actually have almost a moral footprint in terms of where they are going," Ryan said.
The era of ungoverned, wild-west AI experimentation officially expired this month. Organizations that treat governance as the steering wheel and braking system of their AI strategy will move faster and smarter than their competitors, while those still driving without controls will find that the next turn carries a $5 million price tag.
This article originally appeared on Dataconomy and is reproduced with permission.