This is the first episode in our Forrester Technology and Innovation Forum series, recorded live in Austin, Texas. Over the coming months we will be sitting down with Forrester analysts and their clients at the Forums in Austin, London and New York.Graeme Scott opens the series with Alla Valente, Principal Analyst on Forrester's security and risk team, who covers governance, risk and compliance, third party risk, contract lifecycle management and, increasingly, all of the above as they collide with AI.Alla is asked the question every board is asking, which is whether AI is simply the next emerging technology. Her answer is no, and the reason is specific. With SaaS and cloud, organisations chose whether to adopt, when, where in the business and who got access. That choice no longer exists. AI is already inside your organisation whether you have a strategy for it or not. As she puts it, not having an AI strategy is a strategy. It is just not a very good one.From there she draws a distinction most organisations have not yet made. AI governance is a function. It is your policy, your charter, your process for deciding which use cases are acceptable. Governing AI is the execution of that, and it happens through compliance, risk management, security and responsible AI. Organisations reached for governance first because enterprise risk management was not mature enough to move at the speed AI demanded, and the gap between the document and the delivery is where the exposure sits.She is equally direct on third party risk. Almost nobody is building their own models. You are buying foundation models, buying data, using open source, which is also a third party. AI arrives through the ecosystem, and third party risk management in most organisations is deprioritised, federated and underfunded compared with enterprise risk.The section enterprise leaders should sit up for is contracts and concentration. Organisations are using AI to contract faster, but they have not contracted for AI. Most contracts still say nothing about model training, data access, who is responsible when there is an incident, who fixes it and what the recourse is. Her line on this is the sharpest in the episode: contracts are your AI guardrails that have teeth, and they are the only ones that do. Alongside it sits concentration risk. If your business runs on one provider's model and something makes that model unusable, how long is the disruption and how much can you absorb? Map it before the crisis, not after.