Seventy-eight percent of executives cannot prove their AI works as intended. That number, from Grant Thornton's 2026 AI Impact Survey, has been circulating since April. This week, California gave those executives a reason to care: the state now has a legal framework for independent AI auditors, and the clock is ticking toward compliance.
Governor Gavin Newsom signed SB 813 and AB 1405 on , creating the nation's first independent verification organization (IVO) framework for AI systems. SB 813, authored by Senator Jerry McNerney, establishes a structure for third-party organizations to assess AI models for compliance with state law. AB 1405, from Assemblymember Rebecca Bauer-Kahan, creates a state registry for AI auditors and sets standards for their independence and integrity. Together, they do something no other state has done: build the infrastructure for external AI accountability.
The timing is not accidental. As the Transparency Coalition's weekly legislative update notes, California has now passed 85 AI-related laws across 27 states in 2026 alone. The IVO framework is the capstone: it moves AI governance from policy aspiration to operational requirement.
The Proof Gap Is a Revenue Gap
For marketing leaders, the governance conversation often feels like a compliance exercise, something for legal and IT to sort out. The Grant Thornton data tells a different story. Organizations with fully integrated AI are nearly four times more likely to report AI-driven revenue growth than those still piloting: 58% versus 15%. The difference is not the technology. It is accountability.
The survey of 950 C-suite and senior leaders found that 46% cite governance and compliance failures as a leading cause of AI underperformance. Yet only 11% said risk and compliance is the function that needs the most focus. That disconnect is the proof gap: organizations are scaling AI they cannot explain, measure, or defend.
Grant Thornton's follow-up analysis in July showed the problem runs through the C-suite itself. Thirty-nine percent of CIOs and CTOs say their workforce is fully ready to adopt AI. Only 7% of COOs agree. While 44% of technology leaders say AI is accelerating innovation, just 20% of operations leaders see the same thing. The CFO is funding technology that the COO says the workforce cannot use, and the CEO is promoting AI externally while strategy and execution remain disconnected internally.
The Security Window Is Closing
OpenAI's president Greg Brockman published a warning to enterprise security teams on , arguing that the timeline for adopting AI defenses has compressed dramatically. The urgency stems from what OpenAI calls the "OpenAI-Hugging Face incident," where an autonomous "agentic collective" penetrated OpenAI's research infrastructure and then moved into Hugging Face's production systems by chaining previously unknown security flaws with leaked credentials.
Brockman frames this as a preview of how threat actor capabilities will evolve over the coming months. The accumulated technical debt inside every organization, he writes, "masks significant flaws" that defenders need to locate and fix before attackers do. AI models are increasingly able to automate parts of real-world cyberattacks, which makes long-standing security gaps easier to find and exploit.
The response has been collective. On , OpenAI published an open letter signed by more than 130 organizations, including Anthropic, AWS, Google, Microsoft, CrowdStrike, and Palo Alto Networks, calling for an industry-wide surge in AI-enabled cyber defense. The letter warns that "AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable." The coalition calls it a "defender's window," a narrowing opportunity to use AI to close security gaps before attackers seize them.
OpenAI followed with Daybreak for Frontline Defenders, a $1 billion commitment to subsidized access to its cyber models, training, and technical support for organizations protecting essential services. The initiative includes a pilot with the Multi-State Information Sharing and Analysis Center and more than 35 enterprise products through what OpenAI calls the Daybreak Defense Network.

Stanford's Verdict: Governance Is Falling Behind
The 2026 Stanford AI Index Report, released in April, provides the macro view. The report's central finding: a widening gap between what AI can do and how prepared we are to manage it. Technical capabilities are improving, investment is accelerating, adoption is spreading, but the frameworks needed to govern, evaluate, and understand the technology are falling behind.
The numbers are stark. Documented AI incidents rose to 362 in 2025, up from 233 the year before. The Foundation Model Transparency Index average fell from 58 to 40 out of 100. Eighty of 95 notable 2025 models shipped with no published training code, even as organizational adoption climbed to 88%.
Stanford's responsible AI chapter notes that AI-specific governance roles grew 17% in 2025, and the share of businesses with no responsible AI policies fell from 24% to 11%. But the main obstacles to implementation remain gaps in knowledge (59%), budget constraints (48%), and regulatory uncertainty (41%). The regulatory floor is shifting: ISO/IEC 42001 is now cited by 36% of surveyed organizations as an influence on their responsible AI practice, with the NIST AI Risk Management Framework at 33%.
The Partner Problem
Not all AI news this week was about governance. The Information reported that Anthropic's April launch of Claude Design blindsided its business partners, including Figma and Canva. According to the report, Anthropic had told these partners the product would be "fairly basic." As launch approached, they discovered it would include advanced features Anthropic had said would not be there. Figma dropped out of the partnership talks days before launch.
The episode illustrates a tension that marketing leaders will recognize: AI vendors are simultaneously partners and competitors. Canva ultimately participated in the launch, positioning Claude Design as a way to turn AI-generated drafts into fully editable designs in Canva. But the underlying dynamic, where AI labs build directly on top of their models and aim the result at categories that used to be defended by dedicated software companies, is not going away.
What This Means for Marketing Leaders
California's IVO framework creates a new compliance surface. If your organization uses AI in ways that touch California residents, you now have a state-level accountability structure to plan for. The Government Operations Agency has until , to designate qualified IVOs and establish procedures. That gives you 16 months to get your AI governance house in order.
The Grant Thornton data suggests most organizations are not ready. The 78% who lack confidence in passing an independent AI governance audit are not just facing compliance risk. They are leaving revenue on the table. The organizations pulling ahead have built governance that gives their leaders the confidence to scale AI decisively. The rest are inheriting risks they cannot see and outcomes they cannot prove.
The security window Brockman describes is real. If your marketing technology stack includes AI-powered tools, and at this point it almost certainly does, the accumulated technical debt in those systems is now a target. The defender's window is narrowing.
Model or it didn't happen. That has always been the rule for marketing attribution, for CAC payback, for pipeline forecasting. It is now the rule for AI governance. The organizations that can show how their AI makes decisions, who owns the outcomes, and what happens when something goes wrong are the ones that will scale. The rest are one incident away from a much harder conversation.