In most enterprises, that infrastructure is partial, inconsistent, or absent precisely where AI systems need it most.
Why This Matters Now
The governance frameworks that have emerged for enterprise AI, including the EU AI Act, the NIST AI RMF, and ISO 42001, share a common architectural dependency. They require organizations to know what data their AI systems were trained on, to verify that data's quality and provenance, to enforce purpose limitation on data processing, to support data subject rights at the model level, and to maintain lineage records that connect AI outputs back to the data that produced them.
These requirements presuppose data governance infrastructure that is mature, comprehensive, and operationally effective. In reality, the organizations now being asked to implement AI governance are often the same organizations whose data governance programs are incomplete, whose data inventories are partial, whose data lineage records are manual or absent, and whose data quality processes exist at the team level rather than at the enterprise level.
AI governance cannot be built on top of data governance that does not exist. The compliance obligation is real. The infrastructure required to meet it, in many organizations, has not been built. That gap is where the most significant AI governance failures will occur.
The Governance Problem Beneath the Surface
AI governance and data governance have historically been managed as separate disciplines, owned by different teams, built on different tooling, and governed by different frameworks. AI governance addresses model risk, deployment controls, and AI-specific regulatory requirements. Data governance addresses data quality, data lifecycle management, and data policy compliance.
AI regulation has collapsed this separation. The EU AI Act's data governance requirements in Article 10, the NIST AI RMF's data provenance requirements, and the GDPR's processing accountability requirements that extend to AI training all require AI governance and data governance to function as integrated disciplines. Where they operate as separate programs with separate owners and no systematic connection, the AI governance program will consistently fail to meet requirements that depend on data governance capabilities it does not have access to.
The problem is not that AI governance programs are inadequate. The problem is that they are being built on top of data governance foundations that were not designed to support them.
What This Actually Means in Enterprise Practice
Training Data Lineage Requires Data Governance That Does Not Exist for AI
AI governance requires knowing what data trained each model, what version of that data, from what sources, processed through what transformations. This is a data lineage requirement. Most enterprise data governance programs maintain lineage for analytical and reporting purposes at a level of granularity that is insufficient for AI training data documentation. The lineage exists at the dataset level. AI governance needs it at the individual record level for data subject rights purposes.
Data Quality Frameworks Were Not Built for Training Data
Enterprise data quality frameworks define quality dimensions, set thresholds, and report quality metrics for data used in operational and analytical processes. These frameworks were not designed for training data assessment. The quality dimensions that matter for training data, including representativeness across subgroups, labeling consistency, and temporal relevance, are different from the quality dimensions that operational data governance programs measure. The programs exist. The intersection they need to cover does not.
Data quality for AI training is not a subset of operational data quality. It requires different assessment criteria, different documentation standards, and different governance processes. Organizations that have strong operational data quality programs frequently discover that those programs provide limited support for AI training data governance.
Data Minimization for AI Conflicts with AI Performance
Data minimization is a foundational principle of modern data governance: collect and retain only what is necessary for the defined purpose. AI systems challenge this principle structurally. Larger, more diverse training datasets generally produce more capable, more robust models. The data governance principle that limits data collection and the AI development principle that values comprehensive training data are in direct tension.
Resolving this tension requires data governance infrastructure that can define minimization obligations for AI training use cases specifically, which most programs have not built.
Data Subject Rights Require AI-Aware Data Governance
Supporting data subject rights for individuals whose data trained an AI model requires data governance infrastructure that connects personal data records to training datasets to model versions. None of the components of this chain are new governance requirements in isolation. The connection between them, the architecture that allows a data subject right exercise to trigger a model-level assessment, requires data governance and AI governance to function as a single integrated system. In most organizations, they do not.
How Different Teams See This: Where They All Miss
The gap between AI governance requirements and data governance capabilities is an organizational design problem. It persists because the two disciplines were built separately and are being asked to integrate retroactively by regulatory requirements neither was designed for.
Framework Cross-Walk
- EU AI Act, Article 10: Requires data governance practices for AI training data that most existing data governance programs were not designed to provide.
- NIST AI RMF, Map Function: Data lineage and provenance assessment requirements that depend on data governance infrastructure that may not exist at the required level.
- GDPR Articles 17 and 22: Data subject rights and automated decision-making requirements that extend into AI training data and model governance.
- ISO 42001: Requires that AI governance be supported by organizational data management capabilities. Explicitly acknowledges the dependency between AI governance and data governance.
Every AI governance framework creates requirements that extend into the data governance layer. The frameworks do not assume that data governance exists. They require organizations to build the intersection and most have not.
The Enterprise Reality Gap
The enterprise reality gap is between AI governance compliance claims and the data governance infrastructure those claims depend on. An organization can document AI governance processes, implement AI-specific controls, and report AI compliance status while the data governance capabilities those processes depend on are absent, partial, or misaligned with AI-specific requirements.
The gap becomes visible when the AI governance program is asked to deliver a specific output that requires data governance infrastructure: a training data lineage record for a regulator, a representativeness assessment for a high-risk system, an erasure impact assessment for a data subject rights request. At that moment, the dependency on data governance becomes concrete, and the gap becomes apparent.
AI governance programs that have not assessed their dependency on data governance infrastructure are building compliance posture on a foundation they have not inspected. The inspection reveals the gap. The regulatory inquiry that triggers it is the more expensive version of that inspection.
Enterprise Scenario: The AI Compliance Program With a Missing Foundation
The AI governance program was well-built for the layers it addressed. The data governance foundation it depended on was not built to support it. The compliance gap was not in AI governance design. It was in the assumption that data governance infrastructure required by AI regulation would exist when needed.
Industry Signal
Regulatory examinations of AI governance programs have consistently surfaced data governance gaps as a primary finding category. AI Act supervisory authorities, financial services regulators examining model risk governance, and data protection authorities examining AI processing under GDPR have all identified training data documentation, data lineage, and data quality assessment as areas where organizations have governance processes at the AI layer but insufficient infrastructure at the data layer. The finding is predictable. The organizations that are prepared for it are those that assessed the dependency before the examination.
The examination question that exposes the gap is simple: show me the training data governance documentation for your highest-risk AI system. The organizations that can answer it clearly have built the integration. The ones that struggle have discovered the gap at the worst possible time.
Enabling Capabilities
- AI-aware data cataloging: Data catalog capabilities extended to include training dataset documentation, version tracking, and linkage to model training records.
- Training data lineage platforms: Tools that track training data from source through processing to model training, at the granularity required for data subject rights and regulatory documentation.
- Data governance and AI governance platform integration: Architectural connections between data governance platforms and AI governance tools that allow compliance requirements to be met across both layers through integrated infrastructure.
- Enterprise data quality frameworks extended for AI: Quality assessment methodologies that address AI-specific dimensions including representativeness, labeling quality, and temporal relevance.
- Privacy ops platforms: Data subject rights workflows extended to query AI training data registries as a standard step in erasure and access request fulfillment.
A Practical Starting Point
Assess the data governance dependency before building the AI governance structure. For each AI governance requirement in your program, identify the data governance capability it depends on and assess whether that capability currently exists at the level required.
Produce a dependency map: AI governance requirement, dependent data governance capability, current capability state, gap. Prioritize gap closure based on regulatory obligation and operational risk. Build the data governance foundation and the AI governance structure in parallel, not sequentially.
The dependency assessment is faster and cheaper to perform before building the AI governance program than after discovering the foundation is missing during regulatory examination.
Questions Leaders Should Be Asking
- For each AI governance requirement in our program, what data governance capability does it depend on, and have we assessed whether that capability currently exists?
- Who is responsible for the data governance capabilities that AI governance requires, and do they have the mandate and resources to build AI-specific extensions to existing programs?
- Can we produce Article 10 training data documentation for our highest-risk AI system today, or would that require work that has not been done?
- What is the current state of training data lineage in our AI development programs, and does it meet the level of detail required for regulatory documentation?
- How are our data governance and AI governance programs connected, and what integration exists between their respective tools and processes?
What to Require From Vendors
Ask directly:
"What data governance capabilities does your AI platform provide or require, and how does your platform support the training data documentation requirements of the EU AI Act Article 10?"
Expect as evidence:
- Documentation of what training data governance the platform provides natively versus what the customer must build
- Integration capabilities with data governance platforms for lineage and provenance tracking
- Specific guidance on Article 10 documentation and what the platform can and cannot support
- Data management documentation that supports customer AI governance compliance obligations
An AI platform vendor who has not considered the data governance infrastructure required to support their platform's AI governance obligations has left a significant compliance dependency to the customer without helping them understand it.
Demonstrating Diligence
- Documentation: AI governance to data governance dependency map; training data documentation for high-risk systems; data governance capability assessment with gap identification.
- Process: Integrated AI and data governance review process; training data documentation as a required artifact in AI development lifecycle; data governance review as a prerequisite for AI system deployment.
- Technical evidence: Training data lineage records; data quality assessment outputs for training datasets; integrated governance platform configurations.
AI governance diligence requires demonstrating not just that AI governance processes exist but that the data governance foundation they depend on has been built.
Closing Perspective
AI governance and data governance are not two separate programs that happen to share some vocabulary. They are interdependent disciplines that require integrated infrastructure to function. The regulatory frameworks that govern AI have recognized this interdependence and built requirements that cross the boundary between the two.
Organizations that build AI governance without building the data governance foundation it requires are investing in compliance documentation that will not hold up when tested against the requirements it claims to address. The investment in integrated infrastructure is larger upfront and materially less expensive than the remediation required when the dependency gap is discovered under regulatory pressure.
The organizations that will navigate AI governance most effectively are those that treated data governance maturity as a prerequisite rather than an aspiration, built the integration between the two disciplines before regulatory examination forced them to, and produced AI compliance documentation that is grounded in data governance infrastructure that demonstrably exists.
AI governance is only as strong as the data governance it stands on. Build the foundation first.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
