Chapter and Role Reference
What each chapter of The Governed Enterprise covers, and where to start if you are facing a specific problem rather than building a program from scratch. The book is organized into seven parts that run from what you are governing, through how to build the infrastructure, to where AI actually operates in a consumer goods business. Page numbers are the printed page numbers in the paperback and hardcover.
If you are facing something specific
The book works as a reference as well as a sequence. This is the map the Introduction gives for that. Select a row to mark the chapters it names.
Establishes the three categories of AI that matter for consumer goods companies, traditional predictive AI, generative AI, and agentic AI, and why each requires a different governance approach. Most governance failures occur because organizations apply the same controls to fundamentally different technologies.
The AI Landscape Has Changed
Separates predictive, generative, and agentic AI, and establishes why the controls that work for one fail for another. Closes on the inventory, on the principle that you cannot govern what you have not mapped, and most organizations find systems in production that no one formally approved.
The Governance Imperative
The legal exposure, treated as current rather than future. The Air Canada ruling, the FTC's substantiation standard, and the EU AI Act's compliance deadlines are the anchors. This is the chapter a General Counsel takes to a board.
AI Governance Fundamentals
The five pillars of CPG AI governance, accountability, transparency, explainability, fairness, and safety, with the NIST AI Risk Management Framework as the working foundation. Ends with a test for governance theater, which is the state of believing you have governance because you have documentation.
Addresses who owns AI governance in the organization, how to write policies business leaders will actually follow, how data governance underpins everything AI touches, and how to extend governance requirements to vendors and co-manufacturers who operate on your behalf.
Ownership and Accountability
Where AI governance sits and who answers for it. Reporting through the CIO creates a structural conflict, because that role's primary accountability is enablement, which pressures approvals toward speed. Covers how an AI Governance Council is constituted and what it decides.
Policies That Actually Work
Policies that hold on a plant floor and in a boardroom, built for clarity, enforceability, and operational integration. Identifies the data that requires executive authorization before any AI touches it, and treats vendor AI as needing its own policy rather than a clause in the internal one.
Data Governance as the Foundation
Classifying what AI may reach. The category most classification schemes miss is operational secrets: retailer trade terms, pricing and margin structures, supplier volume commitments, M&A pipeline data. These are neither intellectual property in the legal sense nor regulated data, and disclosure still causes the damage.
Third-Party AI Governance
The AI already running inside software bought years ago: forecasting and anomaly detection in the ERP, generative drafting in the CRM, pattern recognition in the quality platform. Covers the build versus buy decision and how governance obligations extend to co-manufacturers and third-party logistics providers.
Examines how governance functions in the environments where AI actually runs: marketing and sales operations, procurement and logistics, manufacturing and quality, finance and human resources. This is where governance moves from policy to practice.
AI in Marketing and Sales
Governing generated claims and packaging copy. The mechanism is a pre-approved claim library the AI draws from, with mandatory regulatory review for anything outside it. Works through where FDA substantiation and EPA registration rules bite, including the legally significant gap between an antibacterial and an antiviral claim.
AI in Supply Chain
Agentic procurement and the spend authority model. Opens with 23 purchase orders issued between 11 PM and 3 AM to a single supplier, each below the authorized per-transaction threshold, totaling $1,043,000, with no fraud and no malicious intent. The governing question is whether a human is still the actor.
AI in Manufacturing and Quality
Validation protocols for vision and quality systems, designed around the systematic failure modes that scale creates rather than around random error. Includes the Kraft Heinz vision system on the Claussen pickle line, where the supply chain runs on a ten-day window from field to jar.
AI in Accounting and Finance
Separates committing the company from paying what it has already committed, because the controls differ with the direction of the action. Covers vendor verification against payment fraud: authentication on banking detail changes, waiting periods before new payment information takes effect, and duplicate and manipulation detection.
AI in Human Resources
Screening, selection, and monitoring, and the EEOC's expectation of human oversight. A process where a human is nominally in the loop but routinely approves AI recommendations without independent review does not meet that expectation and will not hold up as a defense when an outcome is challenged.
Addresses emerging AI security threats and how to protect AI systems in manufacturing, distribution, and commercial environments. Covers how threat actors are weaponizing AI against consumer goods companies and the security challenges specific to AI running in operational contexts.
Weaponized AI Threats
Deepfake audio and video, and AI-enabled business email compromise, with FBI reporting behind the figures. The two documented tactics are generated correspondence impersonating senior executives and voice cloning used to authorize wire transfers, and both run on recordings your company published itself.
AI Cybersecurity Threats
Prompt injection as the attack that arrives inside the data rather than through the perimeter. Draws on published research covering 1,054 test scenarios across 17 business tools, which applies directly to any company connecting agents to its business systems.
AI Security for Operations
The paths that now connect the corporate IT network to the operational technology running the line, including cloud platforms holding real-time models of physical production equipment. Attackers traverse those paths in both directions, which is a security architecture problem rather than a tooling one.
Provides the frameworks for assessing which AI systems pose material risk, establishing oversight that detects problems before they cascade, and responding effectively when AI systems fail.
AI Risk Assessment
Scoring and prioritizing exposure. The category specific to consumer goods is safety and compliance risk: a quality vision system that develops a systematic blind spot for one defect type, a predictive maintenance model that misses a failure condition on a food safety component, AI-generated documentation that a regulator reads.
Monitoring, Auditing, and Testing
A metric, a frequency, an escalation threshold, and a named owner for every system in production. A bias finding that surfaces in litigation rather than in monitoring is a governance failure rather than a model failure. Covers what forecast accuracy has to be measured at to mean anything.
Incident Response
The playbook for when AI gets it wrong, starting with the distinction between a system that fails and a system that works exactly as built and produces a bad outcome. The manual fallback procedures matter most, and they have to be designed before the system goes live rather than during the incident.
Confronts the culture, change management, and capability-building challenges that determine whether a governance program becomes operational reality or remains a document no one follows.
Building an AI-Ready Culture
Governing shadow AI, and the quieter failure where a model runs clean long enough that people stop checking it. Opens with a demand forecasting system that ran well for eighteen months, after which the manual cross-checks lapsed and a systematic over-forecast went unnoticed for three months.
Change Management
Why a policy that lives in a document repository and gets reviewed annually is documentation rather than governance. Governance works when it is embedded in workflows people already follow. Legal and IT are critical enablers of a rollout and should not be its public face.
Examines the evolving regulatory environment, provides a maturity model for assessing organizational readiness, and shows why governed organizations deploy AI faster and at greater scale than ungoverned competitors, which makes governance a differentiator in valuation, positioning, and execution.
The Regulatory Landscape
The regimes reaching consumer goods uses of AI, including the EU AI Act's risk-based classifications and the conformity assessment, risk management, data governance, transparency, and human oversight duties that a high-risk designation triggers. This is the chapter the Regulatory Record keeps current between editions.
AI Governance Maturity Model
A staged model for assessing where an organization actually is. Stage two, Reactive, is the common resting point: policies exist and have been communicated, a Governance Council has been established, and reviews still reach only high-visibility deployments or the ones Legal flagged.
Why Governed Organizations Win
Scale, from pilot to enterprise-wide deployment. The argument runs through two versions of the same board meeting. In the governed organization the questions already have documented answers and approval takes days or weeks. In the ungoverned one, Legal raises liability no one has assessed and the sequence restarts.
Front matter and appendices
For the Executive With Five Minutes
The problem, the cost of governance failure with the loss ranges attached to each mode, and the solution, in four pages. Written for a reader who will not get to page 100.
Introduction
Opens at 2:00 AM with a procurement agent that has committed $847,000 to a fraudulent vendor, then moves to a 6:00 AM call where a co-manufacturer's AI quality system has been auto-approving batches for three weeks and a consumer has found metal fragments. Carries the reference map reproduced above.
Next Steps
Every chapter closes with actions you can start immediately. Appendix A consolidates all of them into one reference organized for retrieval. An asterisk marks the core subset, which is the minimum viable governance foundation and the work of a first ninety days.
Glossary
Definitions for the technical terms, AI concepts, and regulatory bodies used throughout the book. Written for an executive reader rather than a specialist one.
Sources
Full citations for every named company, regulatory action, research finding, and figure in the text. Named examples are drawn from public reporting and cited there.