Confident female manager holding laptop leaning on wall with team of colleagues collaborating in background

EY US AI Risk and Governance Survey

AI governance has entered its next phase: closing the confidence gap

Governance has moved from aspiration to operating model, but maturity is uneven.


Most large organizations have established the foundations of responsible AI. Policies are in place. Oversight committees have been formed. Reviews, controls and human oversight are becoming part of the enterprise operating model. 

But as AI adoption accelerates and autonomous agents begin taking actions across business processes, a more consequential question is emerging … 

Can governance keep pace? 

The inaugural Ernst & Young LLP (EY US) AI Risk and Governance Survey of more than 200 US senior AI decision-makers at publicly traded companies with at least $1 billion in annual revenue reveals a widening gap between governance design and operational confidence. 


EY US AI Risk & Governance Survey


A young man leans forward as he explains his idea, using thoughtful gestures while teammates listen across the collaborative workspace.
1

Chapter 1

Building a foundation of AI governance

Nearly all respondents (98%) report their organization having formal AI governance policies in place, and 69% say their organization has a fully unified AI governance policy in place. Yet 69% are concerned that their organization lacks the internal expertise needed to effectively keep evolving its AI governance controls. About half (47%) say their organization has previously bypassed its AI governance process for urgent deployments.


A man and woman sit together in a booth at a workplace, discussing work on a laptop. The space is cozy, designed with colorful partitions. Another professional is seen walking in the foreground.
2

Chapter 2

Agentic AI raises the stakes and the margin for error

Agentic AI raises the stakes further. Among respondents whose organizations use agentic AI, 85% say they have at least a handful of agentic AI systems in their organization executing activities such as running code, placing inventory orders or detecting cybersecurity incidents without real-time human intervention. However, 49% of those whose organization uses agentic AI say their existing governance framework has not yet been specifically updated to include agentic AI risk and requirements, while 26% cannot detect unauthorized AI agents operating internally.


The biggest agentic AI risk is that human oversight hasn’t evolved accordingly. AI governance provides the necessary guardrails that allow organizations to move quickly without losing control, especially when agentic AI is already making real business decisions.
Confident middle-aged man wearing glasses and a suit sitting at a desk with a laptop, appearing thoughtful and focused in a bright, open-plan office setting.
3

Chapter 3

Cybersecurity is where AI governance is tested

Cybersecurity provides another test of whether governance works in practice. Eighty-nine percent of senior AI decision-makers report encountering AI-related risks during the past year, yet 41% say senior leaders do not have visibility into all AI tools currently operating within their organization. About a third (36%) say their organization has experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, operational disruption and brand damage.

Senior AI decision-makers are clear that the consequences of AI incidents can be material, raising the stakes for effective governance and resilience, particularly as AI becomes more embedded in regulated workflows and cyber-sensitive business processes. According to the findings, 81% say they are concerned about a third-party AI-enabled cyberattack compromising AI tools, while 72% are concerned about their organization failing to comply with new or emerging AI-specific regulations.

A diverse team of young professionals discussing business strategies around a conference table equipped with laptops and documents in an office meeting room.
4

Chapter 4

Governance has been designed, but has not yet been operationalized

There’s a broader pattern reflected throughout the survey: organizations know they need stronger controls, but they are less certain those controls can keep pace with the risk environment they are now expected to manage. This is a confidence gap with their ability to match the pace of governance with AI ambitions.

As the use of AI expands, and as agentic systems take on more autonomous activity, the ability to demonstrate control effectiveness becomes as important as the control itself.

Organizations are applying yesterday’s governance rules to today’s interactions with AI. Boards and C-suites are under immense pressure to accelerate their AI adoption and implement agentic AI systems. In haste and without proper governance in place, they may create significant risk of reputational, financial and operational damage.
Korean businesswoman and her male colleagues working on laptop in the office. Copy space.
5

Chapter 5

Formal AI reviews are surfacing gaps and prompting action

The research points to the growing importance of independent assurance. Although 98% of respondents said their organization conducts a formal AI assurance review at least annually, 92% of those conducting formal AI assurance reviews found issues. After a formal AI assurance review, organizations modified, paused or stopped AI systems, evidence that assurance is not simply validating existing controls but surfacing risks that require action.

Person presenting to colleagues during a meeting in a modern office conference room.
6

Chapter 6

Closing the confidence gap

The next phase of AI governance will be less about writing policies and more about demonstrating that they work. Leaders need visibility across the full AI estate, clear accountability for autonomous activity, controls embedded into deployment workflows and recurring evidence that systems are behaving as intended. 

Organizations that close this confidence gap will be better positioned to move quickly, without losing control, and to pair AI ambition with accountability, evidence and trust. 


EY US AI Risk & Governance Survey



Summary 

The EY US AI Risk and Governance Survey finds that widespread policy adoption has not yet translated into consistent operational confidence. Agentic AI, cybersecurity exposure and regulatory pressure are testing whether controls can keep pace with deployment. Formal assurance reviews are exposing weaknesses and prompting organizations to modify, pause or stop AI systems. Leaders can narrow the gap by strengthening visibility across the AI estate, clarifying accountability for autonomous activity, embedding controls into workflows and producing recurring evidence that governance is effective.

About this article

Authors

Related articles

How AI vulnerability discovery is rapidly reshaping SOC reporting

SOC reporting is evolving as AI vulnerability discovery accelerates. From controls to testing and disclosures, scrutiny and expectations are rising.

Agentic AI: re-architecting assurance for a world of continuous risk

Agentic AI for assurance is a paradigm shift that will reshape how we approach trust, governance and accountability in our work.

Redefining the future of audit for the AI era

As the use of AI expands, high-quality audits are vital to promoting trust. At EY US, we’re meeting this moment and looking to what’s next. Learn more.

Joe Link + 1