AI governance gaps widen as enterprises race ahead—boards, lawyers, and leaders sound alarm on trust and accountability

Eye on AI

The gist

As China’s enterprises sprint to embed AI everywhere, gaping governance holes are putting trust, compliance, and business value on the line.

What to know

Governance Gaps Threaten Trust

AI oversight lags far behind adoption as boards, lawyers, and leaders warn that fragmented policies and language barriers leave critical sectors exposed to compliance failures and eroding public trust.

Despite near-universal pressure to scale AI for customer experience, only 38% of European organizations have a clear AI governance approach, exposing widespread governance gaps that undermine trust and compliance. The complexity of managing AI across multilingual and multi-market environments further exacerbates these challenges, with 64% citing language diversity as a major obstacle. Trust in AI remains strongly contingent on transparent governance and human oversight, as 87% of respondents express confidence only when AI is supervised by humans, underscoring the fragile balance between rapid adoption and accountability.

In legal practice, AI governance is rapidly evolving from a mere compliance checkbox into an integrated, cross-system infrastructure essential for accountability and defensibility. Reports emphasize the need for a 'governance spine' that orchestrates AI workflows across strategy, process, forensic validation, and client acceptance—layers that are interdependent and cannot be retrofitted downstream. Yet, 43% of legal firms lack formal AI policies, and only 9% actively enforce them, revealing a critical gap between adoption and governance maturity. This gap is especially pronounced in smaller firms, which struggle with resource constraints but still require formal guidance to mitigate risks.

Boards across industries, including energy and finance, are awakening to the inadequacy of traditional corporate governance models in overseeing AI’s probabilistic nature. KPMG’s global risk chief warns that directors must develop sufficient AI fluency to question assumptions and identify accumulating risks, as failure to act risks reputational damage and lost business value. However, surveys reveal only 17% of energy leaders feel prepared for independent AI governance audits despite 64% of boards integrating AI risk oversight, highlighting a readiness gap that threatens to entrench poor governance practices before they can be corrected.

Across sectors from multifamily property management to technology infrastructure, rapid AI adoption is outpacing governance frameworks, creating operational blind spots and compliance vulnerabilities. For example, only 13% of multifamily leaders feel confident passing an AI governance audit, while 86% of infrastructure leaders express confidence despite just 30% having formal AI governance policies. Industry giants like Microsoft and Apple now emphasize governance, identity, and security controls as prerequisites for deploying AI agents, yet 80% of organizations have already encountered risky AI behaviors. This underscores the urgent need for integrated, continuously monitored governance architectures that transform governance from a bureaucratic hurdle into a strategic enabler of safe, scalable AI innovation.

Sources

Agentic AI Raises Security Stakes

The surge of autonomous AI agents is outpacing security frameworks, driving a wave of infrastructure incidents and forcing enterprises to rethink governance with continuous, layered defenses and strict human oversight.

As enterprises accelerate AI adoption, operational complexity and security risks have surged, particularly with the rise of agentic AI systems that autonomously access and manipulate sensitive data across multiple workflows. Gartner forecasts a leap from under 5% to 40% of enterprise applications embedding AI agents by the end of 2026, amplifying the challenge of enforcing least-privilege access and continuous monitoring beyond traditional prompt-level security. Snowflake’s multi-layered defense-in-depth approach—spanning data, model, and agent layers—exemplifies how integrated governance frameworks can mitigate risks such as unauthorized data exposure, prompt injection attacks, and uncontrolled data sprawl through zero-copy architectures and role-based controls.

The operational risks of AI deployment extend beyond technical vulnerabilities to include unpredictable agent behaviors like hallucinations, malicious skill downloads, and silent performance degradation, which traditional monitoring tools often miss. As highlighted by a financial services firm’s experience with AI agents quietly generating conservative risk scores that eroded revenue over months, continuous human oversight remains indispensable to detect and correct such anomalies in real time. Companies are increasingly investing in specialized AI governance solutions—such as Microsoft Agent 365—that provide end-to-end observability and enforce strict identity and security controls, underscoring a new baseline expectation for robust agent governance.

Despite widespread confidence among infrastructure leaders—86% express faith in their AI governance capabilities—a glaring governance paradox persists as only 30% have formal AI policies, and a mere 4% among the most exposed organizations maintain such frameworks. This disconnect fuels an 'AI-infrastructure gap' where 93% of companies have suffered AI-related infrastructure incidents, often due to applying AI-generated infrastructure as code directly or with minimal review, as reported by Spacelift. Organizations that adopt automated validation and enforce formal governance policies, dubbed 'Pioneers,' experience significantly fewer governance failures, highlighting the critical need for continuous monitoring, least-privilege enforcement, and evolving security models to manage AI’s operational risks effectively.

Enterprises must exercise deliberate control over AI tool authorization, ensuring only enterprise-grade solutions with rigorous compliance certifications like SOC1 and SOC2 are deployed to mitigate data security and operational risks. Differentiated licensing models complicate governance, as corporate-licensed users may access sensitive data while others use public versions, necessitating strict controls to prevent data bleed and unauthorized access. This complexity demands integrated governance frameworks that combine continuous monitoring, auditability, and least-privilege enforcement to bridge the AI adoption execution gap and avoid costly surprises—such as the infamous $500 million AI cost overrun due to unchecked consumption.

Sources

Workforce Readiness Is the Bottleneck

AI’s business value depends on upskilling employees and breaking organizational silos, as middle management inertia and inconsistent risk training threaten to undermine responsible AI deployment and operational impact.

Workforce readiness emerges as the linchpin in translating AI investments into measurable business value, with BCG’s 10-20-70 rule underscoring that 70% of AI’s value stems from rethinking the people component rather than technology alone. Sanjeev Vohra of Genpact highlights the 'frozen middle'—overstretched middle managers—as a critical bottleneck, emphasizing that active CEO involvement and cross-functional leadership are essential to break silos and embed AI into core workflows rather than relegating it to advisory or experimental roles. This organizational readiness requires disciplined management systems that combine Geoffrey Moore’s Zone to Win framework with leadership methodologies like Thinking in Outcomes and the Big Bet Experiment Planner to maintain rapid, focused experimentation on high-value pain points while cultivating cultural readiness.

Effective AI adoption demands comprehensive workforce upskilling that goes beyond technical training to encompass AI ethics, risk awareness, and real-time judgment. NatWest’s initiative to offer all 60,000 employees a multi-month course on AI’s ethical risks exemplifies how AI literacy must empower employees to recognize when confident AI outputs might jeopardize customer experience and to exercise human oversight through mechanisms like a 'pause button' for escalating edge cases. Similarly, USA Today’s ethical AI guidelines integrate specialized training, human editorial review, and a dedicated AI council to ensure transparency and continuous governance, illustrating that embedding AI risk controls directly into workflows is vital for responsible AI use and bridging the gap between AI experimentation and operational value.

Organizational change also requires redefining productivity expectations and fostering cultural shifts that enable employees to transition from manual task execution to higher-value activities augmented by AI. Hershey’s finance team experience reveals a wide spectrum of AI comfort levels among employees, necessitating ongoing education to unlock productivity gains and responsible AI use. Their approach includes embedding governance practices akin to physical asset management, ensuring segregation of duties and controls prevent AI from operating unchecked, while leveraging AI to generate strategic communication aids and simulate stakeholder questions. This continuous adaptation to evolving AI capabilities and regulatory landscapes is critical to sustaining workforce readiness and maximizing AI’s business impact.

At the governance apex, board members must attain basic AI fluency to fulfill their oversight responsibilities effectively, enabling them to question assumptions, understand risk accumulations, and ensure management has the talent and controls to challenge AI outputs before they influence decisions. KPMG’s global risk chief warns that boards focusing solely on automation risk missing the strategic imperative of building a workforce capable of using AI responsibly and maintaining accountability. Trust—rooted in explainability, fairness, accountability, and transparency—is foundational for durable AI innovation, making workforce readiness and governance discipline inseparable pillars in closing the AI adoption execution gap.

Sources
WTF is SEO?The Digital Leader: A Big Bets Briefing on Strategy and AIDecoding Customer ExperienceWorkivaFortuneEye on AI

AI Value Hinges on Integration

Boards demand end-to-end governance and real-time transparency as enterprises shift from isolated AI pilots to embedding AI in core workflows, making continuous oversight and strategic alignment non-negotiable for lasting business returns.

By mid-2026, the AI industry has pivoted from focusing solely on enhancing model capabilities to emphasizing robust governance, budget control, and seamless operational integration within enterprises. This shift reflects a growing recognition that AI’s true business value emerges not from isolated pilots but from strategic, large-scale deployment embedded deeply into core workflows across functions such as procurement, finance, and customer service. As Eminent Global Research Solutions highlights, organizations embedding AI into these critical processes—rather than treating it as a peripheral productivity tool—are the ones realizing measurable improvements in operational efficiency and revenue generation.

Central to this strategic integration is the establishment of comprehensive, living governance frameworks that transcend static compliance checklists. These frameworks must address data quality, ethical transparency, and regulatory compliance while incorporating continuous monitoring and risk assessment tailored to AI’s evolving impact. As one expert explains, enterprise AI governance involves “the full operational framework, the rules, roles, processes, and technical controls” that ensure AI systems are responsibly built, deployed, and held accountable, with policies that evolve alongside AI capabilities to define autonomous actions versus human escalation.

Boards and executive leadership are increasingly demanding transparent, structured communication about AI initiatives, prioritizing use cases based on measurable business outcomes and strategic alignment. Grant Thornton’s analysis of energy firms reveals that boards expect a centralized, continuously updated catalog of AI use cases to guide investment decisions, alongside clear explanations of how AI will drive revenue, contain costs, mitigate risks, and ensure compliance. This transparency, coupled with realistic timelines and crisp success criteria benchmarked against legacy processes, is essential to securing foundational investments and managing expectations as enterprises scale AI from pilots to production.

Trust remains a critical bottleneck in scaling AI to deliver significant business value, especially within finance leadership where the stakes are high. CFO Matt emphasizes that even a 95% accuracy rate is insufficient without trust in both AI outputs and the underlying systems, necessitating rigorous continuous testing and process redesign—what he terms 'harness engineering'—to ensure predictable, defensible outcomes. This trust deficit contributes to many organizations languishing in pilot phases, with only about one in eight CEOs reporting AI-driven revenue growth and cost reduction, underscoring the urgent need for workforce upskilling and continuous governance to bridge the AI adoption execution gap.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.