AI & Data Governance Advisory

The real cost of ungoverned AI — and what to do about it

Mary Hartwell advises boards and enterprise leaders on where AI governance failures turn into balance-sheet events, and where the absence of governance is quietly the biggest brake on AI value capture. She turns the enforcement record and the deployment data into a practical case for acting now.

The case for governance

The governance gap is now a balance-sheet event

Regulators across three continents have shown both the willingness and the legal infrastructure to impose penalties that are material even to the largest technology companies. The pattern is consistent: organizations that could not show a documented AI or data governance program paid the most — and paid it in public.

€5B+
Total GDPR fines issued since the regulation took effect
EU regulators, as of mid-2026
€1.2B
Meta's single largest GDPR penalty, for unlawful cross-border data transfer
Irish DPC, 2023
7%
Maximum EU AI Act fine (of global turnover) for prohibited AI practices
EU AI Act, Regulation 2024/1689
$5B
FTC settlement precedent for undocumented third-party data governance
FTC v. Meta, 2019
"Air Canada is responsible for all representations made by its AI systems" — the court rejected the airline's argument that its chatbot was a separate legal entity, and awarded damages to the plaintiff. Moffatt v. Air Canada, British Columbia Civil Resolution Tribunal, 2024
The cost of delay

The other side of the ledger: what waiting costs

The research is just as clear in the other direction. Organizations don't stall AI because the technology fails — they stall because they have no governance framework they trust enough to let AI reach production. That hesitation has a price tag too.

54%
Share of AI models that ever reach production without a governance program
Gartner, 2022
2.3×
Faster deployment to production for organizations with formal AI governance
Accenture Responsible AI Study, 2023
56%
Of organizations cite lack of a governance framework as the top barrier to shipping AI
McKinsey Global AI Survey, 2023
$15.7T
Projected AI contribution to global GDP by 2030 — concentrated among those who scale
PwC Global AI Study
"Governance is not a constraint on AI deployment velocity. It is the mechanism by which AI velocity is sustained." Accenture, Responsible AI Research, 2023
MH

Mary Hartwell

Global Data & AI Governance Executive

Global Practice Leader who has built data governance programs from zero at United Technologies, II-VI, Axiall, and Syniti — 2026 Data Governance Solution of the Year award winner, and published author on AI readiness and data governance.

About Mary

A speaker who leads with the evidence, not the hype

Mary Hartwell has spent her career building data governance programs at some of the world's largest enterprises — not frameworks on a shelf, but operating programs with councils, stewardship structures, domain governance, and teams who know how to run them. She founded the Data Governance Council and Data Governance Office at United Technologies, built the MDM and governance team from scratch at II-VI, and most recently led Syniti's global Data Governance practice across three regions. Before that, she spent five years inside IBM's most complex SAP S/4HANA transformation programs, running data migration and master data governance on timelines that couldn't afford bad data.

Her thesis, sharpened across two decades in the field: governance isn't a compliance project — it's the infrastructure that makes AI, analytics, and transformation possible. Companies that want to do AI well have to get their data right first. Her writing on data governance, AI readiness, and data literacy has appeared in NODE Magazine, the Syniti Blog, Connectivity for IR, and TechNovice, and her work was recognized with the 2026 Data Governance Solution of the Year Award.

Connect with Mary on LinkedIn →

Why now

The regulatory window is closing

The rules governing high-risk AI are no longer hypothetical — they are on the calendar.

August 2024

EU AI Act enters into force, establishing the first comprehensive AI-specific enforcement regime.

February 2025

Enforcement begins on prohibited AI practices — social scoring, real-time biometric surveillance, subliminal manipulation.

August 2026

High-risk AI compliance obligations take effect: conformity assessments, technical documentation, audit logs, and human oversight required for HR, credit, healthcare, and education AI systems.

2027 and beyond

Notified-body conformity assessments and anticipated US federal AI legislation raise the bar further — organizations that govern early set the baseline; those that wait play catch-up.

Bring the research to your boardroom or stage

Mary Hartwell speaks to boards, executive teams, and industry audiences on what AI governance actually costs to skip — and what it earns when done well.

hello@hartwellandcompany.com