Why AI Governance Will Explode in 2026
Kamlesh Lal argues AI governance has shifted from theoretical thought-leadership into real operational implementation in 2026, driven by the EU AI Act reaching its enforcement deadlines and the NIST AI RMF becoming a global reference. He frames it as the ideal career opening for non-technical GRC, audit, and cybersecurity professionals — governance is about impact, risk, and responsibility, not building models. He stresses that boards have stopped asking whether to use AI and now ask how to defend their use of it, and prescribes building practical governance artifacts like risk-assessment templates over memorizing regulations.
The video describes a world where binding regulation is landing in 2026 and boards are anxious about exposure, but governance is only just shifting from theory to implementation and the practitioner base is still forming. Requirements exist; operational maturity does not yet.
Why governance matters
- Regulatory pressure is now concrete, not abstract: the video pins 2026 as the year the EU AI Act "gets into high gear" as its provisions come into force, turning documentation, transparency, and human oversight into legal obligations with fines "into the millions and millions of euros or dollars."
- The GDPR precedent is the explicit template — just as GDPR "became the benchmark" for data privacy and was adopted even outside the EU, the EU AI Act is expected to globalize AI governance the same way, so non-EU orgs are already exposed.
- Board-level accountability has arrived: leadership has stopped asking "should we use AI?" and now asks "how do we defend our use of AI?" — governance is the function that answers that and shields the org from later regulatory exposure.
- The NIST AI Risk Management Framework supplies the backbone (govern, map, measure, manage) and is "being used by regulators, enterprises globally," making risk management a cross-border expectation, not a US-only concern.
- The video marks the shift from policy docs to operational controls: risk classification determines "what sort of controls you implement," so governance is now about tiered controls per system, not white papers.
- There is a real skills and implementation gap: he notes orgs are "very, very nervous" about exposure and that the discipline requires asking the questions engineers don't — who approves deployment, what happens if the system malfunctions, what data the model relies on.
- Governance is oversight beyond technology: an expanding risk surface "doesn't just require technical controls, it also requires oversight," grounding fairness, accountability, transparency, and safety as operational requirements.
In their words
Boards are asking, "How do we defend our use of AI?"— Kamlesh Lal
AI governance is not theoretical in 2026.— Kamlesh Lal
It's not about building models from scratch. It's about understanding the impact, risk and responsibility.— Kamlesh Lal
It doesn't just require technical controls. It also requires oversight.— Kamlesh Lal