---
title: "Data Governance vs AI Governance: Why It's the Wrong Battle"
url: "https://atlan.com/context-and-chaos/issue/data-governance-vs-ai-governance-why-its-the-wrong-battle/"
description: "The risk surface has expanded. The answer is one control plane, not another silo."
keywords: "Data Governance, AI Governance, Enterprise AI, Risk Management"
---

> Atlan is hosting Context Conference, bringing together the leaders and builders at the frontier of giving AI the context it needs to understand their business. It runs online on October 28, 2026, from 11:00 AM to 2:00 PM ET. Atlan co-founder Prukalpa Sankar opens and closes the day. Leaders from AstraZeneca, BNY and Verizon share why they invest in context and what they get from it. Registrants get early access to The AI Context Gap, a new study from MIT Technology Review Insights. Register: https://atlan.com/context-conference/

A Context & Chaos deep dive (Atlan's practitioner newsletter) by Charlotte Ledoux and Vivek Dubey, published March 12, 2026 (14 min read). It argues that "data governance vs AI governance" is a false battle: the foundations are the same, the risk surface has expanded into models and autonomous agents, and the answer is one active governance control plane, not another silo.

**Authors.** [Charlotte Ledoux](https://www.linkedin.com/in/charlotteledoux/), data and AI governance strategist (the practitioner voice: trust inside organizations, where AI breaks existing governance, what boards ask). [Vivek Dubey](https://www.linkedin.com/in/vivekdubey15/), data and AI advocate at Metadata Weekly, works on product, growth, and community at Atlan (the structural argument: why fragmented governance stacks compound risk). Charlotte writes the newsletter [Data Governance Playbook](https://thedatagovernanceplaybook.substack.com/).

## The trap: why organizations are fighting the wrong battle

- Data, AI, and information governance are built in separate rooms with separate frameworks, committees, and languages. Boards cannot tell which one owns risk.
- CXO research places AI governance among the top emerging board-level priorities. Boards are signing off on agents that trigger real-world outcomes autonomously and want visibility, control, and accountability.
- Forrester projects AI governance software will reach $15.8 billion by 2030, 7 percent of total AI software spending.
- Standing up AI governance as a separate track deepens the split. The sustainable response is to extend and converge existing governance into one active control plane governing how information and intelligence are used end to end.

## Governance is a trust engine, not a paperwork function

Governance usually shows up as a 40-page policy deck nobody reads, a quarterly steering committee approving what already happened, and a painful access request process, so people build workarounds. Boards and regulators do not ask whether a framework exists; they ask whether they can trust the information behind a decision and show how it was made and what constraints applied.

"Data Governance is not a library of rules. It's an operating system for trust." In the authors' house analogy, the policy deck is the rules taped to the fridge; the operating system is the plumbing alerts and the door locks.

## The trust foundation you already have

Existing data governance has already built trust infrastructure:

- Data quality: the numbers people see are correct.
- Privacy: controlling who sees what, and proving it to regulators.
- Lineage: where data came from and how it was transformed.
- Access control: only the right people reach sensitive data.

That foundation assumed a human at the end of the chain applying judgment. When an agent executes (places the order, sends the email, triggers the workflow), ungoverned trust becomes a trust crisis.

## What AI changes: new risk surfaces, very little time

- Mayfield's 2026 CXO Network Survey of 266 Fortune 50 to Global 2000 technology leaders: 42% already have AI agents in production; 72% are in production or actively piloting.
- Gartner predicts that by 2027 half of all business decisions will be augmented or automated by AI agents.

**Worked example: a mid-sized European retailer** with strong data governance (tracked quality scores, enforced privacy, tight access, documented lineage) deploys an AI agent for dynamic e-commerce pricing on clean, governed data. But:

- A vendor fine-tuned the pricing model on a training set including US market data; the retailer sells in the EU. Nobody reviewed the training data, and the model is biased toward aggressive discounting that does not match its margin strategy.
- The agent's RAG pulls "pricing guidelines" from the internal wiki and also grabs an unapproved draft Black Friday scenario, which it treats as policy.
- The agent runs human-on-the-loop with a daily analyst review, but makes 400 price adjustments on a Sunday night; the analyst checks Monday at 10am.

Result: 400 products repriced by a biased model on unapproved guidelines with no human review, customer complaints, a six-figure margin impact, and questions from compliance and the board. Every data quality check passed. What was ungoverned: the model supply chain, the context assembly, and the agent's action surface. "The shift from 'AI that informs' to 'AI that acts' is the single biggest governance challenge most organizations aren't ready for."

## AI governance is data governance

The risks are new but the disciplines are not: is the data accurate enough for the decision, do we have the right to use it this way, what happens downstream if it is wrong. AI governance extends these questions into models, prompts, and automated decisions. The page's mapping table shows each row as the same governance discipline pointed at a wider surface; data governance teams already cover the data side and need to be invited into the AI loop.

- Gartner recommends mapping AI governance into the same foundational pillars used for data and analytics governance, to avoid duplication and gaps.
- JPMorgan Chase's Naren Chittar ([via Mayfield](https://www.mayfield.com/the-agentic-enterprise-in-2026/)): "Governance must exist in every layer of the stack, from models and data to applications and interfaces, while enabling safe self-serve environments where employees can build and deploy their own agents."
- Most AI governance failures are old governance failures that AI made visible. Weak data governance means ungovernable AI; data governance that ignores model and agent consumption will be obsolete quickly.

## The anti-pattern: fragmented stacks, compounding risk

Data governance runs in one stack (catalog, glossary, lineage, access policies), AI governance in another (model registry, risk committee, red-teaming guidelines), security on the side, information governance with legal. Fragmentation produces four problems:

- **Inconsistent definitions.** "High risk customer" means different things in the warehouse, the CRM, and the AI risk register.
- **Policy gaps.** Warehouse masking rules may not apply in a retrieval pipeline or chatbot.
- **Broken explainability.** No clean end-to-end story after an incident; worst with agents that pull governed data, reason through an ungoverned model, and act in a third system.
- **Slow scaling.** Every new AI use case triggers fresh negotiation between data, AI, security, and compliance teams.

Governance exists in every lane but connects across none of them.

## One governance control plane, built on context

A unified governance control plane is a horizontal layer that understands data, information, and AI assets, knows how they relate, encodes policy once, and enforces it everywhere work happens. It maintains a living graph of context (relationships between assets, policies, owners, and the decisions they feed), not a static catalog.

- New models or agents are discovered and linked into lineage automatically.
- A tightened policy updates controls across the warehouse, the AI application, and the agent layer.
- A steward's metric definition change propagates to every experience exposing it.
- Data governance teams own AI-ready data practices: labeling, lineage, observability, quality baselines. AI governance teams plug into the same foundation for model-specific controls: validation, bias mitigation, lifecycle gates.
- Each governed AI use case becomes a reusable context product; patterns from the first agent are reused for the next hundred.

Layering catalogs, policy engines, and model registries on disconnected systems compounds governance debt; building on shared context scales.

## Questions leaders should be asking

- **Ownership.** Who is accountable for AI governance, and how does it connect to data governance and security?
- **Decision risk.** For the highest-stake decisions, can we name the data and models involved and reconstruct the decision? Who is responsible for model results and impacts?
- **AI security.** Where do models and agents touch sensitive data? How is shadow AI detected and controlled? Are we protected against prompt injection?
- **Architecture.** Are we converging on one control plane or adding parallel stacks? How many systems must be hand-updated when a policy changes?

## Closing: convergence or confusion

At the Gartner D&A Summit 2026, a unified "Data and AI Governance" track sat alongside a dedicated AI track with sessions on governing agents; the opening keynote framed the challenge as navigating AI on the data and analytics journey to value; CXO surveys showed boards prioritizing AI governance while production outpaced frameworks. Organizations that converge now (one set of principles, one shared understanding of risk, one control plane spanning data, models, and decisions) move faster; those that fragment will spend the next 18 months reconciling policies and audit trails. "The question was never data governance versus AI governance. It was always whether you are building one thing or three."

## References

Mayfield, The Agentic Enterprise in 2026; Forrester, AI Governance Market Forecast; Forrester, Enterprise AI Governance Survey; Gartner, D&A Governance Framework; Gartner, Data and Analytics Summit 2026 session agenda; NIST AI Risk Management Framework; NIST AI 100-1; EU AI Act; OECD AI Principles. Forrester links: [blog](https://www.forrester.com/blogs/ai-governance-software-spend-will-see-30-cagr-from-2024-to-2030/), [report](https://www.forrester.com/report/global-commercial-ai-software-governance-market-forecast-2024-to-2030/RES181688).

## The Insight Index (recommended reads)

- [Your Data Agents Need Context](https://www.a16z.news/p/your-data-agents-need-context) (Jason Cui and Jennifer Li)
- [From Words to Wisdom: How to Structure Knowledge for AI](https://www.linkedin.com/pulse/from-words-wisdom-how-structure-knowledge-ai-bruno-fievet-kpf1e) (Bruno Fievet)
- [Managing Enterprise Context in the AI Era; A Practitioner's Perspective](https://www.linkedin.com/pulse/managing-enterprise-context-ai-era-practitioners-karthik-ravindran-9rtec) (Karthik Ravindran)
- [Unified Context-Intent Embeddings for Scalable Text-to-SQL](https://medium.com/pinterest-engineering/unified-context-intent-embeddings-for-scalable-text-to-sql-793635e60aac) (Keqiang Li, Bin Yang)
- [Analytics Engineering's Unfinished Work](https://loglevelinfo.substack.com/p/analytics-engineerings-unfinished) (Tim Castillo)
- [OpenAI's Frontier Proves Context Matters. But It Won't Solve It.](https://www.linkedin.com/pulse/openais-frontier-proves-context-matters-wont-solve-prukalpa--guorf) (Prukalpa)

Originally published in the [Context & Chaos newsletter on Substack](https://metadataweekly.substack.com/p/data-governance-vs-ai-governance). Related reads: [BI-Ready Is Not AI-Ready](https://atlan.com/context-and-chaos/issue/bi-ready-is-not-ai-ready/), [Semantic Layers Failed. Context Graphs Are Next.](https://atlan.com/context-and-chaos/issue/semantic-layers-failed-context-graphs-are-next/), [Context Graphs as AI Evaluation Infrastructure](https://atlan.com/context-and-chaos/issue/context-graphs-as-ai-evaluation-infrastructure/). All issues: [https://atlan.com/context-and-chaos/](https://atlan.com/context-and-chaos/).