It was great to be part of the GRC Conference 2026 in San Diego last week, hosted by ISACA and the Institute of Internal Auditors. The conference brought together more than 50 speakers and 65 exhibitors to share their knowledge insights covering emerging risks, evolving regulations and GRC fundamentals.
AI is the dominating theme across conference agendas this year, and the GRC Conference was no exception. While many sessions focused on AI, both as threat and opportunity, the defining message from GRC Conference 2026 was one of convergence.
AI governance, data governance, cybersecurity, privacy and assurance are increasingly interconnected, pushing organizations toward a more continuous and data-centric approach to managing risk.
Four takeaways for AI, data and risk leaders
1. AI governance is moving from policy to operational accountability
The ever-present AI debate is evolving, and is beginning to advance beyond acceptable-use policies and AI principles into operational reality. Risks are materializing as incidents and governance teams are struggling to establish the oversight they need to adequately identify where key exposures exist.
Organizations now need to define who owns AI-supported decisions, how those decisions can be explained and how controls can be evidenced. Agentic AI raises the stakes further by introducing systems that can act with greater autonomy, lacking human interaction at each step of decision-making processes.
2. Data governance is becoming the foundation for AI, privacy and cyber risk management
Across the conference, many apparently separate GRC challenges converged on the same dependency: understanding the data involved. Organizations need visibility into what data they hold, where it resides, how sensitive it is, who can access it, how it is used and where it flows.
This was the core theme of our session, “Data-Centric Governance in the Age of AI.” Delegates can review the session in the event app or via the Attendee Hub.
Weak data foundations make AI governance, privacy compliance and security assurance harder to sustain.
3. Continuous assurance is replacing point-in-time GRC
Annual reviews and static control assessments are increasingly mismatched to cloud, AI and rapidly changing technology environments. Organizations need to migrate toward continuous monitoring for more current evidence of control effectiveness and faster identification of emerging exposure.
GRC teams need to be able to show how risk is changing, rather than simply whether a control existed at the last assessment. Meanwhile, audit teams and external assessors are increasingly focused on evidence that demonstrates control effectiveness over time, not just its presence.
4. GRC is becoming more integrated, resilience-focused and decision-led
Cybersecurity, privacy, enterprise risk, compliance and internal audit are becoming less effective when managed as separate disciplines. Deepfakes, third-party dependencies, quantum risk and AI all cut across traditional organizational boundaries.
The model that is emerging in response to this dynamic threat environment is more coordinated assurance, clearer accountability and risk information designed to support business decisions, built on a robust foundation of data intelligence.
Ground Labs helps organizations turn these governance priorities into practical action by providing the data intelligence they need to understand where sensitive and high-value data resides across cloud, on-premises and endpoint environments.
By discovering, identifying and classifying data at scale, organizations can strengthen AI governance, reduce privacy and security exposure, support continuous assurance and give risk teams a more accurate foundation for decision-making and risk management.