AI governance asks what a model was trained on, whether that data was permitted for the purpose, who approved deployment, what the model is monitored for, and who can switch it off. Four of those five questions are answered by data lineage, classification, consent records and ownership. That is why an organization with no data governance cannot have AI governance: there is nothing underneath it to appeal to.
In practice. The fastest route to defensible AI governance is to extend what exists. Add "approved for model training" to the classification scheme, require lineage for training datasets, put model approval on the existing council agenda, and log the decision. That is weeks of work rather than a new program.
Where it goes wrong. AI governance is built as a parallel structure with its own committee, policy set and vocabulary. Within a year it has a different owner and a different answer for the same dataset, and the first regulatory question exposes the gap. One set of decision rights over data, extended to models, is the arrangement that holds.