Skip to content

Author

Raj Vasireddy

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access 2026

From Policy to Pipelines: Closing the AI Governance Execution Gap

The rapid adoption of artificial intelligence across enterprise operations has created an urgent governance challenge that existing policy-based approaches have failed to resolve. Industry data reveals that a majority of employees report using AI tools their organizations have not authorized, a substantial share of organizations report AI-related security incidents, and most organizations discover AI agents operating without their security team’s knowledge. This paper identifies three structural failure modes explaining why AI governance fails at runtime: timing failure (governance engages at procurement but risk emerges during operation), visibility failure (sanctioned governance cannot reach unsanctioned usage), and abstraction failure (policies specify principles but not operational mechanisms). Through analysis of industry data, regulatory requirements, and documented incidents, the paper presents evidence that each failure mode reflects a design limitation inherent to policy-centric governance. The paper proposes the Operational AI Governance Maturity Model (OAGMM), a framework organized around four independently assessed operational dimensions - discovery, enforcement, GRC integration, and agentic governance - each scored across five levels of operational capability. Rather than a single aggregate rating, the OAGMM produces a dimension-specific profile together with a floor-based composite score, resolving the diagnostic limitation of aggregate maturity models in which strength in one dimension can mask critical exposure in another. The runtime governance architecture is correspondingly extended to address autonomous AI agents through explicit agent identity and registration, agent action audit trails, agent-to-agent interaction monitoring, and automated decision-boundary enforcement. The model is illustrated through analysis of a documented industry incident and application to five organizational scenarios spanning financial services, healthcare, technology, manufacturing, and energy. This work contributes to the emerging literature on AI governance operationalization and provides practitioners with a structured, dimension-aware framework for closing the gap between governance intent and execution.

Raj Vasireddy · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.