New survey of senior AI executives shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace — despite mounting reputational, cybersecurity and shadow AI risk
- About half (47%) of respondents say their organization has previously not applied its AI governance process for urgent deployments, despite 98% having formal AI governance policies in place.
- Agentic AI adoption is creating new governance challenges, with 26% of respondents whose organization uses agentic AI admitting that their organization cannot detect unauthorized AI agents operating internally.
- About a third (36%) have experienced an AI incident or failure that caused a materially negative impact to their organization, including data loss, financial damage, brand damage and operational disruptions.
NEW YORK, September 15, 2026 – Although organizations are formalizing AI governance while rapidly deploying AI and autonomous AI agents, many are still struggling to keep policy and practice aligned, according to the new Ernst & Young LLP (EY US) AI Risk and Governance Survey. By surveying 202 senior AI executives (including board members, C-suite, VP+ leaders) at organizations generating at least $1 billion in annual revenue, the study explores how leaders govern AI, including: how quickly governance frameworks are adapting to agentic AI, the extent and impact of AI-related risk, and the role of formal assurance reviews in identifying and correcting issues.
The survey found that while almost all senior AI executives (98%) report having formal AI governance policies in place, about two-thirds of senior AI executives expressed concern over a lack of internal expertise to effectively evolve (69%), implement (63%) or design (63%) AI governance controls at their organization. About half (47%) of the respondents have even admitted that their organization has previously not followed its AI governance process for urgent deployments, even as AI-related incidents, cyber risk and shadow AI have become more common.
“Organizations are applying yesterday’s governance rules to today’s interactions with AI,” said Richard Jackson, EY Americas Assurance Chief Technology Officer and EY Global and Americas Assurance AI Leader. “Boards and C-suites are under immense pressure to accelerate their AI adoption and implement agentic AI systems. Moving fast and applying appropriate governance are not mutually exclusive — both are needed to avoid creating the risks of reputational, financial and operational damage.”
Agentic AI is outpacing governance frameworks
Agentic AI is being rapidly adopted across enterprises, with 91% of senior AI executives reporting their organization uses agentic AI, either through active pilot programs or full enterprise deployment. However, governance practices have not kept pace with adoption. Roughly half (49%) of respondents whose organization uses agentic AI say their organization’s existing governance framework has not yet been updated to specifically include agentic AI requirements and risks. While agentic AI systems are already executing critical actions — from detecting cybersecurity threats to running code — 85% of senior AI executives whose organization uses agentic AI admit that at least a handful of these systems execute actions without real-time human involvement.
As organizations scale autonomous AI adoption, critical visibility gaps are emerging, with about a quarter (26%) of senior AI executives whose organization uses agentic AI reporting that their organization cannot detect unauthorized AI agents operating internally.
“The biggest agentic AI risk is that human oversight hasn’t evolved accordingly,” said John McLain, EY Americas Assurance Technology Risk AI Leader and EY Americas Assurance AI Deputy Leader. “AI governance provides the necessary guardrails that allow organizations to move quickly without losing control, especially when agentic AI is already making real business decisions.”
AI risk is widespread, with many already experiencing financial and reputational damage
Senior AI executives express significant concerns about AI risk, ranging from fear of third-party AI-enabled cyber attacks (81%) to high-profile AI failure publicly impacting their organization’s reputation (75%), their organization failing to comply with new or emerging AI-specific regulations (72%), and the inability to accurately trace or audit the data lineage and inputs that feed critical AI decision models (72%). These anxieties are grounded in real-world events. In the past year, 89% of respondents say they encountered AI-related risks, including cybersecurity risks (52%), human risk (47%) and shadow AI risk (46%).
These risks have materialized into tangible organizational harm. About a third (36%) of leaders surveyed report that their organization has experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, operational disruption and brand damage.
Companies are course correcting to address AI governance gaps
Enterprises are turning to formal AI risk and compliance reviews to bridge the AI governance gap. Nearly all (98%) respondents said their organization has conducted a formal AI assurance review at least annually, and among those who conducted a formal AI assurance review:
- 64% significantly modified a quarter or more of their AI systems; 14% had to modify three-quarters or more of their AI systems
- 29% paused a quarter or more of their AI systems; 9% paused three-quarters or more of their AI systems
- 25% fully stopped a quarter or more of their AI systems; 5% fully stopped three-quarters or more of their AI systems
Among the most common issues organizations find in their formal AI assurance reviews include data quality problems (57%), AI model drift (48%) and shadow AI (39%).
“The fact that reviews so consistently uncover issues and lead to modifications, pauses or cancellations shows that AI governance and assurance work when implemented,” Jackson said. “It also reinforces the need to build these disciplines into how AI systems are designed, tested and governed, and to then operate them at a frequency that keeps pace with the technology.”
For additional survey findings, visit: https://www.ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap.