top of page

Governance Is the New Adoption Blocker (and the New Deal Driver)


For the past two years, the central question in enterprise AI was a capability question: can it do the work?


Between Now Assist's expansion across product lines, agentic workflows moving into general availability, and autonomous specialists resolving the majority of routine IT and HR requests at reference customers, that question has largely been answered. The work can be done.


So why do so many AI programs still stall between pilot and production?


Because the question that decides funding has changed. It's no longer "can it do the work?" It's "can we trust it to do the work - and prove that trust to an auditor?" That's a governance question, and right now it's the single biggest blocker in enterprise AI adoption. It's also, not coincidentally, the fastest-growing line item in enterprise AI spend. AI Control Tower average deal sizes more than doubled quarter over quarter in early 2026 - a signal that buyers have stopped treating governance as a phase-two concern.




The five questions that stall AI programs


When an AI initiative dies in committee, it's rarely because a demo failed. It's because someone senior asked a question nobody in the room could answer:


  1. What AI is actually running in our enterprise? Not what was approved - what's running. Embedded vendor AI, developer copilots, business-unit SaaS agents, and sanctioned platform AI all count. Most organizations cannot produce this inventory today.


  2. Who — or what — is each agent acting as? Agents authenticate, hold permissions, and take actions. If an agent's effective privileges exceed the human it serves, you have a privilege-escalation problem wearing a productivity costume.


  3. What is it allowed to do, and who decided? Policy needs to live somewhere enforceable - not in a slide deck. Which actions require human approval? Which data can an agent touch? Which workflows can it trigger autonomously?


  4. What did it actually do, and why? When an agent takes an action, you need the reasoning trail, not just the audit log entry. Runtime observability into how agents reason - where they made decisions and when to course-correct - is the difference between "we logged it" and "we can explain it."


  5. What happens when one goes wrong? Every autonomous system eventually misbehaves - a compromised agent, a bad instruction chain, an integration acting on stale data. If your answer doesn't include real-time detection, automatic permission revocation, and a kill switch, your answer is incomplete.


If your organization can answer all five, governance accelerates your AI program: every new use case inherits the trust framework instead of re-litigating it. If you can't, every use case fights the same battle from scratch - and most lose.




What "governed AI" looks like on the platform


ServiceNow's answer, significantly expanded at Knowledge 2026, is to structure AI Control Tower around five verbs - and they map almost one-to-one to the five questions above:


  • Discover. | Identify AI assets across the enterprise - not just ServiceNow's - spanning AWS, Azure, Google Cloud, and Microsoft 365. This is the inventory that answers question one.


  • Govern. | Centralize policy: what each agent may do, which actions require approval, how AI use maps to regulatory obligations. Capabilities like Now Assist Guardian and Sensitive Data Handler enforce guardrails at the platform layer rather than in documentation.


  • Secure. | Treat agents as identities with lifecycle management - provisioned, permission-scoped, and de-provisioned like any workforce identity. The Veza and Armis acquisitions signal how seriously ServiceNow is taking agent identity and connected-asset security.


  • Observe. | Runtime observability (via the Traceloop acquisition) into agent behavior - how agents reason, where they decide, when to intervene. Including detecting the scenario every CISO fears: an agent behaving abnormally and attempting to hide its actions, flagged in real time, permissions revoked, shut down.


  • Measure. | Track ROI and consumption against baselines, so the AI program's value case is continuously evidenced rather than asserted once in a business case.




The uncomfortable part?

Governance exposes readiness.


The moment an organization stands up real AI governance, it discovers the problem was never just visibility.

The inventory exercise surfaces customization debt that interferes with agent behavior. The policy exercise surfaces knowledge bases too stale to ground AI answers. The measurement exercise surfaces the absence of baselines - you can't prove AI improved resolution time if you never reliably measured it.


Governance, in other words, is a forcing function for readiness.


That's why the organizations moving fastest right now aren't the ones that bought the most AI - they're the ones that did the architectural groundwork: CMDB health, CSDM alignment, knowledge lifecycle, process standardization, and baseline metrics.


That readiness question - what it actually takes to make your platform AI-ready, and how to assess it honestly - is where this series goes next. Stay tuned.



bottom of page