Skip to content

7 AI Governance Questions Every CX Leader Should Ask

August 28, 2026 | | Customer Experience, AI

AI governance is the set of decisions that determine what an AI system is allowed to do, what data it can touch, who is accountable for its outputs, and how its performance is monitored after launch. For customer experience teams, answering 7 questions before any use case goes live prevents the most common and expensive AI failures.

Right now, most teams can't answer them. A 2026 IBM Institute for Business Value study of 2,000 technology executives found that 77% of organizations report AI adoption is already outpacing their governance capabilities. The tools arrived, but the discipline is still catching up.

Governance has a reputation as the department of slow, the thing added right before launch or cleaned up after an incident. In our work, the opposite plays out. Teams that ask hard questions early ship faster, because they're not relitigating risk at every launch, and they're not rebuilding customer trust after a preventable failure.

What Does AI Governance Look Like in Practice? 

If your team can answer all 7 questions below, launch with confidence. If you can't, you've found your pre-launch work.

1. What could go wrong, and who will catch it?

Every AI system eventually produces an output that's wrong, weird, or harmful, so accountability has to be assigned before launch: a named owner, defined failure modes, and a clear response path. If the answer to "who is watching?" is "no one, specifically," the use case isn't ready. Accountability is a design decision, and it's much cheaper to make in advance than after an incident.

2. What data does the AI system rely on, and who's allowed to see it?

Customer data doesn't stop being customer data because an AI is reading it. Before launch, document what the system ingests, where that data travels, whether it trains anything, and whether the access it grants matches the access your security policies allow. This is where unapproved tools do the most damage: an employee pastes customer information into a free tool, and sensitive data now lives somewhere your security team has never reviewed.

3. What should the AI never be allowed to do on its own?

Some decisions should always include a human: denying a claim, closing an account, making a promise to a customer. Draw those lines before a single use case gains momentum, because they're much harder to draw after teams have built workflows around the shortcut. Clear boundaries also accelerate adoption. People trust systems more when they know where the system stops and human judgment starts.

4. Who owns the outcome when a human and an AI share the work?

Accountability can't belong to the AI, so every human + AI workflow needs a designated owner for what ships. An agent assisted by AI, an analyst reviewing AI-generated synthesis, a marketer editing AI-drafted copy: in each case, define the supervisor, the escalation path, and the accountable owner. Designing that operating model deliberately is what separates a scaled capability from a pile of pilots.

5. What happens when employees use AI tools you haven't approved?

They already are. IBM's research found 70% of technology leaders say teams across the business are deploying technology faster than IT can track it. While the official strategy takes shape, your teams are using whatever tools they can access. That reveals real pain points worth learning from, and it introduces real risk worth managing. You can't govern what you can't see, so create a safe way for people to disclose what they're using, then score each use case on value and readiness. Retire, consolidate, or fix before you add more.

6. How will you know if the AI gets worse?

Launch-day validation proves a system worked once; only recurring measurement proves it keeps working after the data shifts, the vendor updates the model, or usage patterns change. We saw this discipline pay off outside of AI when a national bank rebuilt its log-in journey: 8 coordinated workstreams paired with a live dashboard produced 97% log-in success and 94% registration success, and the dashboard is what protects those numbers. AI deployments deserve the same treatment: measure financial gain, customer experience, customer ease, and employee experience, continuously.

7. Could you explain the AI system to a regulator, an auditor, or the customer it affects?

If the honest answer is no, the use case has a trust problem waiting to surface. Explainability isn't only a compliance requirement; it's increasingly part of the customer experience itself, because customers reward companies they trust with their data. It's why we maintain SOC2 Type II certification for our own work, and why we'd recommend treating compliance as an asset you can point to rather than a hurdle you clear.

Governance is 1 of 9 steps

These 7 questions cover the governance layer of an AI program. They sit inside a bigger framework: 4 steps to build an AI enablement strategy and 5 to make it real, from anchoring AI to your brand promise through measuring every deployment.

We've made the full guide, AI Enablement for Customer Experience: The Nine-Step Approach, free to read.  

You can also see how we apply AI in our own client work, including the governance and security standards behind it. And if you'd rather talk through how these questions apply to your program, speak with an expert. 

JP Joe Piette, EVP of Customer Experience at Andrew Reise
Joe Piette
EVP, Customer Experience

Speak to an Expert

Talk with our EVP of Customer Experience about how we can help you design and implement customer, employee, digital, or contact center experience strategies that drive results.

Book a 30-minute meeting

 

Frequently Asked Questions

What is AI governance in customer experience?

AI governance in CX is the framework of rules, accountability, and monitoring that determines how AI systems interact with customers and customer data: what the AI can do on its own, what requires a human, what data it can access, and how its performance is measured over time. Strong governance is established before launch, not added after an incident.

When should AI governance be established?

At the beginning of an AI program, before any individual use case gains momentum. Governance built in early works as a speed advantage because teams stop relitigating risk at every launch. Governance added after something goes wrong is a cleanup project that costs more and erodes customer trust.

Does AI governance slow down AI adoption?

No. In practice, teams with clear governance ship faster because the hard questions (what data can this touch, who is accountable, what should it never do alone) are answered once instead of debated per launch. Clear boundaries also improve employee adoption, because people trust systems more when they know where human judgment takes over.

What is shadow AI and why does it matter?

Shadow AI is employee use of AI tools that haven't been approved or reviewed by the organization. It matters because it can put sensitive customer data into systems no security team has evaluated. It's also a source of insight: shadow AI reveals the real pain points employees are trying to solve, which is why the right response is a safe disclosure path and a use-case inventory, not a ban.

How do you measure whether an AI deployment is working?

Measure every deployment continuously across 4 dimensions: financial gain, customer experience, customer ease, and employee experience. Launch-day validation only proves the system worked once; recurring measurement catches quiet degradation as data, models, and usage change.

Who is responsible for AI governance in a CX organization?

Every use case needs a named accountable owner, and the overall program typically sits with the leader who owns the experience AI is changing, often the CX leader, working with security, legal, and compliance. Responsibility can be shared across a team, but it can never sit with the AI itself.