The Three Pillars of Trustworthy AI — and Why Most Organisations Aren’t Ready 8 min read This blog post was authored by Jonathan Wyatt - Managing Director, Technology Consulting and Alvaro Rueda - Senior Manager on The Protiviti View.AI is no longer a future consideration. It is already embedded across operations, from customer interaction and compliance monitoring to software development and decision support. Yet as adoption accelerates, organisations face a more fundamental challenge: how to deploy AI safely, at scale, and have confidence in the results.Many organisations are adopting AI faster than their governance, data and control environments can support. This creates visibility gaps that delay decisions and weaken confidence in controls, echoing risks long associated with spreadsheets and end-user computing (EUC) adoption.Trustworthy AI is not simply the result of better models. It is the result of better conditions around those models. Without governance and visibility, even advanced systems become difficult to control. When data is weak, AI can produce confident outputs built on unreliable foundations.The organisations that will lead in AI are not those with the largest budgets, the most models or the most ambitious pilots. Instead, they will be those that create conditions for AI to be used responsibly, consistently and sustainably. They will focus their investments on use cases that generate measurable business value.Three pillars matter most: governance, shadow AI management and data discipline. Topics Artificial Intelligence 1. Governance: The architecture of accountabilityThe first pillar is governance. To address the need for AI oversight, leading organisations are now developing policies, forming committees, establishing principles and launching internal task forces. These are important first steps, but they’re not enough on their own.AI governance becomes effective only when it establishes clear accountability. Key accountability questions include the following:Who owns the AI system?Who is responsible for its performance?Who approves its use?Who monitors it after deployment?Who challenges whether the output is appropriate?Who is accountable for remediation when something goes wrong?It’s common for a business team to own the use case, while IT manages the platform. Data teams might be responsible for the underlying datasets. Oversight roles can span compliance, risk, legal and cybersecurity. Vendors could supply the model or infrastructure. As a result, many people are involved, but accountability for the final outcome is not always clearly defined.This accountability gap is one of the most important risks in enterprise AI.A well-designed governance framework should provide a clear path to responsible AI adoption by defining decision rights, approval pathways, risk classifications, minimum controls and escalation triggers. In practical terms, this starts with an AI inventory, named ownership for material use cases, risk-tiering and minimum control requirements that vary according to the level of impact.Findings from Protiviti’s AI Pulse Survey 2026: Shadow AI & Cyber Risk Insights also indicate that organisations with formal AI governance frameworks report stronger visibility and greater confidence in their controls.The key is proportionality. Not every AI use case carries the same risk. A tool used to summarise internal meeting notes should not require the same level of scrutiny as AI used to support credit decisions, financial crime monitoring or customer-impacting decisions. Effective governance allows organisations to distinguish between low-risk and higher-risk use cases, applying stronger controls where the potential impact is greater.AI governance may require dedicated intake, review and oversight mechanisms, including the board and the organisation as a whole treating AI as a standing governance priority, particularly while adoption remains emerging and fragmented. But these mechanisms should connect into existing risk, compliance, technology, data, third-party and assurance frameworks rather than becoming a permanent parallel structure.2. Shadow AI: The risk you cannot seeThe second pillar is shadow AI; this term refers to the use of AI tools by employees or business units without formal approval, oversight or integration into the organisation’s control environment. In many ways, it is the next evolution of spreadsheet and EUC risk: business-led technology adoption that solves actual problems but creates control gaps when it becomes embedded without ownership, validation or monitoring. This can include employees using personal generative AI accounts, business teams adopting unapproved software-as-a-service (SaaS) tools or developers experimenting with open-source models.This behaviour is usually not driven by bad intentions. Employees are often trying to work faster, solve problems or improve productivity. When approved enterprise tools are too slow, too restrictive or unavailable, they find alternatives.The problem is that unmanaged AI use can create significant risks. Employees may enter confidential information, client data or proprietary code into tools without understanding how that information is stored, processed or used. Without proper vetting, third-party dependencies can emerge, particularly as AI becomes integrated into less visible SaaS and vendor tools.A general prohibition is not the answer. Blocking AI tools without providing viable alternatives often drives usage further underground. A better response is to make responsible AI use easier than misuse by offering approved tools, clear rules, fast approvals, controlled testing environments and practical employee education.Discovery is therefore a critical capability. Organisations need tools and processes that allow them to detect where AI is being used, by whom, for what purpose and at what level of scale. This is particularly important where something initially developed for personal use as a productivity accelerator starts to be adopted by wider teams or used more extensively in business processes. Discovery helps identify when teams are becoming overly reliant on AI solutions that may be delivering value but remain little more than working prototypes.3. Data: The foundation AI cannot fixData is the third pillar. AI does not fix poor data. It amplifies it. If the underlying data is incomplete, biased, outdated or poorly governed, the AI output may appear sophisticated while resting on unreliable foundations.Many organisations have complex legacy environments, inconsistent data ownership, and data sitting across multiple systems with different definitions, quality standards and access controls. Lineage may be incomplete. Consent and legal bases for AI-related use may not be clearly documented.For AI to be trusted, organisations need to know what data is being used, where it came from, whether it is appropriate for the use case and whether it meets defined quality standards. This does not mean that every organisation must complete a multiyear data transformation before deploying AI. That is unrealistic. The practical starting point is not enterprisewide data perfection. Instead, organisations should confirm that the data supporting priority AI use cases is owned, traceable, lawful, sufficiently complete and fit for purpose.Protiviti’s AI Pulse Survey 2025: How Data Confidence Drives AI ROI confirms this point: Progress with AI closely correlates with the quality and management of data, and as organisations mature, their data practices become more structured and intentional.A more pragmatic approach is to focus on priority use cases. Organisations should identify the AI initiatives with the greatest business value, assess the specific data requirements for those use cases and address the most important data gaps in parallel with controlled pilots.Manage three pillars together, not in isolationThe three pillars are structurally connected and should be managed as one integrated programme. The mistake many organisations make is to treat governance, shadow AI and data as separate issues.Governance without shadow AI visibility risks governing only the official AI estate while missing the tools already being used across the business. Governance without data discipline creates policies around systems whose inputs may not be trusted. Shadow AI discovery without a governance framework leaves organisations with a list of risks but no clear mechanism to assess, approve, restrict or remediate them.The lesson from spreadsheet and EUC risk is clear: Once business-critical tools become embedded without visibility, ownership or controls, remediation becomes harder. AI raises the same challenge, but at greater speed and scale. The organisations that lead will be those that create the conditions for responsible adoption before fragmented experimentation evolves into embedded risk.Toby Steindler, a senior manager with Protiviti’s risk and compliance practice in Zurich, contributed to the article.This blog is part of a series on AI governance. In the next post, we will examine the first pillar in more detail: what effective AI governance looks like in practice, why accountability is still being underbuilt and how organisations can create governance structures that enable responsible adoption rather than slow it down. Find out more about our solutions: Artificial Intelligence At Protiviti, we deliver cutting edge artificial intelligence solutions, helping you leverage existing Al technologies or build custom solutions for your enterprise. Risk Management Consulting We help our clients confidently navigate dynamic business environments, enabled by high-performing risk and control ecosystems. We bring leading insights and innovative capabilities to help you effectively manage risks and compliance and meet tomorrow's challenges today. Data and Analytics Services Protiviti partners with organisations to provide data and analytics services that support the creation of modern data foundations, optimise data governance and implement advanced analytics strategies — from AI and machine learning to real-time reporting. Cybersecurity Consulting Our cybersecurity services assess, develop, implement, and manage end-to-end next generation solutions tailored to your needs. We share your commitment to protecting your data and optimising your business and cyber resiliency. Regulatory Compliance Protiviti’s regulatory compliance and risk management consulting team brings a blend of experience and fresh thinking through a unique mix of consulting talent combined with former industry professionals. Leadership Rita Gatt As managing director, technology and cybersecurity at Protiviti, Rita leads a dedicated team focused on solving complex organisational challenges, with a particular emphasis on leveraging data, AI and technology to do so. With over 20 years of experience navigating ... Learn More Hirun Tantirigama Hirun is a managing director and Protiviti Australia's technology consulting lead with 18 years’ experience in providing risk and regulatory advisory services across a variety of clients and industries. He has led complex, transformational programs across areas such as ... Learn More Featured insights and client stories Anthropic’s Mythos Raises the Cyber Threat Level BLOGS 5 min read The AI-People Conundrum: Learning to Lead, Not Lag | AI Pulse - Vol.5 SURVEY 10 min read Reimagining the Software Development Lifecycle in the Age of AI INSIGHTS PAPER 11 min read Guide to AI Governance – Frequently Asked Questions RESEARCH GUIDE 153 min read Protiviti Launches Anthropic's Claude to Elevate Research, Insights, Client Delivery CLIENT STORY 3 min read AI Data Centres and the First Mile Infrastructure Fallacy BLOGS 6 min read Cybersecurity and Resiliency in the Age of AI: Taming the Digital Genie Before It Gossips BLOGS 5 min read Six shifts redefining the modern CIO WHITEPAPER 12 min read