AI Governance Becomes a Competitive Test as Regulation Catches Up With Adoption
Companies are integrating artificial intelligence into core operations faster than their internal controls can evolve. André Rizzo argues that accountability, workflow redesign and effective governance—not access to technology alone—will determine which businesses turn AI into lasting value.

André Rizzo, McGill Executive Institute Faculty Member and Digital Transformation and Emerging Technologies Advisor, contributed to this story.
Artificial Intelligence (AI) is moving from isolated corporate experiments into procurement, recruitment, customer service, financial decisions and industrial operations. As adoption accelerates, however, many businesses still lack a complete picture of where the technology is being used, who is responsible for it and what authority has been delegated to automated systems.
That gap is becoming more consequential as the European Union’s AI Act moves further into its phased application. For companies, the impact extends well beyond legal departments: the rules can influence product development, cybersecurity, data governance, human resources, marketing, supplier relationships and investment decisions.
“Many companies are still underestimating the operational impact,” André Rizzo, an international specialist in AI governance, speaker and author, told EUBizNews. “The EU AI Act is often treated as a legal or compliance project: classify the system, document it, assess the risk and move on. But in practice, AI regulation reaches much further into the organisation.”
Rizzo, a faculty member at the McGill Executive Institute and co-founder of Canada’s AI Sovereignty and Innovation Cluster, maintains that artificial intelligence has become as much a management and strategic issue as a regulatory one.
Adoption Is Advancing Faster Than Corporate Visibility
The scale of the challenge is growing alongside AI adoption. Eurostat data show that 19.95% of EU enterprises used AI technologies in 2025, up from 8.1% in 2023. Among large companies, the proportion reached 55.03%.
Those figures indicate that regulation is taking effect while AI becomes embedded in mainstream business activity. Yet regulatory exposure varies considerably depending on how the technology is used.
AI employed by a bank to assess creditworthiness, by a hospital through medical software or by a company to screen job applicants can raise high-risk considerations and require stronger controls. A hotel producing marketing copy, a manufacturer summarising internal documents or a retailer operating a basic customer-service chatbot may face a different risk profile.
“The mistake is treating all of these as the same ‘AI compliance’ problem,” Rizzo said.
Before companies can classify risk, they must first identify the systems operating inside their organisations. That is increasingly difficult as employees adopt generative AI independently, business units purchase AI-enabled products and suppliers embed automated functions into existing software.
A 2026 EY survey of senior AI executives at large companies found that 41% lacked visibility over all the AI tools being used within their organisations.
“Ultimately, one cannot govern what the organisation does not know it is using,” Rizzo said.
The issue also extends beyond the EU. Companies based elsewhere can become subject to European requirements or customer expectations if they sell into the bloc, operate there, supply European businesses or participate in regional value chains.
For executives, the relevant question is therefore broader than formal compliance. Businesses must be able to explain where AI is being used, its purpose, the accountable decision-maker, the associated risks and the evidence available to demonstrate control.

Governance as Commercial Infrastructure
Regulation and innovation are frequently presented as opposing forces, but Rizzo sees governance as an enabler when it is designed to support decisions rather than merely block them.
“Poor governance creates bureaucracy. Good governance creates, above anything else, clarity,” he said. “It tells people what they can do, under what conditions, who can approve it and where the boundaries are.”
A functioning framework can accelerate adoption by preventing every team from having to design a new risk assessment each time it introduces an AI application. It can also help companies move pilot projects into production without losing control over data, cybersecurity or third-party technology.
Governance is becoming commercially relevant as well. When two suppliers offer similar AI capabilities, the company that can document the origin of its models and data, explain how it assesses risks and establish what happens when a system fails may have an advantage in procurement and partnership decisions.
The difference between written policies and operational control remains significant. According to the EY survey cited by Rizzo, 98% of the large companies surveyed had formal AI-governance policies, but 47% acknowledged previously bypassing those processes to accelerate an urgent deployment.
“Having governance and having governance that works operationally are two very different things,” he said. “The competitive advantage will not come from having the largest number of AI policies. It will come from being able to adopt AI faster, more consistently and with greater confidence than competitors.”
Europe and Latin America Face Different Starting Points
The European regulatory experience offers lessons for Latin America, but Rizzo cautions against replicating the bloc’s architecture without accounting for regional economic and institutional differences.
Risk-based governance, transparency, accountability, protection of fundamental rights and clearly assigned responsibilities can help Latin American companies manage domestic risks and strengthen their access to European customers and supply chains.
However, regulatory obligations designed for large European financial or technology groups could impose disproportionate costs on smaller companies operating with less capital, weaker digital infrastructure and limited access to specialised compliance teams.
The 2025 Latin American Artificial Intelligence Index from the UN Economic Commission for Latin America and the Caribbean found that the region generated approximately 14% of global visits to AI solutions despite accounting for about 11% of global internet users. It nevertheless received only around 1.1% of global AI investment, compared with its roughly 6.6% share of world GDP.
The region is therefore showing strong demand for AI without attracting a corresponding proportion of investment. Its adoption pattern is also heavily concentrated in generative applications, which accounted for approximately 78% of regional traffic to AI tools. More advanced activity involving development platforms, models and application programming interfaces remained below the global average.
“The challenge for Latin America is to build safeguards without importing regulatory complexity that unintentionally raises barriers to innovation, particularly for SMEs,” Rizzo said.
He argues that the exchange should work in both directions. Europe has accumulated experience in safeguards and institutional frameworks, while Latin America has demonstrated a capacity for rapid digital adoption under more constrained economic conditions.
Instant-payment systems illustrate that strength. More than 75% of adults in Brazil use Pix, according to World Bank data cited by Rizzo, while fast payments represent more than 40% of digital-payment volumes in several Latin American economies.
AI Agents Change the Accountability Question
The governance challenge becomes more complex as companies shift from systems that generate content or recommendations to AI agents capable of executing tasks, interacting with other systems and acting under delegated authority.
“The question is no longer, ‘What can the AI say?’ It becomes: ‘What is the AI authorised to do?’” Rizzo said.
Among companies using AI agents, 85% reported that at least some agents were performing important actions without real-time human intervention, according to the EY research referenced during the discussion. Yet 49% said their governance frameworks had not been updated to cover agentic AI, and 26% could not detect unauthorised agents operating internally.
The consequences vary by sector. In banking, an error can affect lending, fraud controls or customer finances. In healthcare, it can influence diagnosis or treatment. In manufacturing, an AI system connected to operational technology may affect production or physical safety.
Less-regulated sectors are not immune. Employees can upload confidential information to external models, disclose intellectual property, generate inaccurate advice or create cybersecurity vulnerabilities.
Rizzo argues that companies need an operating model rather than a standalone policy. That includes an inventory of AI systems, designated ownership, risk classification, controls over data and vendors, proportionate human oversight, continuous monitoring, incident-response procedures and explicit limits on what automated systems can do.
The Challenge Moves From Experimentation to Redesign
Access to advanced AI models is unlikely to provide a durable competitive advantage because broadly similar technology will be available to thousands of organisations. The larger divide will emerge between companies capable of redesigning their operations around AI and those that continue to manage disconnected pilot projects.
IBM’s 2025 CEO study found that only 25% of AI initiatives had delivered their expected return on investment and just 16% had scaled across the enterprise. McKinsey research also showed that more than 80% of respondents had yet to see a tangible enterprise-level earnings impact from generative AI.
Among the organisational factors examined by McKinsey, workflow redesign had the strongest relationship with a company’s ability to obtain an earnings benefit from the technology.
“The next phase is less about acquiring AI and much more about organisational redesign,” Rizzo said. “The companies that succeed will be those that redesign processes around AI rather than simply adding AI to existing processes.”
The economic potential remains considerable. PwC’s analysis of nearly one billion job advertisements found that industries most exposed to AI recorded around three times the growth in revenue per employee seen in the least-exposed sectors. At the same time, the skills demanded by employers were changing 66% faster in AI-exposed occupations.
Leadership will therefore need to determine which decisions can be automated, which require human judgement and which risks the organisation is prepared to accept. Companies will also need to retrain employees and create structures that connect technical teams with legal, operational and commercial functions.
“The first phase of generative AI was an experimentation phase: organisations were asking, ‘What can this technology do?’” Rizzo said. “The next phase is much more demanding: ‘What should we allow it to do, under whose authority, how do we redesign the organisation around it, and how do we scale it?’”
Within three to five years, simply using artificial intelligence will no longer distinguish a company. The competitive divide will be between organisations that have converted AI into a trusted, governed and scalable business capability and those still attempting to control a fragmented collection of experiments.



