The Handoff Problem: Why AI Governance Dies Between Depts
- By Winston Thomas
- November 24, 2025

Phil Coady has a message for chief data officers, and it’s one they're eager to discuss: They’re solving yesterday’s problems with tomorrow’s technology, but the operational reality requires a new alliance.
As chief revenue officer at Dataiku, Coady spends his days watching the collision between corporate aspiration and operational chaos. And from where he sits, at the company’s newly inaugurated headquarters in Singapore, the view is clear – it’s about AI governance.
“I guarantee, Winston, you’ve heard a ton,” Coady explains over a call. “I don't think there are challenges that are any different than the challenges we had with the internet and with the cloud.”
It’s a deliberately provocative comparison. Because if AI governance is just cloud governance with better marketing, why is everyone still scrambling?
The handoff problem
Here’s what CROs understand and what savvy CDOs are actively architecting for: Governance doesn’t fail in the architecture; it fails in the handoffs.
“In finance, for example, there are basically three teams: data, risk, and compliance,” Coady explains. “And they tend not to talk to each other for a whole [lot of] reasons.” He pauses to accentuate the issue. These are the people who are supposed to govern AI together, and their channels are as static and unreliable as inter-departmental data feeds that haven’t been reconciled in a quarter.
The CRO perspective is focused on speed and results. Where a CDO might concentrate on the structural integrity of a framework, a CRO sees an organizational chart with fault lines running through it. “If groups don’t want to talk to each other, Dataiku is not going to get them to talk to each other necessarily,” Coady admits. “That’s been going on for 30 years inside of corporations.”
But this is where the modern CDO steps in. They know that technology alone isn’t the fix, but it provides the source of truth needed to force the conversation. “What Dataiku can often do is give them a visualization of the data that they can unify on,” he says. Not a consensus but just a shared reality. Sometimes, that’s enough.
The marketing accusation
When I raise the criticism that AI governance is “mostly marketing” in APAC’s fragmented regulatory landscape, Coady doesn’t flinch. “I get what they’re saying," he responds. “Having a governance framework like the E.U. AI Act is only valuable if you’re actually going to follow up, and if you’re actually going to put penalties in place for not being compliant.”
This view aligns perfectly with the CDO’s shift from ‘policy’ to ‘policing.’ Coady invokes FedRAMP, the U.S. federal security standard. “What is the repercussion of not being FedRAMP compliant?” It’s a rhetorical question. Everyone knows companies can talk about compliance for years without actual consequences. “Until you’re ready to do something about it, it’s just talk.”
It is the CRO’s advantage to see through the performance to the underlying incentive structure. And right now, the best CDOs are using that incentive structure to secure budget for real governance, moving beyond theater to implementation.
The fragmentation trap
Here’s where the interview with Coady gets interesting. Most AI governance discussions focus on responsible AI, including issues of bias, fairness, and transparency. Yes, they are important stuff. But Coady — and increasingly the CDOs managing the P&L of data — think about governance the way you’d govern employees. “I want to know how many I have. I want to know where they are. I want to know their performance. I want to know what they’re doing. I want to know if they’re costing me too much money.”
It’s a fundamentally operational view that bridges the gap between technical debt and financial risk.
“The data is with the biggest companies in the world,” Coady notes. “Those companies are cloud providers, lakehouse providers, LLM providers and business application providers. Trying to get AI to go across all of that and give you a unified output can definitely be challenging."
The solution? “Unless you build governance into the core part of who you are as a company, you’re going to really struggle to get it right.” So, not bolted on afterward and not delegated to compliance, but built in from day one. Such an approach validates the CDO’s long-standing argument for “security by design.” It is also where Coady believes Dataiku’s decade-plus experience gives them an edge.
The agentic accountability question
When Agentic AI’s autonomous agents arrive — really arrive, not the chatbots we’re calling agents today — who gets pointed at when things go wrong?
“When a regulatory body comes in, someone needs to get pointed at,” Coady says flatly. While the CRO worries about liability, the CDO is concerned about lineage.
He tells about a financial institution customer running an agent “in an autonomous fashion, in fairly business-impactful ways… I was as surprised as anyone, to be super honest.”
But here’s his key insight: “This [Agentic AI] train is on the tracks and is going forward. Whether we’re here, you’re here, or anyone’s here.” The question isn’t whether autonomous AI happens, but whether your governance can point to a human when it does. That’s because most regulators still need a human to govern them.
The real long pole
Today, everyone is focused on agent building. But when you ask Coady about the future of agentic AI, he dismisses the hype. “The building of agents will very soon become a commodity,” he predicts. Everyone will have agent builders. The real challenge is “The orchestration of the agents. The management of the agents. The governance.”
When Jensen Huang, NVIDIA’s chief executive officer, talks about 100 million AI assistants, novice CDOs hear a scaling challenge. Seasoned CROs and CDOs alike hear a governance nightmare. “The management of this is going to be the long pole in any tent that we walk into,” says Coady.
The inherent contradiction is clear: We spent a decade democratizing data analytics, and now we’re about to hand autonomous agents to everyone. The CDOs who thought they’d solved governance in 2023 are now upgrading those frameworks to handle autonomous action, realizing they are the only ones who can prevent the scaffold from collapsing.
Coady has seen this movie before. So have his CRO peers. Fortunately, this time, CDOs aren’t just watching but directing the scene — but not all of them.
Image credit: iStockphoto/william87
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.