Increasingly complex and overlapping new technology regulations are causing ‘digital entropy’ for businesses, according to a new report from the International Association of Privacy Professionals (IAPP).
The Organizational Digital Governance Report 2024 highlights the impact that the development and integration of emerging technologies is having on companies, with most having difficulty adapting their governance to the stream of changes.
According to the report, firms’ governance and compliance frameworks are being stretched by increasingly complex and overlapping regulations, making it harder to integrate emerging technology, such as AI.
That’s resulting in “digital entropy,” with businesses unable to take full advantage of technology due to uncertain, often overlapping rules coming from different directions.
In their report, the IAPP identifies a “matrix” of digital governance and compliance requirements, spanning cybersecurity, AI governance, online safety, content moderation, privacy and data protection.
As technology is developed and becomes widely used, incoming laws and regulations means businesses have to adapt to suit requirements for national security, law enforcement, intellectual property, as well as competition and antitrust laws.
As a result, security and privacy teams are under increasing pressure to expand their roles, often into areas beyond their usual expertise. Without a unified strategy for managing digital regulations, organisations are left vulnerable to compliance risks.
Notably, the study found that C-suite leaders for specific domains are adding more responsibilities to their own functions, which often fall well outside their remits.
For example, 69% of chief privacy officers surveyed have acquired additional digital governance responsibilities for AI, while 69% are responsible for data governance and data ethics, 37% for cybersecurity regulatory compliance, and 20% for platform liability.
That trend continues at a team level, with over 80% of privacy teams gaining digital governance responsibilities that extend beyond privacy, while 55% of privacy professionals work in functions with AI governance responsibilities.
More than one in two (58%) of privacy professionals also picked up data governance and data ethics responsibilities, and 32% cover cybersecurity regulatory compliance. Meanwhile, almost one in five (19%) have platform liability responsibilities.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- IT Leaders Split on Generative AI’s Role in Cybersecurity
- Cyber Leaders Reveal Compliance and Boardroom Struggles
To address the problem, the IAPP says that firms should establish clearer, better defined digital governance models. That could have a number of benefits, including improved digital strategies, greater transparency and visibility in decision making, and improved coordination across digital governance subdomains.
“There is massive disorder and a lack of structure in both the private and public responses to the litany of emerging digital risks and requirements,” said IAPP president and CEO, J. Trevor Hughes.
“Organisations have recognized the growing gaps in governance and now must prioritise appointing leadership to steer their response.”





