AI GovernanceAugust 16, 2026· 6 min read

12 AI Governance Questions CIOs Should Bring to Gartner IT Symposium 2026

Four days in Barcelona, hundreds of vendors, one estate to govern. Twelve questions — three per layer of control — that separate platforms which enforce from platforms which report, with the good answer and the dodge for each.

Umberto Malesci

Umberto Malesci

CEO & Co-Founder


Four days in Barcelona. Hundreds of exhibitors, dozens of them selling something called AI governance. If you are a CIO or Chief AI Officer walking Gartner IT Symposium/Xpo 2026 with an agent programme behind you and a board mandate in front of you, the floor is not a shopping problem — it is a filtering problem. (Kosmoy is exhibiting; here is where to find us and what we'll show.)

The fastest filter we know is a fixed set of questions, asked identically at every booth, scored on the answers rather than the demos. Below are the twelve we would bring — three for each layer of control an enterprise AI estate needs. For every question: why it matters, what a good answer sounds like, and what a dodge sounds like.

One rule before the list: a yes without a mechanism is a no. Governance vendors rarely say "we can't." They say "we integrate," "that's on the roadmap," or "our dashboard shows that." The twelve questions are designed so those answers stand out.

Twelve questions, four layers of controlTwelve CIO questions grouped into the four layers that answer them. Inventory: everything listed, owners named, shadow AI found. Monitoring: traces replayable, cost attributed, quality evaluated. Governance: one policy point, guardrails apply, approvals recorded. Action control: runtime boundary, kill switch works, evidence produced.INVENTORY01Everything listed02Owners named03Shadow AI foundMONITORING04Traces replayable05Cost attributed06Quality evaluatedGOVERNANCE07One policy point08Guardrails apply09Approvals recordedACTION CONTROL10Runtime boundary11Kill switch works12Evidence produced
Twelve questions, four layers. A vendor that answers one column is a point tool; the estate needs all four.

Register: questions 1–3

1. Can you list every model, agent and MCP server we run — including the ones you didn't build?

Why it matters: every control downstream assumes an inventory. Most tools inventory what passes through them, which is not the same thing.

A good answer names harvest sources — Microsoft, AWS, Google, Salesforce, ServiceNow, internal runtimes — and a record shape with owners and lifecycle states. A dodge shows you a list of the vendor's own deployments and calls it your estate. The practice is buildable before you buy anything: our master AI agent registry page describes the record model, and the 30-day inventory plan is the working version.

2. When the inventory and reality disagree, which one wins?

Why it matters: an inventory that is not reconciled against what actually runs is a spreadsheet with confidence. The interesting agents are precisely the ones nobody registered.

A good answer describes reconciliation — discovered agents matched against approved use cases, unmatched entries flagged and routed to review. A dodge is "teams register their agents in our portal." Shadow AI does not fill in portals.

3. Does every entry have a named owner who knows they own it?

Why it matters: when an agent misbehaves at 2 a.m., the registry either produces a phone number or it produces a meeting.

Good: owner and business unit are mandatory fields; orphaned entries block approval. Dodge: "ownership is configurable."

Observe: questions 4–6

4. Show me one full trace — retrieval, tool calls, policy decisions included.

Why it matters: when quality drops or a regulator asks why did the system say this, you need to replay the decision, not the metric. Monitoring tells you something broke; observability is the evidence for why.

Good: a span-level trace carrying the guardrail decisions and the cost, not just the timings. Dodge: a dashboard of averages.

5. Can you attribute AI spend to team, application, use case and agent — including failed calls?

Why it matters: the provider invoice is one number per API key. Every retry, every looping agent, every prompt that quietly doubled is invisible in it. AI FinOps is a per-call discipline or it is bookkeeping.

Good: attribution stamped on each request in the path. Dodge: "we import your billing exports" — useful, but it cannot see a failed call or stop a running one.

6. Are production interactions sampled into evaluations — or does testing end at release?

Why it matters: models drift, prompts change, retrieval corpora rot. Release-gate testing ages out in weeks. Good: online evaluation scoring live traffic, with failed evals linking back to the traces that produced them. Dodge: a benchmark slide from the model vendor.

Govern: questions 7–9

7. Can one policy apply to every provider and cloud — changed once, enforced everywhere?

Why it matters: your estate is already multi-vendor, whatever the strategy deck says. Policy per platform means policy drift. Good: a gateway in the request path speaking one API across providers. Dodge: "we support all major clouds" (support ≠ enforce).

8. Where do guardrails run — in the request path, or in a report?

Why it matters: a PII filter that reads logs after the fact is an incident-detection tool. One that blocks in-line is a control. Good: input and output checks with block/redact actions, and a way to test them adversarially. Dodge: "we detect violations" — detection without an enforcement point is a to-do list.

9. Who approved this use case, and can you show me the record?

Why it matters: the EU AI Act made approval evidence a first-class artifact. Good: risk classification tied to the registry entry, approvals with timestamps and actors, re-review triggered when the model or tools change. Dodge: "we integrate with your GRC tool."

Contain: questions 10–12

10. Is there a boundary a compromised agent cannot escape?

Why it matters: prompts are advice; boundaries are physics. An agent with standing credentials and open egress is one injection away from being someone else's agent. Good: a runtime sandbox — in Kosmoy's case, the Action Capsule, where egress is physically limited to the paired gateway and credentials exist only for the run. Dodge: "our agents are instructed not to."

11. Can you stop one agent mid-run — without taking down everything around it?

Why it matters: the kill switch is the difference between an incident and an outage. Good: a per-agent stop that revokes credentials and closes egress, rehearsed, logged. Dodge: "you can disable the integration."

12. Can you produce audit evidence from operations — or do we rebuild it per audit?

Why it matters: evidence assembled by hand for each audit is expensive and stale by the time it is read. Good: EU AI Act, ISO/IEC 42001 and NIST AI RMF bundles generated from registry state and gateway logs — the same records operations already produces. Dodge: a services engagement.

Scoring the floor

Score each answer 0 (dodge), 1 (mechanism, no evidence) or 2 (mechanism plus evidence you could verify). Twelve questions, six minutes per booth, maximum 24. Vendors will cluster: point tools score well in one column and near zero elsewhere — which is fine if a column is all you need, and worth knowing if it is not. The pattern to watch is the vendor that answers the visibility questions fluently and goes quiet at questions 10–12. Watching is not governing.

If you want the longer version of this exercise, the CIO AI Control Checklist extends these twelve to forty questions across ten control areas — printable, ungated, scored the same way.

Bring the hard case to Barcelona

We will be on the expo floor all four days, 9–12 November. Bring your worst answer from the twelve — the question where your current stack scored zero — and we will show you, live, how the four layers close it: registry, observability and FinOps, gateway policy, containment. Book a meeting before the event — booth queues are real — or email sales@kosmoy.com with the days you are on site.

FAQ

What AI governance topics matter at Gartner IT Symposium 2026?

The questions CIOs are bringing to Barcelona cluster into four: do we know every model, agent and MCP server we run; can we observe cost and behaviour per system; can we enforce one policy across vendors; and can we stop an agent that misbehaves. Vendors on the floor answer some columns and not others — the gaps are the finding. For session details, use the official agenda on Gartner's site; this article deliberately covers the questions, not the programme.

How should a CIO evaluate AI governance vendors at a conference?

Ask the same short questions of every vendor and score the answers, not the demos. A good answer names a mechanism — a registry reconciliation, a gateway cap, a kill switch — and offers evidence. A dodge names a roadmap, a partnership or a dashboard. Twelve questions take about six minutes per booth.

Is Kosmoy at Gartner IT Symposium/Xpo 2026 in Barcelona?

Yes — Kosmoy is an exhibitor at the 9–12 November 2026 conference in Barcelona. The team demonstrates the master agent registry, gateway policy enforcement, AI FinOps with hard caps, evaluation and red teaming, and Action Capsule containment as one workflow. Meetings can be booked in advance.


Gartner and Gartner IT Symposium/Xpo are trademarks of Gartner, Inc. and/or its affiliates. Kosmoy is an exhibitor at the 2026 Barcelona conference. Gartner does not endorse Kosmoy or its products.

gartner-it-symposiumai-governanceagentic-aicio

See how Kosmoy works

Discover how enterprises govern, secure, and optimize AI at scale.

Or email sales@kosmoy.com.