
Most failed AI projects do not fail because of the technology. They fail because of the data – more precisely, because no data governance sets out how that data is to be handled.
The figures are sobering. Gartner forecasts that around 80 per cent of data and analytics governance initiatives will fail by the end of 2027, because they lack genuine business urgency. And when AI projects fail, the cause is rarely the model. An article in t3n gets to the heart of it: the data often exists already, but nobody has decided who may use it for AI, who authorises access and what rules apply. That is not a data quality problem, it is a governance problem.
Which is exactly what this article is about. What data governance is, why it is becoming the foundation of every AI success, and how mid-sized companies build it without disappearing under a mountain of bureaucracy.
Data governance is the set of rules for handling data across the entire company. It sets out who is responsible for which data, how that data is collected, maintained and used, and who may access what. It is therefore the overarching framework for the whole of data management. In short, it answers three questions: who is responsible, what the rules are, and how they get applied.
It is worth separating this from the technology, because that is where confusion usually starts. Data governance is not the same as the infrastructure the data sits in. Where data is stored and processed is described by the data architecture; the technical platform for it is provided by the data platform. Governance sits one level above. It is the rules-and-people layer that determines how that technology may be used.
An analogy helps. The data architecture is the road network, the data platform is the vehicles, and governance is the highway code plus the question of who holds a licence. Without those rules, even the best infrastructure is of little use.
When professionals talk about a data governance framework, they mean exactly this interplay of policies, roles and processes, brought together in a binding structure. Such a framework is not a rigid document but a living programme that grows with the company's data estate and requirements. For SMEs, the main point is that it does not have to be complete from day one – it can mature step by step.
It also differs from neighbouring disciplines. Data management deals with the technical side; data security protects against unauthorised access. Governance decides who may have access in the first place, and in doing so forms the backbone of any workable data strategy.
The most important reason today is artificial intelligence. AI models only work with clean, accessible and documented data. A system built on fragmented silos delivers unusable results. That turns data quality from an IT issue into a business risk, and makes data governance for AI the precondition for trustworthy results in the first place.
A Gartner survey of 782 infrastructure and operations leaders shows just how badly data becomes the bottleneck. Thirty-eight per cent name poor data quality or limited data availability as the direct cause of failed AI projects. Disorganised data is money left on the table.
The second reason is compliance. If you have to be able to show which data you process and how, you need clear responsibilities and documentation – whether for data protection under the GDPR or for the EU AI Act. How the two regimes interact is something we set out in our article on AI, data protection and the GDPR. Governance provides the foundation on which compliance can be evidenced at all.
The IBM Cost of a Data Breach Report 2025 shows the size of the gap. Sixty-three per cent of organisations hit by a data breach had either no AI governance policy or one still in development. Without it, companies can neither prove which systems process which data nor enforce consistent rules, and the risk grows with every new AI application. What that looks like when it goes unmanaged is the subject of our article on shadow AI in companies.
The third reason is simply that you make better decisions. When reports contradict each other and nobody trusts the numbers, data-driven initiatives stall. Governance breaks open the classic data silos in which every department maintains its own version of the truth, and creates a shared, reliable basis. Only then do business intelligence and analytics deliver robust results – the basis for sound decisions, with or without AI. It is no accident that 61 per cent of organisations are evolving their data and analytics operating model because of AI technologies, according to Gartner. The technology is finally forcing the structure that data teams have spent years asking for.
A working framework rests on a handful of clearly identifiable pillars. Cover these four and you have the essentials in place.
Complete, consistent and current data is the basis for everything else. Data quality is not a one-off tidy-up before a project but an ongoing process, because quality degrades continuously across the data lifecycle. Clear standards and regular checks keep it stable.
The most common reason governance fails is unclear ownership. Every data domain therefore needs a responsible person – a data owner and data stewards, in the jargon – who are accountable for the quality, access and use of their data. What counts is not the title but the clear mandate. For mid-sized companies that explicitly does not mean having to create a C-level role such as a chief data officer. It is enough that one person is given a cross-functional mandate for data quality, access and use, often the head of IT or the managing director themselves.
Who may see, change and use which data? A well-thought-out permissions model is the basis of data security. It protects sensitive information while making sure the right people get the right data, backed up by policies and processes people can actually understand.
Governance depends on repeatable procedures. How is data captured, released, deleted? How is its origin documented? That traceability is what turns individual rules into a robust system – and it is also the basis for any compliance audit. Part of that is keeping the path of the data traceable, what is known as data lineage. It shows where a value came from and which processing steps it went through, which is particularly valuable when an AI result is questioned or a regulator comes asking.
How other mid-sized companies assemble these building blocks in practice is something you can pick up first-hand at d:u27 in Münster, on the Data Stage and on a dedicated SME Stage by and for mid-sized companies, where a range of data and AI use cases are presented.
The good news for mid-sized companies is that this does not have to be a bureaucratic mega-project. On the contrary, the most common mistake is over-engineering – producing extensive rulebooks that nobody actually follows. Gartner names missing business urgency as the main reason initiatives fail. Governance that is seen purely as a cost never takes hold.
The pragmatic route therefore starts small and specific:
Building up step by step avoids the classic trap in which companies first buy expensive governance software and then wonder why nothing changes. Structure and responsibilities come first, tools support them later.
The mindset behind it matters most. Data governance is a leadership matter, not purely an IT task. Only when management demands data quality and clear ownership do rules turn into something people actually follow.
Take a mid-sized manufacturer introducing an AI assistant for quotations. It starts by mapping only the data it needs – product master data, price lists, customer history – and sorts out ownership and access for just that. Governance grows out of real needs rather than being drawn up on paper.
How other companies walk this pragmatic path and avoid the typical pitfalls is what the people doing it will tell you at d:u27 on 13 and 14 April in Münster.
Data governance is not an end in itself and not bureaucracy for its own sake. It is the basis for data being reliable, AI working in a trustworthy way and compliance becoming demonstrable. That is precisely why it determines whether your AI initiatives succeed or fail – often before the first model even runs.
For mid-sized companies the opportunity lies in the pragmatic approach, and the reward is more than risk avoidance. Companies where governance is a habit make faster, better-informed decisions and get AI projects into live operation more reliably, while others remain stuck in pilot phases and contradictory reports.
How companies walk that path in concrete terms is at the centre of d:u27 on 13 and 14 April 2027 in Münster. Around 17,000 participants come together across six stages, with more than 80 masterclasses and over 350 speakers, including a dedicated Data Stage for everyone who thinks about data and AI from the foundations up. And if you want to get up to speed beforehand, the d:u Education library has the right masterclasses on demand. Secure your tickets for d:u27 now!
