The EU AI Act moved into enforcement this month, and the compliance software market responded the way it always does: with products.
Two of the largest platforms in the category shipped AI governance offerings within five days of each other. Agent inventories. Runtime monitoring of tool calls. Policy engines that evaluate what an AI agent is doing while it does it.
Those are real products solving a real problem — for a company running fleets of AI agents in production. If that’s you, go look at them.
It is not the problem in front of the 40-person manufacturer, the regional clinic, or the 200-person financial services firm that your vCISO practice supports. Those organizations don’t have an AI enforcement problem. They have an AI inventory problem, and it’s a much older kind of problem than the vendors are pricing for.
The actual state of AI at a mid-market company
Here’s what I keep finding when someone actually looks.
Three people in customer service pasting client information into a general-purpose chatbot, because it drafts a better email than they do. A SaaS vendor who added an AI feature in a release note nobody read, which now processes data covered under a BAA. A contract that acquired the phrase “AI-powered” at renewal with no corresponding change to the security exhibit. A marketing tool trained on a customer list somebody exported in 2024.
None of that is exotic. All of it arrived sideways — not through a project, not through architecture review, not through anything that would have triggered a control.
You cannot enforce policy against systems you have not enumerated. A runtime guardrail is worth exactly as much as the completeness of the inventory it’s watching, and at a mid-market company that inventory does not exist yet.
So the order matters, and most organizations are being sold it backwards. Assess, then govern. Every organization I have watched invert that order ended up governing the wrong things very carefully while the real exposure sat in a browser tab.
This is not a new discipline
Here’s the part that should be reassuring if you run a vCISO practice: nothing about this requires a new competency.
Ask what’s in use. Ask who owns it. Ask what data touches it. Ask what happens when the output is wrong, and who notices. Ask whether the vendor’s terms changed. Ask whether anyone can turn it off.
That’s discovery. That’s asset inventory. That’s third-party risk. That’s the work you already do, pointed at a category that didn’t exist in your last assessment cycle.
NIST published the AI Risk Management Framework precisely so this wouldn’t require improvisation. It’s structured the way the rest of NIST’s material is structured, which means it maps to what you’re already running rather than sitting beside it. I’ve spent a good part of my career arguing that NIST frameworks are working tools rather than reference documents, and the AI RMF is a clean example of that — you can run it as an assessment tomorrow.
NIST AI RMF has been in RealCISO since May. Deliberately not as a separate module or a separate SKU: it’s assessment content, running inside the same project as a client’s NIST CSF or SOC 2 work, mapped against the same evidence set, scored on the same L1–L5 maturity scale. One project, multiple frameworks, one evidence set. AI governance shouldn’t be a second engagement your client has to be sold.
Why “thin” is the right shape here
There’s a structural argument underneath this that’s worth making plainly.
A compliance platform that tries to become a runtime enforcement agent is choosing to compete with security tooling — EDR, CASB, DLP, proxies — on those tools’ home ground, with a fraction of their telemetry. It’s a thick strategy. It sells well and it demos beautifully.
The alternative is to stay thin: be the layer that assesses the program, tracks whether it’s maturing, and connects to the best-of-breed tools that already hold the runtime signal. That’s a less impressive demo and a much more defensible position, because the assessment layer is the one thing every organization needs regardless of which enforcement tools they’ve bought.
Reasonable people inside this industry disagree about that, and I’d rather state the position than pretend it’s settled.
What to do in the next 30 days
If you deliver vCISO or compliance services, three things, in order:
Run an AI discovery pass across your book of business. Not a questionnaire — a real inventory. Sanctioned tools, unsanctioned tools, vendor-embedded AI, and anything with “AI” in a contract signed in the last 18 months.
Score it as a risk domain, not an emergency. Put it in the assessment you’re already running. If AI governance shows up in a client’s program as a separate crisis workstream, you’ve made it harder to fund and harder to sustain.
Set a re-measurement date. This inventory will be wrong in 90 days. That’s not a failure of the inventory; it’s the nature of the category. Instrument it so you can see the drift rather than rediscovering it annually.
None of this requires new tooling. It requires deciding that AI is a domain you assess on a cadence, like every other domain.
Govern it after you can see it. Not before.
Run a client assessment through itSee the multi-tenant view, the white-label reporting, and the per-client economics with our team. |
Book a Demo |