3 best practices to bridge the AI strategy and governance divide KPMG's Q2 AI Pulse Survey found the share of organizations in the driving-adoption phase rose from 13% to 22%, yet only about a third say AI roles, responsibilities, and processes are clear and well managed, and just 29% name a C-suite executive as single point of accountability for AI-informed decisions. Steven Hill, managing partner at OakTruss Group, said risk tiering should begin at portfolio assessment rather than deployment, and that CIOs should build the observability layer and hand the business an AI register that forces the naming conversation. The survey results and Hill's recommendations outline three practices for closing the gap between AI strategy and governance. According to the latest KPMG AI Pulse Survey https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf , the share of organizations in the driving-adoption phase rose significantly in Q2, increasing from 13% to 22% and representing the largest movement observed anywhere along the AI maturity curve. But while AI governance is evolving from principle to practice, only about a third say roles, responsibilities, and processes are clear and well managed. Many organizations still work to translate governance principles into operational discipline, with only 29% pointing to a named C-suite executive as a single point of accountability for AI-informed decisions. The issue with AI governance is broader than operational discipline. Just as cybersecurity and testing need to be incorporated early in the software development lifecycle, the seeds of governance need to be incorporated directly into AI strategy and innovation, and governance needs to always be traceable back to the business objectives of the applications being governed. According to Steven Hill, managing partner at cybersecurity and AI governance advisory firm OakTruss Group, the test of whether strategy and governance are aligned is simple. “Can the CIO answer, without a project, what every AI system in the company did last month and who is accountable for each?” he says. “If that takes a fire drill, then AI strategy and governance are running on separate tracks.” So here are three recommendations to narrow the gap so you can drive faster AI adoption for your organization. According to Hill, most organizations tier risk and governance systems at deployment, which turns governance into a tax that arrives late and gets fought. “Tiering should begin at portfolio assessment, when leadership is deciding what to fund,” he says. “The tier sets the control load, the control load sets the true cost, and the true cost determines whether the use case clears its hurdle rate at all.” Plenty of AI initiatives look attractive until you price the continuous oversight, he adds. “The range between high and low can be dramatic,” he says. “That’s strategy information, not compliance information, and a CIO who surfaces it early stops the portfolio from filling up with things that should never have been funded in the first place.” To put this into practice, ensure your innovation pipeline and how you identify and prioritize AI-related ideas have robust frameworks at every stage-gate. Even at the innovation workshop https://www.cio.com/article/3574330/how-innovation-workshops-help-to-get-smart-about-gen-ai-use-cases.html stage, when you brainstorm ideas, you can incorporate elements such as project risk and complexity into your evaluation criteria. Make coarse- and fine-grained risk-tiering a seamless part of your innovation pipeline as you take ideas to value. CIOs often get handed AI governance because AI looks like technology, in that it’s considered an IT responsibility. But according to Hill, the accountable owner of a system or AI use case that denies credit is the one who owns credit, not the platform. “The CIO’s genuine competence is to help make behavior observable: inventory, logging, telemetry, standing reporting,” Hill says. “Risk appetite, tiering decisions, and named ownership belong to the business and the board. A CIO who accepts the whole thing takes unbounded liability for decisions they don’t make, and lets the business skip the work. So the practical move is to build the observability layer, then hand the business an AI register that forces the naming conversation.” The observability layer and register should be more than implementing an AI governance platform since these often compound the issues, making things more about IT and less about the business. Full observability needs to extend into the original AI idea repositories and use case registers as well. The US federal government’s rollout of the Federal Agency AI Use Case Inventory https://www.bing.com/ck/a? &&p=82a8b558e1feaa5df89c1bdb041136272fc52bdf8aee91ede7230e669c50f1dcJmltdHM9MTc4NzYxNjAwMA&ptn=3&ver=2&hsh=4&fclid=2c6d01c5-ace1-68f7-34c4-1743ad5069ac&psq=federal+government+ai+use+case+inventory&u=a1aHR0cHM6Ly9naXRodWIuY29tL29tYmVnb3YvMjAyNS1GZWRlcmFsLUFnZW5jeS1BSS1Vc2UtQ2FzZS1JbnZlbnRvcnk is a solid example of how this kind of register can provide the important upstream data on mission and business objectives. It’s also important to extend this observability into AI economics and ROI both estimated and actual . Ensure you have a consistent way to calculate AI ROI and keep track of both predicted and realized value, as well as quantitative and qualitative benefits. The upside here is huge in that according to the same KPMG research https://assets.kpmg.com/content/dam/kpmgsites/xx/pdf/2026/06/global-ai-pulse-q2.pdf , those with full cost visibility are five times more likely to report established ROI than organizations without full visibility. AI governance policies are easy to ignore as written guidelines, but it’s far harder for the business to sidestep them if they’re part of the overall platform and formal set of strategy and governance systems. “Strategy and governance drift apart when governance lives in a document, and strategy lives in systems,” says Hill. “Registration and logging should be properties of the platform, and there’s no model access, compute, or production path without being in the inventory. If it’s opt-in policy, shadow AI wins and the inventory is stale the day it’s finished. If it’s infrastructure, every new initiative inherits governance by default, and oversight scales at the speed of adoption rather than being an afterthought. This is the CIO’s highest-leverage contribution, and the one that no one else in the organization can make.” Scaling AI implementations is far more than just getting AI governance right. It’s about developing clear lines of sight and alignment between AI strategy, governance systems, and processes, so governance is cognizant of strategy and vice versa. It comes down to human accountability, and setting clear roles and expectations for both the business and IT.