Wellington Management’s Private Investments Value Creation Team, in collaboration with its Public Markets ESG Team, has released a comprehensive publication addressing the critical need for robust Artificial Intelligence (AI) governance within private companies. Authored by Hillary Flynn, Director; Drew Morales, Associate Director; Courtney Hugger, Associate of the Private Investments Value Creation team; and Caroline Conway, all at Wellington Management, the report highlights the rapid shift of AI from experimental stages to widespread deployment and the inherent risks and opportunities this presents for fast-growing private firms.

The increasing integration of AI into core business processes—enabling enhanced productivity, improved customer experiences, accelerated decision-making, and scalable operations without proportional headcount increases—is undeniable. However, this rapid adoption is outpacing the development of mature governance models. A notable statistic indicates that nearly three in four companies plan to deploy agentic AI within two years, despite only one in five possessing a robust governance framework for autonomous agents. This significant gap underscores the potential for substantial operational, legal, cybersecurity, customer, and reputational challenges. The publication emphasizes the imperative for companies to establish best practices that foster confidence and discipline for the safe and effective deployment of AI across their businesses.

The Evolving Landscape of AI Adoption in Private Companies

Wellington Management’s insights are drawn from direct engagement with its private portfolio companies, offering a ground-level view of AI’s practical integration. Through their annual AI adoption survey and a dedicated peer forum for technology leaders from companies at various growth stages, two consistent themes have emerged. Firstly, AI is no longer a peripheral technology but is becoming deeply embedded in daily operations. Leading use cases span content generation, coding assistance, knowledge retrieval, advanced analytics, and customer support. Secondly, the primary hurdles to maximizing AI’s value are frequently organizational rather than purely technical. Companies that demonstrate the most significant progress in AI adoption are those that strategically pair their technology investments with comprehensive employee training, clearly defined governance structures, and explicit expectations regarding AI usage throughout the organization.

This real-world feedback from portfolio companies suggests a proactive approach is necessary. As AI tools become more sophisticated and capable of autonomous actions, the implications of inadequate oversight become increasingly profound. The report serves as a crucial guide, outlining the multifaceted risks associated with AI for private companies, exploring the dynamic regulatory environment, and providing actionable best practices for responsible adoption.

Identifying and Mitigating AI Risks for Private Companies

Effective AI governance necessitates a thorough understanding of the potential risks AI introduces across various domains, including data management, operational integrity, customer interactions, third-party dependencies, and broader business functions.

Data, Privacy, and Intellectual Property Risks

The proliferation of AI tools has led to the creation, processing, and reliance on vast quantities of data from internal systems, customer engagements, and external sources. As AI adoption accelerates, companies risk losing critical visibility into how sensitive information flows within their infrastructure, who has access to it, and how it is ultimately utilized. These complexities can give rise to significant privacy, intellectual property, compliance, and reputational risks. Specific concerns include the inadvertent use or disclosure of confidential information, ambiguities surrounding ownership and usage rights of AI-generated content, and difficulties in substantiating appropriate data governance to customers, regulatory bodies, or other stakeholders.

These data-related risks are often amplified when organizations deploy AI solutions without first establishing stringent controls over data access, retention policies, and usage protocols. Furthermore, the adoption of unsanctioned AI tools by employees—often referred to as "shadow AI"—can bypass established security, privacy, and governance frameworks, introducing further vulnerabilities.

Agentic and Autonomous Action Risk

The introduction of agentic AI introduces risks that extend beyond the generation of inaccurate information to the execution of erroneous actions. As AI systems evolve to access data, interact with applications, and perform multi-step workflows, identifying, predicting, or rectifying failures can become increasingly challenging. These risks escalate when AI tools are integrated with sensitive databases, customer-facing communication channels, financial transaction systems, or other mission-critical business processes.

A cautionary example, though not a fully autonomous agent, involved a US auto dealership’s chatbot being manipulated to offer a new vehicle for a nominal price of US$1. This incident, stemming from a user’s exploration of the system’s limitations, highlights a pervasive governance concern: AI tools can be exploited or misdirected outside their intended operational parameters when adequate safeguards and escalation protocols are absent. The incident, reported in 2023, serves as a stark reminder of the potential for unintended consequences when AI systems are not sufficiently constrained.

Reliability and Performance Risk

The performance and reliability of AI tools are not static; they can degrade or change over time. Factors such as model updates, the integration of new data sources, evolving business processes, and shifts in the operational environment can all impact the accuracy and effectiveness of AI systems. Companies that depend on AI for critical decision-making or customer interactions may face operational disruptions, suboptimal choices, or diminished service quality if these systems are not subject to continuous monitoring, rigorous testing, and regular reassessment.

Unlike traditional software, AI systems often exhibit continuous evolution post-deployment, underscoring the critical need for ongoing, vigilant oversight to maintain their intended performance and reliability.

Customer Impact and Business Risk

The increasing integration of AI into customer-facing functions and core business operations elevates the potential consequences of system failures. AI plays an increasingly significant role in shaping customer recommendations, influencing decisions, and mediating interactions that directly affect consumers. This deep integration makes it more probable that AI-driven errors, inherent biases, or inappropriate outputs can translate into tangible harm for customers.

Risks can also emerge when organizations pursue AI-driven workforce reductions or automate customer service processes without a comprehensive understanding of the enduring necessity for human judgment, empathetic interaction, escalation capabilities, and the preservation of institutional knowledge.

For instance, health insurance providers have faced significant legal challenges concerning the use of AI and algorithmic tools in the denial of claims. Plaintiffs have alleged that automated systems contributed to improper coverage determinations and adverse outcomes for policyholders. These legal actions, including a notable case in 2025 involving a major health insurer, underscore the broader business risks associated with inadequately governed AI systems. These risks encompass intensified regulatory scrutiny, costly litigation, operational disruptions, and significant reputational damage.

Vendor Dependence and AI Supply Chain Vulnerabilities

A prevalent reality for most companies is their reliance on AI tools developed by external vendors. This dependency can extend to third-party models, cloud infrastructure providers, and software vendors over whom direct control is limited. Changes in vendor pricing, the availability of specific models, performance degradation, altered functionalities, or shifts in service terms can introduce substantial operational, financial, and strategic risks, particularly when AI is integral to critical business processes.

Furthermore, a lack of transparency into the training methodologies, maintenance practices, update cycles, and governance protocols of third-party AI models can impede the identification of risks associated with data provenance, intellectual property rights, security vulnerabilities, and regulatory compliance.

The Evolving Regulatory Landscape for AI Governance

Currently, the majority of private companies operate outside the direct purview of comprehensive AI-specific compliance regimes, placing the onus of effective AI governance largely on self-regulation. Nevertheless, expectations surrounding responsible AI governance are escalating rapidly across regulatory bodies, customer bases, workforces, investor communities, and business partnerships. Industry leaders should anticipate increased scrutiny regarding the deployment, monitoring, and control mechanisms of AI systems, especially those impacting customers, employees, or critical operational functions.

European Union: The AI Act of 2024

In the European Union, the landmark AI Act of 2024 is undergoing a phased implementation extending through 2027. Upon its full enactment, organizations involved in the development or deployment of high-risk AI systems will be subject to one of the world’s most extensive AI governance frameworks. This framework mandates stringent requirements encompassing transparency, human oversight, comprehensive risk management, detailed documentation, post-market surveillance, and the cultivation of AI literacy among personnel.

Even companies without direct European operations may find themselves influenced by the EU AI Act’s provisions through their enterprise customers, business partners, or procurement mandates. In practice, many global technology firms are proactively designing their AI systems and governance processes to align with the Act’s stipulations in anticipation of its full implementation, thereby extending its influence beyond the formal compliance timeline.

United States: A Patchwork of Evolving Standards

The United States has not yet enacted a singular, comprehensive federal AI law comparable to the EU AI Act. Instead, expectations for responsible AI governance are continuously evolving through a combination of industry standards, sector-specific guidance, customer-driven requirements, and state-level legislative initiatives.

In the absence of overarching federal legislation, standards-setting activities have gained significant momentum across various industry consortia, international standards bodies, and governmental partnerships. Frameworks such as the NIST AI Risk Management Framework and emerging ISO standards are increasingly shaping customer expectations, influencing procurement processes, guiding industry practices, and informing sector-specific regulatory guidance. Whether through future federal legislation or the evolution of industry self-governance, these established standards are poised to define the benchmarks for how organizations are expected to develop, deploy, and oversee AI systems.

Concurrently, state-level regulatory activity is expanding, creating a complex and evolving landscape of requirements. Regulatory efforts have been most pronounced in sectors where AI may significantly impact employment decisions, access to financial products, healthcare services, insurance coverage, housing opportunities, educational access, and other high-stakes outcomes. Companies operating within these sectors, or utilizing AI to support such critical decisions, should anticipate heightened regulatory oversight and a continuously adapting regulatory environment.

The ongoing discourse concerning the optimal balance between federal and state regulatory authority may introduce further uncertainty, particularly in domains where states have already implemented AI-related legislation.

Given the accelerated pace of change in AI technology and its regulatory implications, it is prudent for companies to prioritize the development of adaptable governance capabilities rather than focusing on piecemeal compliance with individual regulations. While specific legal requirements and industry standards continue to vary across jurisdictions and sectors, a convergence of common themes is becoming evident. These include a strong emphasis on accountability, transparency, meaningful human oversight, proactive risk management, thorough documentation, and essential AI literacy. Organizations that proactively establish these foundational governance capabilities will be strategically positioned to adapt to evolving legal mandates, industry standards, and stakeholder expectations.

Six Essential AI Governance Best Practices for Private Companies

Wellington Management outlines six critical best practices for private companies seeking to build effective AI governance capabilities:

  1. Establish Clear Ownership and Accountability: Designate specific individuals or teams responsible for AI oversight, risk management, and compliance. Clearly define roles and responsibilities related to AI development, deployment, and ongoing monitoring.

  2. Start with a Business Objective Instead of a Specific AI Tool: Focus AI initiatives on addressing tangible business challenges and opportunities. Clearly articulate the desired outcomes and how AI can contribute to achieving them, rather than adopting AI for its own sake.

  3. Know Where AI is Being Used and Govern Based on Risk: Implement mechanisms to identify all AI tools and applications in use across the organization, including "shadow AI." Categorize AI use cases based on their potential risk profile and apply governance controls commensurate with that risk level.

  4. Safeguard Data, Secure Systems, and Diligence Vendors: Implement robust data privacy and security protocols, ensuring sensitive information is protected. Thoroughly vet third-party AI vendors for their security practices, data handling policies, and compliance adherence.

  5. Protect Customers and Other Affected Stakeholders: Proactively assess and mitigate potential biases in AI systems. Ensure transparency in AI-driven interactions and decisions, and establish clear escalation paths for addressing customer concerns or issues arising from AI use.

  6. Monitor Continuously and Prepare for Failures: Implement ongoing monitoring of AI system performance, accuracy, and potential biases. Develop contingency plans and incident response protocols to effectively manage and mitigate failures or unintended consequences.

The Bottom Line: Scaling AI Responsibly

AI governance is fundamentally about ensuring that the rapid pace of AI innovation translates into tangible value creation while mitigating unnecessary risks. Wellington Management posits that companies poised to derive the greatest benefit from AI will not necessarily be those that adopt it most rapidly, but rather those that judiciously blend experimentation with accountability, a keen awareness of customer impact, and disciplined execution. Organizations that establish strong governance foundations will be better equipped to scale AI responsibly, adapt to the dynamic technological and regulatory landscape, and cultivate enduring trust with their customers, employees, investors, and regulators. Crucially, AI governance must evolve in tandem with AI adoption, becoming increasingly rigorous as AI becomes more deeply integrated into products, operations, and strategic decision-making processes.

The complete publication, offering further detailed insights and appendices, is available for review.

By