
Companies with large AI budgets are struggling to keep their oversight systems up to speed with the technology. A new EY report finds that a majority of AI decision-makers at U.S. firms with over $1 billion in revenue worry their governance frameworks are not sufficient. While 69% of respondents claim to have a fully unified AI governance policy in place, the same percentage admits their organization lacks the internal expertise to effectively evolve those controls.
Pressure to Deploy Outpaces Oversight
Operational demands are eroding compliance. About 47% of survey participants acknowledged their companies have previously bypassed governance processes to meet urgent development goals. This pressure is likely increasing as firms adopt agentic AI. The vast majority of users of these autonomous agents say some of them execute critical actions, such as running code, placing inventory orders, or flagging cybersecurity incidents, without real-time human intervention.
Despite this rapid adoption, governance frameworks have not kept up. Almost half of those using AI agents reported that their oversight has not been updated to address the specific risks of these systems. A significant portion of companies also cannot detect unauthorized agents operating internally. The report notes that high-profile cases of autonomous agents running for extended periods without detection in seemingly secure environments highlight the brand, financial, and operational risks that arise when visibility and control are limited.
Many firms are starting to feel the consequences of these gaps. Cyber risk is often the first area where governance failures become visible. AI decision-makers reported encountering AI-related risks in the previous 12 months at high rates. While companies are using mandatory training and other steps to mitigate these dangers, 41% still do not have visibility into all the AI tools currently in use. Concerns over compliance with new AI-specific regulations are also widespread, with 72% of respondents expressing worry about meeting these legal requirements. A material negative impact from an AI failure has been experienced by 36% of the companies surveyed.
These findings suggest that while many organizations have policies on paper, the practical effectiveness of those controls is often limited. An incomplete registry of AI models, a policy that is bypassed under pressure, or a control that cannot detect unauthorized use in real time can all produce the same outcome: governance exists, but confidence in its operational effectiveness remains low.