- Director of Value Creation
Skip to main content
- Funds
- Capabilities
- Insights
- About Us
FEATURED EQUITY FUNDS
FEATURED FIXED INCOME FUNDS
Asset classes
Artificial intelligence has moved rapidly from experimentation to deployment. For fast-growing private companies, the opportunity is substantial: AI can improve productivity, enhance customer experience, accelerate decision-making, and help teams scale without adding commensurate headcount. AI tools are also now increasingly embedded in core business processes and capable of taking actions with limited human involvement.
Notably, nearly three in four companies plan to deploy agentic AI within two years despite only one in five having a mature governance model for autonomous agents.1
This gap creates risk. Companies that move quickly without appropriate oversight may expose themselves to operational, legal, cybersecurity, customer, and reputational challenges. We believe it is critical for companies to adopt best practices that create the confidence and discipline required to safely deploy AI across their businesses.
Here, we outline the risks AI presents to private companies, explore its evolving regulatory landscape, offer best practices for adoption, and share resources for companies.
Figure 1
What We’re Hearing from Portfolio Companies
Wellington's private portfolio companies provide a valuable window into how AI adoption is evolving in practice. Through our annual AI adoption survey and a peer forum hosted by Wellington that brought together technology leaders from portfolio companies at different stages of growth, two themes emerged consistently. First, AI is becoming embedded in day-to-day operations, with leading use cases including content generation, coding assistance, knowledge retrieval, analytics, and customer support. Second, the biggest barriers to value creation are often organizational rather than technical. Companies reporting the strongest progress are pairing AI investments with employee training, clear governance, and defined expectations for how AI should be used across the business.
Effective AI governance starts with identifying where AI can create risk across data, operations, customer outcomes, third-party relationships, and a range of other domains.
Data, privacy, and intellectual property risks
AI tools increasingly create, process, and rely on large volumes of data across internal systems, customer interactions, and external sources. As adoption grows, companies can lose visibility into how sensitive information moves through their environment, who can access it, and how it is being used. These challenges can create privacy, intellectual property, compliance, and reputational risks. Key examples include the unauthorized use or disclosure of sensitive information, uncertainty regarding ownership and rights associated with AI-generated content, and difficulties demonstrating appropriate governance to customers, regulators, or other stakeholders.
Data, privacy, and intellectual property concerns can be magnified when organizations deploy AI tools before establishing clear controls over data access, retention, and use. Risks may also emerge through employee adoption of unsanctioned AI tools that operate outside established security, privacy, and governance controls (“shadow AI”).
Agentic and autonomous action risk
The risk with agentic AI moves beyond producing a “wrong answer” to taking a “wrong action.” As AI systems gain the ability to access information, interact with applications, and execute multi-step workflows, failures may become more difficult to predict, detect, or reverse. These risks can increase when AI tools are connected to sensitive data, customer-facing channels, payment systems, or other core business processes.
For example, while not a fully autonomous agent, a US auto dealership’s chatbot was manipulated into agreeing to sell a new vehicle for US$1 after a user tested the system’s limits2. The incident illustrates a broader governance concern: AI tools can be pushed outside their intended scope when guardrails and escalation controls are weak.
Reliability and performance risk
An AI tool’s performance can also change over time. Model updates, new data sources, evolving business processes, and changing operating environments can all affect reliability, accuracy, and outcomes. Companies that rely on AI for important decisions or customer interactions may experience operational disruption, poor decisions, or degraded performance if systems are not regularly monitored, tested, and reassessed.
Unlike traditional software, AI systems often continue to evolve after deployment, making ongoing oversight critical.
Customer impact and business risk
As AI becomes more deeply embedded in customer-facing processes and business operations, the consequences of failure increase. AI systems increasingly influence recommendations, decisions, and interactions that affect customers directly. This makes it more likely that errors, bias, or inappropriate outputs translate into tangible harm.
Risks may also arise when organizations pursue AI-driven workforce reductions or customer-service automation without fully understanding where human judgment, escalation, empathy, or institutional knowledge remain essential.
For instance, health insurers have faced lawsuits challenging the use of AI and algorithmic tools in claims denials, with plaintiffs alleging that automated systems contributed to improper coverage decisions and adverse customer outcomes3. These legal challenges highlight the broader business risks associated with inadequately governed AI systems, including regulatory scrutiny, litigation, operational disruption, and reputational damage.
Vendor dependence and AI supply chain vulnerabilities
Most companies will build their businesses with AI tools developed by external vendors. As a result, they may become dependent on third-party models, infrastructure providers, and software vendors they do not control. Changes in pricing, model availability, performance, functionality, or terms of service can create operational, financial, and strategic risk. This is particularly impactful when AI is embedded in critical business processes.
Limited visibility into how third-party models are trained, maintained, updated, and governed may also make it difficult to identify risks related to data provenance, intellectual property, security, or compliance.
Most private companies are not yet subject to a comprehensive AI compliance regime, making effective AI governance largely a matter of self-governance today.
However, expectations around AI governance are increasing rapidly from regulators, customers, employees, investors, and business partners. Leaders should expect greater scrutiny of how AI systems are deployed, monitored, and controlled, particularly where they affect customers, employees, or critical business processes.
Given the pace of change, we believe most companies will be better served by building adaptable governance capabilities than by attempting to comply with individual regulations one at a time. While specific regulations and standards continue to differ across jurisdictions and industries, common themes are emerging around accountability, transparency, human oversight, risk management, documentation, and AI literacy.
Organizations that establish these capabilities early will be well positioned to adapt as legal requirements, industry standards, and stakeholder expectations continue to evolve.
Below, we share best practices for private companies building AI governance capabilities.
AI governance is about ensuring that AI’s rapid innovation creates value without creating unnecessary risk. We believe the companies most likely to benefit from AI will not necessarily be those that deploy it fastest, but rather those that combine experimentation with accountability, customer awareness, and disciplined execution. Companies that establish strong governance foundations will therefore, in our view, be better able to scale AI responsibly, adapt to change, and build trust with customers, employees, investors, and regulators. Critically, governance will need to scale with it, becoming more rigorous as AI becomes increasingly embedded in products, operations, and decision-making.
Appendix A: Prepare for investor questions
Investors are increasingly seeking greater transparency into how companies govern AI, a trend that has expanded beyond the technology sector and is beginning to influence expectations across industries4.
AI strategy and value creation
Governance and accountability
Risk management and responsible use
Organizational readiness and future adaptation
Appendix B: Seven additional best practices for AI developers
Organizations developing AI systems may face additional responsibilities related to product design, testing, transparency, and oversight. The following practices may help AI developers manage these risks throughout the product lifecycle.
Appendix C: AI governance resources
A growing body of guidance is available to help organizations govern AI effectively. The following resources are among the most widely used and practical starting points.
1Deloitte. “State of AI in the Enterprise” (2026) | 2Venture Beat. “A Chevy for $1? Car dealer chatbots show perils of AI for customer service.” (2023) | 3Healthcare Finance. “Class action lawsuit against UnitedHealth’s AI claim denials advances.” (2025) | 4Harvard Law School Forum on Corporate Governance. “AI in Focus in 2025: Boards and shareholders set their sights on AI” (2025)
The views expressed are those of the authors at the time of writing. Other teams may hold different views and make different investment decisions. The value of your investment may become worth more or less than at the time of original investment. While any third-party data used is considered reliable, its accuracy is not guaranteed. For professional, institutional, or accredited investors only.
Experts
Caroline Conway