Point of view
The governance gap: 83% of Indian executives call it essential, 4% have built it
The AI governance gap is not a disagreement about whether governance matters: almost everyone agrees it does. It is a 79-point gap between saying so and having built it, and that gap is exactly where Gartner's cancelled projects come from.

IBM's Institute for Business Value found 83% of Indian executives call effective governance key to successful AI, while only 4% have robust frameworks for managing AI-related risks: a 79-point intent-action gap. That gap is where Gartner's cancelled agentic projects come from.
- IBM, 2025: 83% of Indian executives value AI governance; only 4% have built robust risk frameworks.
- The gap persists because governance is counterfactual value. It prevents incidents that then never demo.
- Gartner names inadequate risk controls among the causes of over-40% agentic project cancellations by 2027.
- India governs AI via existing law under MeitY's AI Governance Guidelines, released 5 November 2025.
- Build governance alongside the first workflow; the cheapest act is naming an accountable human per system.
The evidence
83% of Indian executives say effective governance is key to successful AI, while only 4% have robust frameworks for managing AI-related risks.
43% of Indian organisations have established an AI Center of Excellence, while 75% remain in the early phases of workforce maturity for AI roles.
Over 40% of agentic AI projects will be cancelled by end of 2027, with inadequate risk controls among the three named causes.
India governs AI through existing law under MeitY's AI Governance Guidelines, released 5 November 2025, coordinated by a new AI Governance Group.
How big is the AI governance gap, really?
83% of Indian executives say effective governance is key to successful AI, while only 4% have robust frameworks for managing AI-related risks (IBM Institute for Business Value, November 2025). That is a 79-point gap between belief and construction, and it is the most honest single description of where enterprise AI in India actually stands.
A note on numbers, because this page is about honesty. Figures of "8% comprehensive governance" and "20% risk proficiency" circulate widely, including in our own early materials. We could not verify either against a primary source, so we do not publish them. The IBM India figures above are dated, primary, and India-specific: a better foundation for the same argument, and we would rather use the number we can stand behind than the larger one we cannot.
The gap is not apathy. Almost everyone knows governance matters. What almost nobody has is the built thing: the framework, the model register, the evaluation harness, the escalation path. Knowing and building are different verbs, and the distance between them is where projects die.
83% of Indian executives call effective governance key to successful AI; only 4% have robust frameworks for managing AI-related risks. >IBM Institute for Business Value, AI Infrastructure That Endures (India) (2025)
This is an intent-action gap of exactly the shape the whole market has: near-universal agreement that governance matters, near-total absence of built governance. The 4% who built it are disproportionately the projects that will survive.
Why does the gap persist if everyone agrees governance matters?
Because governance is invisible until it is needed, and by then it is too late to have built it. A framework prevents incidents that never happen; its value is counterfactual, and counterfactual value does not demo. When budget is allocated, the working agent wins over the governance framework every time, because one is visible and one is a set of controls that only prove their worth in a failure that a well-governed project never has.
So governance is deferred. It becomes the thing you will build after the pilot works, and then the pilot ships without it, an incident occurs, confidence evaporates, and the project is cancelled before governance was ever built. Gartner names inadequate risk controls as one of the three causes of the over-40% cancellation rate it expects by end of 2027 (Gartner, June 2025). The 4% who built governance first are drawn disproportionately from the projects that survive.
The fix is sequence, not budget. Governance costs almost nothing to stand up alongside the first build, and a great deal to retrofit after the first incident.
What does an AI governance framework actually contain?
Governance is not a policy document nobody reads. It is a small set of working controls, each of which answers a question you will be asked the day something goes wrong.
An AI governance framework that earns its place contains: a model register recording what is deployed, on what data, and who owns it; an evaluation harness that scores every system against versioned cases so regressions are caught before users are; defined human-in-the-loop checkpoints where errors are expensive and hard to reverse; a documented escalation path for when the system fails; and a review cadence that keeps all of the above current as models and rules change.
None of that is exotic, and none of it takes a year. It takes deciding to build it before you need it. That is the whole discipline, and it is what separates the 4% from the 83%.
What does India specifically require?
India has no standalone AI statute. It governs AI through existing law (the IT Act, the DPDP Act 2023, and consumer protection legislation) under MeitY's AI Governance Guidelines released 5 November 2025 and coordinated by a new AI Governance Group (IAPP, 2025). For a GCC, this means the obligations are not hypothetical future-AI-law obligations; they are present-tense data-protection and accountability obligations that AI deployment activates now.
In practice that translates to three things a GCC must be able to show: consent provenance for training and retrieval data under the DPDP framework, audit trails for what the system did and why, and a named human accountable for each deployed system. A GCC serving overseas customers does not escape this by pointing at the customer's jurisdiction: the processing happens here.
This is also why governance is a genuine advantage rather than a cost. In a market where only 4% have built it, being able to demonstrate consent provenance, audit trails and named accountability is a procurement differentiator, not just a compliance box. An engagement scenario for standing up a governance function shows the shape of the build.
What does this mean for a GCC transformation owner?
Stop treating governance as the phase after the pilot. Build it alongside the first workflow, because the marginal cost then is a fraction of the retrofit cost after an incident, and because the projects that survive are the ones that had risk controls on day one.
Name the owner now. The single cheapest governance act is deciding, before deployment, which human is accountable for each system. It costs a meeting and it closes most of the gap between the 83% and the 4%. Then stand up the register, the harness, the checkpoints and the review cadence as a working set, not a document.
Disclosure: Chokmah is a new practice with no completed client engagements. This page also corrects two figures from our own earlier materials that we could not verify: the honest move, and the one our whole positioning demands. If we cannot verify a number, we do not publish it, even when the unverifiable version is more dramatic. Governance begins with that discipline applied to yourself. A governance and CoE retainer is how we maintain it for a client after the build.
Be in the 4% that built it, not the 83% that meant to
A monthly retainer stands up and maintains the governance framework, the evaluation harness and the escalation path, before the incident, not after.
Talk about a governance retainer · What a diagnostic produces first
Frequently asked questions
What does an AI governance framework contain?
A model register of what is deployed on what data and who owns it; an evaluation harness scoring systems against versioned cases; defined human-in-the-loop checkpoints where errors are expensive; a documented escalation path; and a review cadence that keeps all of it current. It is a set of working controls, not a policy document nobody reads.
Does India have an AI law?
No standalone AI statute. India governs AI through existing law (the IT Act, the DPDP Act 2023 and consumer protection legislation) under MeitY's AI Governance Guidelines released 5 November 2025 and coordinated by a new AI Governance Group. For a GCC the obligations are present-tense data-protection and accountability duties, not future ones.
Who is responsible for AI governance in a company?
A named human per deployed system, not 'the platform' and not a committee in the abstract. The single cheapest governance act is deciding before deployment which person is accountable for each system's behaviour. That decision costs a meeting and closes much of the gap between believing governance matters and having built it.
Do Indian GCCs need AI governance under the DPDP Act?
Yes. The DPDP Act 2023 and the November 2025 AI Governance Guidelines apply to processing that happens in India regardless of where the customer sits. A GCC deploying AI must be able to show consent provenance for its data, audit trails for what the system did, and a named accountable human: the practical core of governance.
How long does it take to stand up a governance framework?
Weeks, not a year, if it is built alongside the first workflow rather than retrofitted. The register, harness, checkpoints and escalation path are a small working set. The cost is low when built first and high when built after an incident, which is exactly why the gap between the 83% who value it and the 4% who have it persists.
Key terms
- AI governance frameworkAn AI governance framework is the documented set of policies, roles, controls and records that determine who may deploy an AI system, on what data, with what testing, and who is accountable when it fails.
- Evaluation harnessAn agent evaluation harness is a repeatable test suite that scores an AI agent's outputs against fixed, versioned cases before and after every change, so teams can tell regression from variance.
- Human in the loopHuman in the loop is a workflow design in which a person reviews, approves or corrects an AI system's output at defined checkpoints before it takes effect, keeping accountability with a human.
More points of view
- Gartner says 40% of agentic AI projects will be cancelled. Here is which 40%.The 40% cancellation rate is not bad luck or immature technology. It is three named, predictable failures (escalating cost, unclear value, absent risk controls) every one of which is decided before the contract is signed, by whether anyone named the workflow first.
- The workflows you should not automateNaming what to leave alone is the first deliverable, not a disclaimer. A vendor who cannot tell you which workflows to keep human is selling you the thing that fails 95% of the time, and the refusal list is the most useful page we can hand a transformation owner.
Frequently asked questions
A model register of what is deployed on what data and who owns it; an evaluation harness scoring systems against versioned cases; defined human-in-the-loop checkpoints where errors are expensive; a documented escalation path; and a review cadence that keeps all of it current. It is a set of working controls, not a policy document nobody reads.
No standalone AI statute. India governs AI through existing law (the IT Act, the DPDP Act 2023 and consumer protection legislation) under MeitY's AI Governance Guidelines released 5 November 2025 and coordinated by a new AI Governance Group. For a GCC the obligations are present-tense data-protection and accountability duties, not future ones.
A named human per deployed system, not 'the platform' and not a committee in the abstract. The single cheapest governance act is deciding before deployment which person is accountable for each system's behaviour. That decision costs a meeting and closes much of the gap between believing governance matters and having built it.
Yes. The DPDP Act 2023 and the November 2025 AI Governance Guidelines apply to processing that happens in India regardless of where the customer sits. A GCC deploying AI must be able to show consent provenance for its data, audit trails for what the system did, and a named accountable human: the practical core of governance.
Weeks, not a year, if it is built alongside the first workflow rather than retrofitted. The register, harness, checkpoints and escalation path are a small working set. The cost is low when built first and high when built after an incident, which is exactly why the gap between the 83% who value it and the 4% who have it persists.
Bring the evidence to your team
We walk in with the failure rates, then the method. Book a free AI Reality Check.