Governance isn't the brake, it's the engine

Why the smartest AI organizations build compliance in, not bolt it on.

Contributors:
Barbara Sondag
CIPP/E, CIPM
Senior Assistant General Counsel - Privacy Data Governance
Intuit
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
There's a persistent myth in tech that legal and governance teams exist to slow things down. That the lawyer's job is to say no and the compliance team's job is to generate paperwork. I've spent my career proving otherwise.
And the work I'm doing right now gives me the clearest evidence yet.
From review checkpoint to policy-as-code
Traditional compliance works like a tollbooth at the end of the highway. By the time a product reaches legal review, so much has been built that pushing back feels unreasonable or too time-constrained. The incentive for product teams becomes "present something so close to finished that changes are too costly to demand."
This model made sense when the pace of product development allowed for it. Now, in the era of generative artificial intelligence, where the data decisions baked into a model at training time are extraordinarily difficult to undo, and where regulatory scrutiny of those decisions is increasing in real time, the old model no longer makes sense.
The new model treats governance as infrastructure — something designed into the system from the beginning, not inspected at the end. Compliance is no longer a stop-point and becomes the infrastructure that lets the business move with confidence. Rules are standardized and encoded. Data use and access controls are applied at the building stage. Review processes run in parallel with development, not after it. Legal and compliance teams shift from gatekeepers to enablers, embedded in the product life cycle rather than waiting at its exit.
What this actually looks like in practice
When I stepped into my current role leading enterprise data governance, one of the first things we did was move the organization from reactive risk management to a proactive strategic mandate — what we call governance-by-design. That required getting executive alignment not just on policy, but on architecture: governance rules that live in the platform, not in a document.
The result is a set of standardized data governance rules mapped directly to enforcement paths on the data platform — running automatically, reducing risk in real time, without requiring a human to review every decision. This shift from bespoke to scalable privacy guardrails accelerated the review time for low-risk cases by 80%.
When a product team wants to use a dataset, they can find out what constraints apply before they've written a line of code. They will know whether they can access the data and how the data can be used. That's not a compliance achievement, but an engineering achievement that compliance made possible.
That's the moment I knew this model worked. The reaction from engineering and product teams was delight. The realization that requirements only needed to be defined once, and that data governance rules answer two critical questions in an automated way: can we access this data, and for what purposes can we use it? That clarity is what real velocity looks like for product teams. That gives builders confidence that they're working with the right set of data, not second-guessing.
The business case is straightforward
Shifting governance to the left reduces cost at every stage. If data is handled inappropriately in a product and the issue is caught by audit rather than by monitoring, it costs the organization a remediation — which may also involve a regulator, and sometimes a headline. Building the controls in from the start means the platform catches it first.
Beyond cost avoidance, governance-by-design creates a genuine competitive advantage. If organizations can demonstrate to enterprise customers, and increasingly to regulators, that their AI products were built with data integrity from the ground up, they will earn the trust that wins deals their competitors lose.
When organizations can show a customer exactly where their data went, what it was used for and who was accountable for those decisions at every step, that transparency can actually move procurement conversations. Enterprise buyers increasingly expect it, and organizations that build it in from the start don't have to scramble to answer those questions at the deal table.
The organizational change is harder than the technical one
Legal and compliance teams must stop showing up as reviewers and, instead, be embedded partners in the build. That's a real identity change, and it's one most teams resist until they've seen the alternative. Product and engineering teams have to accept that some data constraints aren't negotiable, not as a matter of policy, but because consent obligations and regulatory obligations travel with the data regardless of what any architecture decision says. And leadership must fund governance as a platform investment, not treat it as overhead.
None of these shifts happen on their own. To start, answering five questions can help determine where the organization stands.
- Can the organization produce a list of every AI system running in production today? Include the AI systems embedded in third-party tools.
- When a product team wants to use a dataset, how do they find out what constraints apply? How long does it take, and does the answer come from a document or from the platform?
- How long does the organization's fastest, lowest-risk AI review take? Consider the time from request to approval.
- If an enterprise customer asked today where their data went, what it was used for, how long would it take to answer? Make sure the data lineage and accountability infrastructure is keeping pace with the organization's AI ambitions.
- Who is accountable when an AI system produces a harmful output? If the answer is unclear, or points to no one in particular, the organization's governance model has a gap that regulators — or customers — will eventually find.
If the honest answer to most of these is "we'd have to go ask around," that isn't a governance failure. It's a diagnosis, and it's a very common one.
The next move is an important one, but it doesn’t involve writing a policy. It's finding the technical or data leader who already understands why this matters and making them your internal champion. Executive alignment is what turns governance from a compliance function into an enterprise mandate. With commitment from leadership and cross-functional partnership, the organization takes an important step toward building proactive, centralized rule interpretation which will give builders confidence in the data they use.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Barbara Sondag
CIPP/E, CIPM
Senior Assistant General Counsel - Privacy Data Governance
Intuit



