Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

EY Survey Finds AI Adoption Moving Faster Than Governance Controls

EY Survey Finds AI Adoption Moving Faster Than Governance Controls

By
Key Takeaways
  • Governance Policies Are Widespread, but Not Always Followed: 98% of surveyed senior AI decision-makers said their organizations have formal AI governance policies, while 47% said their organizations had previously bypassed governance processes for urgent deployments.
  • Agentic AI Is Moving Ahead of Existing Frameworks: Among respondents whose organizations use agentic AI, 49% said their governance frameworks had not yet been updated specifically for agentic AI requirements and risks.
  • Unauthorized Agents Are Creating Visibility Gaps: 26% of respondents at organizations using agentic AI said their organizations cannot detect unauthorized AI agents operating internally.
  • AI Incidents Are Already Causing Material Harm: 36% said their organizations had experienced an AI incident or failure resulting in data loss, financial damage, operational disruption, brand damage or other materially negative effects.
  • Assurance Reviews Are Prompting Changes: Among respondents whose organizations conducted formal AI assurance reviews, 64% said at least a quarter of their AI systems were significantly modified, while 29% paused and 25% fully stopped at least a quarter.
Deep Dive

Nearly every senior AI executive surveyed by EY says their organization has formal rules governing artificial intelligence. Nearly half say those rules have been bypassed when a deployment was urgent. That runs through EY's new AI Risk and Governance Survey, which found that large US companies are rapidly putting AI and autonomous agents to work while struggling to keep their governance processes aligned with the technology.

98% of respondents said their organizations have formal AI governance policies in place. Yet 47% said their organizations had previously not followed their AI governance process for urgent deployments.

The survey covered 202 senior AI decision-makers at publicly traded US companies with at least $1 billion in annual revenue. Respondents included board members, C-suite executives and leaders at the vice president level or above with direct oversight of AI systems, governance or audit processes. EY fielded the survey from May 28 to June 15. The margin of error was plus or minus 7 percentage points at the 95% confidence level.

The findings also point to a shortage of people equipped to build and maintain those controls. 69% of respondents expressed concern about a lack of internal expertise to effectively evolve AI governance controls at their organizations. 63% said the same about implementing controls, and 63% about designing them.

"Organizations are applying yesterday's governance rules to today's interactions with AI," said Richard Jackson, EY Americas Assurance chief technology officer and EY Global and Americas Assurance AI leader.

Jackson said boards and executive teams are under pressure to accelerate AI adoption and introduce agentic systems, but argued that speed and appropriate governance do not have to come at the expense of one another.

The pressure is particularly visible around agentic AI, where systems can take actions with limited or no real-time human involvement.

Agentic AI Moves Ahead of Governance

91% of respondents said their organizations use agentic AI, either through active pilot programs or full enterprise deployments. Governance has not always moved with it. Among respondents whose organizations use agentic AI, 49% said their existing governance frameworks had not yet been updated specifically to address agentic AI requirements and risks.

At the same time, 85% said at least a handful of their agentic AI systems execute actions without real-time human involvement. EY cited activities ranging from detecting cybersecurity threats to running code. The problem begins even earlier, with knowing which agents are operating inside the company. 26% of respondents whose organizations use agentic AI said their organizations cannot detect unauthorized AI agents operating internally.

"The biggest agentic AI risk is that human oversight hasn't evolved accordingly," said John McLain, EY Americas Assurance Technology Risk AI leader and EY Americas Assurance AI deputy leader. "AI governance provides the necessary guardrails that allow organizations to move quickly without losing control, especially when agentic AI is already making real business decisions."

The findings put a different shape around the familiar problem of shadow AI. An unauthorized generative AI tool used by an employee can expose company information or circumvent approved processes. An unauthorized agent capable of taking actions inside company systems adds another question: what is it permitted to do once it gets there?

EY's survey does not establish how many unauthorized agents are operating inside the organizations surveyed. It shows that more than a quarter of respondents at organizations using agentic AI do not believe their organizations can detect them.

AI Failures Are Already Hitting Companies

The governance problems are arriving alongside AI incidents that executives say have already caused harm. 89% of respondents said their organizations encountered AI-related risks during the previous year. Cybersecurity risks were reported by 52%, human risks by 47% and shadow AI risks by 46%. 36% said their organizations had experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, operational disruption and brand damage.

Concern about future failures was more widespread. 81% of respondents expressed concern about third-party AI-enabled cyberattacks. 75% were concerned about a high-profile AI failure publicly damaging their organization's reputation. 72% were concerned that their organizations could fail to comply with new or emerging AI-specific regulations. The same share expressed concern about being unable to accurately trace or audit the data lineage and inputs feeding critical AI decision models.

That combination of autonomy and weak traceability poses a particular governance problem. Organizations may increasingly rely on AI systems to perform consequential work while still struggling to establish what information informed those systems and what happened once they acted.

Assurance Reviews Are Finding Problems

Companies are also finding problems when they subject their AI systems to formal review. 98% of respondents said their organizations conduct a formal AI assurance review at least annually. Among the most common problems identified through those reviews were data quality issues, cited by 57% of respondents, AI model drift at 48% and shadow AI at 39%.

The reviews frequently resulted in changes to AI systems already in use or development. Among respondents whose organizations conducted formal AI assurance reviews, 64% said their organizations significantly modified at least a quarter of their AI systems following those reviews. 14% said three-quarters or more of their systems were modified.

29% said at least a quarter of their AI systems were paused, including 9% that paused three-quarters or more. 25% said at least a quarter were fully stopped, with 5% reporting that three-quarters or more were stopped. Those percentages describe the share of surveyed executives reporting actions across their organizations. They do not mean that 64% of all AI systems reviewed required modification or that 25% of AI systems generally were stopped.

Jackson said the results show that assurance reviews are identifying issues consequential enough to change deployment decisions.

"The fact that reviews so consistently uncover issues and lead to modifications, pauses or cancellations shows that AI governance and assurance work when implemented," he said.

The survey offers a narrow but notable picture of the companies at the front of enterprise AI adoption. Its respondents work at large, publicly traded US companies already running pilots or deployments involving traditional, generative or agentic AI, and the sample carries a 7-point margin of error.

Within that group, formal governance is nearly universal. So are formal assurance reviews. What is less settled is whether those controls can keep pace with systems that are gaining more autonomy, spreading across the enterprise and, in some cases, operating beyond the organization's view.

The next stage of AI governance is unlikely to be measured by how many companies can produce a policy. EY's findings point instead to whether companies know which systems are operating, what those systems are doing, who authorized them to do it and whether someone can stop them when the controls say they should.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong