Resurgens Technology Partners LLC

08/25/2026 | Press release | Distributed by Public on 08/25/2026 07:47

AI in Practice: Security, Governance, and Risk Management

Governance is usually the part of the AI conversation everyone agrees matters, and the part that gets the least airtime. Teams are moving fast on AI, and the questions around security, legal, and access tend to get answered later than they should.

In this session, Stephen Joy and Andrew Schremp from Resurgens' operations team focus on the first pillar of the AI framework covered in our initial discussion (you can find the recording here), security, governance, and risk management. They walk through:

  • Where cybersecurity and legal exposure tend to show up first
  • How developer access, finance approvals, and IT ops fit into the picture
  • Real examples of what's worked, and what hasn't, across our portfolio, including content you can hand off to your AI / IT owners

Key Takeaways

1. Naming an owner isn't optional, it's the difference between a program and a document.

The portfolio companies that made real progress on governance had one thing in common: a named leader with actual authority over the program, paired with a team that understood the AI tools well enough to spot real risk. Without that person in place, governance becomes a check-the-box exercise, an AUP that gets signed and forgotten. Give someone ownership and agency, and the rest of the program can build from there.

2. AI governance isn't a new discipline, it's your old governance program under new stress.
The concepts aren't foreign to anyone running a software business. What's changed is that employees now have the ability to connect tools and data in ways your existing programs never accounted for. Treat this as extending the perimeter you already have, not building something from scratch.

3. Diligence has caught up to AI, and it's not going away.
AI governance/security has become part of the core diligence workstream when raising capital or selling a software business. A weak program can cost real points on your multiple at sale. A strong one is still a differentiator today, but that window is closing as it becomes table stakes.

4. Start with a 30,000-foot view before you write a single policy.
Before building anything, get a full inventory of what tools your team is actually using, including personal accounts you haven't sanctioned. That baseline is what an effective Acceptable Use Policy gets built on: a tool inventory, a green/yellow/red risk-tiering system for data access, and training tied directly to the policy. Skip the inventory and you're governing blind.

5. Spend without an ROI lens is just spend.
Putting a framework to determine/measure ROI on AI projects is becoming increasingly important as usage becomes matures at organizations and model costs continue to rise. The measurement characteristics can be vague at times, but the companies that take the time to put measurement/visibility infrastructure in place have shown to be more focused, productive and efficient.

Quotes

"AI governance isn't really different from existing governance. It's just that there are cracks in your programs, accentuated by the fact that team members now have more capabilities than ever to connect data you didn't expect them to connect."
- Stephen Joy, VP of Portfolio Operations

"If data is a new moat, and it is, you don't want your data slipping out into the wild west into these different LLMs."
- Andrew Schremp, Operating Executive

Resurgens Technology Partners LLC published this content on August 25, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 25, 2026 at 13:47 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]