
The standard critique of data governance is that it is slow, bureaucratic, and unable to keep pace with the business. That critique describes a symptom accurately and mistakes it for a cause. The underlying problem is arithmetic. Governance programs asked part-time people to sustain full-time vigilance across a data estate that kept growing. Agentic AI is the first development to change that math.
In a recent episode of AI Radicals, host Satyen Sangani spoke with Erin McIntosh, VP of Global Data Operations at CNA Insurance, about rebuilding a global governance program at the moment agentic execution became viable.¹ McIntosh leads governance, analytics, and third-party data strategy across the United States, Canada, and Europe for one of the largest U.S. commercial property and casualty insurers.²
Key takeaways
In McIntosh's experience at CNA, data stewards typically move on after about two years, and stewardship rarely occupies more than roughly 20% of anyone's capacity while they hold the role.¹
CNA is targeting three areas first for agentic governance: stewardship and data ownership, compliance interpretation, and catalog-based quality insight.
Prototyping cycles that used to take three months now run one to three days, which raises both the value and the cost of moving fast.
Before a pilot moves toward production, McIntosh asks for a target outcome, an explicit control condition, a cost to scale, and evidence of business-partner buy-in.
ROI does not show up in data team output. It shows up in reduced cycle times, better underwriting decisions, and improved claims experience.
Why governance programs stall
Ask why governance has underdelivered and the usual answer involves culture or executive sponsorship. McIntosh points somewhere more concrete: the steward role itself.
Stewards are appointed, definitions get written, quality rules get documented, and attention decays. Getting stewards to buy in, to develop rules and definitions, and to stay in the role is, in her description, simply a hard job, and after about two years they typically move on. It is also rarely anyone's whole job while they hold it, running closer to a fifth of their capacity.¹ A governance model built on that arrangement is fragile by design, not because people are unwilling. The strain she describes is widely felt: only 23% of IT leaders say they are very confident in their organization's ability to manage security and governance when deploying generative AI tools.³
The failure shows up as a trust problem. McIntosh described a scene from early in her career: insurance adjusters reviewing reports, each with slightly different numbers, each having learned through experience which version to rely on. "This isn't just a data problem, and it wasn't just a reporting problem, and it wasn't just a technology problem," she told Sangani. "It was a trust problem."¹ Her conclusion is the part worth keeping. Once trust is gone, people do not stop working. They build their own version of reality.
Why governance is a defensible place to start with agents
There is some irony in governance being well positioned for AI. The characteristics that earned it a reputation for bureaucracy are the same ones that make it tractable for agents.
"Governance historically was very much process based," McIntosh said. "That lends very well to AI or agentic-led governance."¹ Monitoring lineage, flagging anomalies, applying a compliance framework consistently, checking whether metadata is complete: rule-bound, repetitive work performed against a surface too large for a human team to traverse on a useful cadence.
The risk calculus is the other half of the argument. Where governance coverage does not yet exist, the comparison is not agent against expert human. It is agent against nothing. "The risk of doing something is better than not doing anything in this space," she said, adding that she hates saying it.¹ She also fences the work carefully: internally focused, scoped to governance channels, with more human direction at the start and the ability to toggle that back as confidence builds. CNA operates in a conservative industry, she notes, and other functions are moving more cautiously.
Gartner reached a similar conclusion from the finance side, advising leaders to treat the first agent as a governance pilot rather than an ROI pilot, because early pilots fail on unclear controls rather than on the technology — and to start where errors are visible and reversible.⁴
The asymmetry is what makes this a beachhead. A governance agent that misfires can be corrected, and the rules it works from can be rewritten. AI built on ungoverned data fails in ways that are considerably harder to unwind.
The cockpit CNA is building toward
McIntosh's structural complaint about governance technology is fragmentation. Lineage, quality, metadata, and compliance have historically lived in separate tools, with no straightforward way to assemble them into a view of governance as a single process. Whatever synthesis happened, a steward did by hand, which is part of why the role has been so hard to sustain.
What she wants instead is a cockpit: one place where those signals converge, where agents surface anomalies and route them onward, and where steward capacity goes to judgment rather than collection. CNA is building that layer on top of its data catalog and existing lineage. Three areas are first in line: stewardship and data ownership, where agents support stewards and in some cases perform the function directly; compliance interpretation across GDPR, secrecy acts, and comparable regimes, an area where privacy obligations multiply with every jurisdiction; and catalog and quality insight, serving quality signals and critical data element context into stewardship workflows and onward to agents that can act on anomalies.
Each involves continuous, rule-bound execution where automation pays off quickly, and each fails recoverably.
The question most pilot reviews skip
The most rigorous thing McIntosh said was also the briefest. Before anything moves toward production, she asks what the control is that it is being compared against.
Her full test has four parts:
A named target outcome. Efficiency, improved decision quality, something specific. Not a pilot for the pilot's sake.
An explicit control condition. CNA applies this to build-versus-buy directly, developing a capability internally and running it against a third-party option on the same data quality problem.
A cost to scale. What production actually takes, once the prototype works.
Business-partner buy-in. Whether the people who would use it will accept and adopt it.
The discipline is not academic. Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls — the same three gaps her four questions are built to close.⁵
Speed makes this discipline more necessary. Work that took three months now takes one to three days, which changes how much a team can produce and how quickly it can get somewhere bad.¹ Her answer is time-boxing and an agreed definition of done. Asked what companies should stop doing immediately, she named focusing on the pilot instead of how to scale the solution, and seeking perfection instead of progress.
Automating a decision and improving one pay differently
The distinction that travels furthest beyond governance concerns what AI is pointed at.
Most initiatives aim at throughput. That ceiling is low. "Automation just gets you efficiency," McIntosh said. "That's all it's going to do for you. It doesn't actually improve the financial components to your organization."¹
Decision improvement is the higher-value target: bringing more context to the moment of decision so the decision itself changes. CNA runs both, typically starting with efficiency because the expected outcome is known and measurable, then moving toward quality as comfort grows.
This reframes measurement. Data organizations do not generate value on their own, since data for its own sake solves nothing. Real return shows up as reduced cycle times, improved underwriting decisions, and efficiencies in claims customer experience. She is equally clear that attributing it is difficult, and that the sharper open question is quantifying the cost of poor quality data as delivery speed increases.
Her best line lands on code review. Teams are asking whether agents can review data product development and BI output. They can, she says, then asks the better question: why not have the agent write to the standard correctly from the beginning, so the review is unnecessary?
Trust, not tooling, is the constraint
McIntosh expects natural language querying, insight generation, and graphical recommendation to change ad hoc analysis substantially. CNA is piloting copilot-assisted dashboard development with people who have never built one, with AI for BI work starting next quarter. She also expects structured reporting to survive, because standardized monthly and quarterly packages in insurance need to be pixel perfect. And she offers a calibration point worth sitting with: the industry once expected PowerPoint to die at the hands of visualization tools, and it did not.
Adoption resolves on whether people trust the data behind the interface and whether the tool returns consistent answers to the same question. That is the real gate.
Within eighteen months, McIntosh commits to CNA's governance body being stood up globally and agentically led, with tighter coupling between security, compliance, regulatory, data governance, and AI governance, and a shift from producing more information toward producing less of it at higher quality, close enough to the decision that someone can act.¹ She will not forecast five years. Three is the most anyone gets from her, and her metaphor for planning right now is building on quicksand.
Asked which belief about governance is simply wrong, she picked the one everybody repeats: that governance is slow. Good data governance, in her formulation, is effective. Bad data governance is what is slow and burdensome.¹ The distinction matters more now, because agentic execution finally makes the good version affordable at scale.
Curious how Alation's data governance and data products capabilities can support an agentically-led program? Book a demo with us today.
Sources & notes
Every external claim on this page is independently verifiable. The public sources are listed here.
All McIntosh statements and quotations, including the two-year steward tenure and ~20% capacity figures, the process-based governance and "risk of doing something" quotes, the three-months-to-three-days compression, the automation-versus-decision-improvement quote, the eighteen-month commitment, and the good-versus-bad governance formulation. Full timestamped transcript available on the episode page. — AI Radicals, "Rewriting the Governance Playbook for the Agentic Era with Erin McIntosh, VP of Global Data Operations at CNA Insurance," 12 August 2026 ↗ https://www.alation.com/podcast/episodes/governance-playbook-erin-mcintosh-cna-insurance/
CNA describes itself as one of the largest U.S. commercial property and casualty insurance companies, operating in the U.S., Canada and Europe. — CNA, "About CNA" (accessed 21 August 2026) ↗ https://www.cna.com/about
Only 23% of IT leaders surveyed said they were very confident in their organizations' ability to manage security and governance when deploying GenAI tools (survey of 360 IT leaders, Q2 2025). — Gartner, 16 April 2026 ↗ https://www.gartner.com/en/newsroom/press-releases/2026-04-16-gartner-says-organizations-with-successful-ai-initiatives-invest-up-to-four-times-more-in-data-and-analytics-foundations
Treat the first finance AI agent as a governance pilot rather than an ROI pilot; early pilots are most likely to fail due to unclear controls, not poor technology; begin with a low-risk, contained workflow where errors are visible and reversible. — Gartner Q&A with Alex Levine, 20 August 2026 ↗ https://www.gartner.com/en/newsroom/new/pr-q-a-new-vis-template/2026-08-20-gartner-says-cfos-mus-pilot-governance-first-before-scaling-ai-agents
Over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls. — Gartner, 25 June 2025 ↗ https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
ANALYST ATTRIBUTIONS & DISCLAIMERS
Gartner, "Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027," Anushree Verma, 25 June 2025.
Gartner, "Gartner Says Organizations with Successful AI Initiatives Invest Up to Four Times More in Data and Analytics Foundations," Rita Sallam, 16 April 2026.
Gartner, "Gartner Says CFOs Must Pilot Governance First Before Scaling AI Agents," Q&A with Alex Levine, 20 August 2026.
Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. GARTNER and Magic Quadrant are registered trademarks and service marks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.
- Customer Stories
- Data Governance
- Data Quality
- Digital Transformation
- Enterprise Data Catalog
- Modern Data Stack
- AI
Keep reading
More from the data desk



