Nearly every large U.S. public companies in a new EY survey has a formal AI governance policy. Almost half have set it aside when a deployment was urgent.
Its inaugural “AI Risk and Governance Survey,” released Sept. 15, found 47% of senior AI decision-makers said their organization had previously bypassed its AI governance process for an urgent deployment, even though 98% reported having formal AI governance policies in place.
EY’s Americas Assurance practice commissioned the survey of 202 board members, C-suite executives and vice presidents or above at publicly traded companies with at least $1 billion in annual revenue. All respondents were U.S.-based and had direct oversight of AI systems, governance or audit processes. The survey, fielded May 28 to June 15, has a margin of error of plus or minus 7 percentage points. EY’s assurance practice sells AI governance and assurance services.
Agentic AI raises the stakes for oversight
Nine in 10 respondents (91%) said their organizations uses agentic AI in pilots or full deployment. Among them, 85% said at least a handful of those systems were executing actions such as running code, placing inventory orders or detecting cybersecurity incidents without real-time human intervention.
Yet 49% said their governance framework had not been specifically updated for agentic AI risks, and 26% said their organization could not detect unauthorized AI agents operating internally.
EY also found 41% of respondents said senior leaders lacked visibility into all AI tools operating inside their organization. And 36% said their company had experienced an AI incident or failure with a materially negative impact, including data loss, financial damage, operational disruption or brand damage.
AI assurance reviews rarely come back clean
Nearly all respondents (98%) said their organization conducts a formal AI assurance review at least annually. EY’s detailed analysis of the survey said 92% of those organizations found issues. The majority significantly modified their AI systems as a result, rather than pausing or stopping them entirely.
Among the most common problems are data quality issues (cited by 57%), model drift (48%) and shadow AI (39%).
EY calls the wider divide a “confidence gap”: companies have built governance structures but struggle to match their pace to their AI ambitions.
A separate OneTrust survey found a related timing problem in a broader international sample. One-third of respondents said employees had used unapproved AI because approved tools or processes were not available quickly enough, while 31% said AI use cases reached governance review only after they were already in use.
OneTrust, an AI governance software company, commissioned Sapio Research to survey 1,200 senior business decision-makers at organizations with at least $100 million in annual revenue across eight markets, including the U.S., in June and July. The findings appear in OneTrust’s 2026 “AI-Ready Governance Survey Report”.
Both surveys rely on respondents describing their own organizations rather than independent verification. Both companies sell AI governance products or services. Their populations and questions also differ, so the percentages are not directly comparable.
All good research leads to more research questions. And for technology leaders, the question these surveys raise next is why governance gets bypassed at all. When nearly half of companies have skipped their own process under deadline pressure, speed seems to be the common culprit.
So what does speed-impervious AI governance look like?