Among the many risks of rapid artificial intelligence development and deployment, a solid majority of companies appear worried that their governance over the disruptive, risky technology may be insufficient.
In an EY survey of 202 U.S. companies with annual revenue of at least $1 billion, 69% of AI decision-makers said their organization has a “fully unified AI governance policy in place.”
Contrarily, though, the same proportion of participants expressed concern that the company “lacks the internal expertise to effectively evolve AI governance controls,” wrote EY, which provides AI governance, risk and compliance consulting services, in its survey.
Also telling is that 47% of those polled acknowledged their company has previously bypassed its AI governance process in favor of urgent development. “These findings suggest that AI governance processes are under increasing pressure to keep pace with AI deployment,” EY said.
The growing prominence of agentic AI may be of particular concern. The vast majority (85%) of survey participants whose companies use AI agents said some of them execute important actions (e,g., running code, placing inventory orders, flagging cybersecurity incidents) without real-time human intervention.
However, almost half (49%) of such participants admitted that their governance framework had not been updated to incorporate agentic AI risks and requirements. And 26% noted that their company can’t detect unauthorized agents operating internally.
“Recent high-profile examples of autonomous agents operating for extended periods without detection, even in environments that appeared to have safeguards in place, underscore the brand, financial and operational risks that emerge when AI agents are not governed with sufficient visibility and control,” EY wrote.
Often, the report said, cyber risk is where governance gaps first become visible. Indeed, 89% of the AI decision-makers reported having encountered AI-related risks in the previous 12 months. While leaders are trying to mitigate such risks with mandatory training and other steps, 41% said they do not have visibility into all the AI tools in use at their company.
Almost three-quarters (72%) of survey respondents indicated they worry about failing to comply with new AI-specific regulations. And 36% said they’ve experienced an AI incident or failure that caused a material negative impact.
While companies largely recognize these risks and many have begun to respond, it’s important to consider what evidence exists that their controls are working.
“An incomplete registry [of AI models and tools], a policy that is bypassed under pressure, or a control that cannot detect unauthorized use in real time can all create the same practical result: Governance exists, but confidence in its operational effectiveness remains limited,” EY wrote.