Nearly half of organizations have bypassed AI governance as rapid deployment creates a global compliance crisis

The rapid acceleration of artificial intelligence (AI) adoption has outpaced the development of corporate guardrails, leading to a precarious landscape where nearly half of all major organizations have intentionally bypassed internal governance protocols to expedite deployment. As firms rush to secure a competitive advantage in a volatile market, the disconnect between the speed of innovation and the rigor of risk management is creating a widening confidence gap. Recent data from EY, Gartner, IDC, and TrustedTech underscores a troubling trend: while corporate leaders are eager to integrate AI, the infrastructure to secure, monitor, and derive tangible value from these tools remains alarmingly underdeveloped.
The Governance Deficit and the Urgency Paradox
For many large-scale enterprises, the pressure to integrate generative and agentic AI has reached a boiling point. An EY survey of 202 senior AI decision-makers at firms with at least $1 billion in revenue revealed that 47% have circumvented formal AI governance policies to achieve faster speed-to-market. This behavior occurs despite the fact that 98% of these same organizations maintain formal AI governance policies.
This phenomenon, often referred to as "compliance fatigue" or "strategic bypassing," suggests that existing frameworks are viewed by management as bureaucratic hurdles rather than essential safeguards. The consequences of these bypasses are becoming increasingly visible in post-deployment assurance reviews. Nearly a quarter of surveyed companies have been forced to fully terminate specific AI initiatives, while 64% have had to implement significant modifications following these audits. The primary drivers for these interventions include critical failures in data quality (57%), AI model drift (48%), and the emergence of "shadow AI"—unauthorized or unmonitored applications (39%).
The Rise of Agentic AI and the Accountability Gap
The shift toward agentic AI—autonomous systems capable of performing complex tasks with minimal human intervention—has further exposed the fragility of current governance models. Because agentic tools can make iterative decisions, they require a level of oversight that static AI policies simply do not provide.
The survey data highlights a significant blind spot: 49% of organizations utilizing agentic AI admit their governance frameworks have not been updated to account for these more complex tools. Furthermore, 39% of these companies report that accountability for monitoring and maintaining machine agents remains undefined. This ambiguity poses a substantial risk to enterprise integrity, as autonomous agents functioning without clear human accountability can propagate errors or violate regulatory standards at scale.
Audit Leaders Struggle with Predictive Visibility
The challenge is not limited to the technical deployment of AI; it is fundamentally altering the profession of internal audit. According to recent findings from Gartner, 64% of audit leaders report that it is becoming increasingly difficult to identify risks before they manifest into material financial or reputational impacts.
This struggle is driven by a trifecta of pressures: the breakneck speed of AI adoption, a rapidly shifting regulatory environment, and heightened geopolitical instability. These factors are effectively overwhelming traditional internal controls and enterprise risk management (ERM) practices. The current environment has created a disconnect between risk identification and corporate action. While audit and compliance departments are tasked with monitoring these threats, only 30% of business leaders acknowledge that their strategic decisions are heavily influenced by insights provided by their risk management teams.
Tegan Gebert, vice president in Gartner’s assurance practice, noted that the current environment has fundamentally raised the bar for leadership. "What it takes for them to fulfill their risk responsibilities is not only harder to achieve, but also even more critical to get right," Gebert stated. This suggests that without a more robust integration of audit insights into the C-suite’s decision-making process, the ability to preemptively address AI-related risks will continue to erode.
ROI Discrepancies and Global Market Realities
The race for AI dominance is also revealing a significant discrepancy in realized value between the United States and other global markets. A survey conducted by IDC and Expereo of 800 multinational enterprises found that US firms are currently underperforming in their AI return on investment (ROI) compared to their counterparts in the Asia-Pacific (APAC) region.
Only 15% of US businesses reported that their AI ROI exceeded expectations, a stark contrast to the 40% of APAC-based companies reporting the same success. Globally, the sentiment remains cautious: 38% of organizations believe AI has only partially met their ROI goals. Interestingly, European companies are the most likely to walk back their investments, with 22% reporting active down-scaling of AI projects. In contrast, the US rate of retrenchment stands at 10%, with the APAC region showing the lowest level of retreat at 6%.
The motivation behind these investments also varies significantly by region. In the US, only 10% of leaders cite "fear of falling behind" as their primary driver for AI adoption, suggesting a more calculated—albeit struggling—approach to implementation. Conversely, 37% of leaders in the APAC region identify the fear of "losing the pack" as a primary motivation, reflecting a more aggressive, market-sensitive adoption strategy.
The Human Element: Training and the Shadow AI Crisis
Perhaps the most significant vulnerability identified in recent studies is the lack of human preparedness. A survey by TrustedTech of 2,001 employees across the US and UK revealed that 44% of workers feel their organizations fail to provide adequate training on the safe and secure utilization of AI. Among leadership, this dissatisfaction is even higher, with 53% of executives agreeing that training programs are insufficient.
This lack of institutional support has led to a reliance on self-education. 41% of workers reported teaching themselves how to use AI, while 30% of decision-makers acknowledged the same. Many are turning to non-professional resources, such as YouTube or blogs, rather than internal corporate training programs.
This self-taught culture is fueling the expansion of "shadow AI." A notable contradiction exists within the IT and telecommunications sectors, where workers express high levels of confidence in their AI skills (87%) but simultaneously report high levels of concern regarding unauthorized AI use (68%). Julian Hamood, founder of TrustedTech, summarized the issue: "You can have a workforce that knows how to use AI and still lack the guardrails for safe adoption. That gap is exactly where shadow AI lives in every industry."
Strategic Implications for the Future
The current state of AI adoption indicates that we are entering a "second phase" of the technology’s lifecycle, where the initial excitement of implementation is being tempered by the harsh realities of governance, ROI, and security. Organizations that have bypassed their own policies to achieve rapid growth now face the daunting task of "retro-fitting" governance into existing workflows—a process that is often more expensive and complex than implementing it from the outset.
The implications for leadership are clear: the era of "move fast and break things" is proving incompatible with the requirements of enterprise risk management. To bridge the current gap, organizations must focus on three core areas:
- Closing the Education Gap: Formalizing AI literacy training to replace the current reliance on self-taught, often unverified, internet-based resources.
- Harmonizing Risk and Innovation: Integrating audit and risk management teams into the early stages of AI development, rather than treating them as a final hurdle to be bypassed.
- Redefining Accountability: Establishing clear protocols for agentic AI, ensuring that every autonomous system has a human-led accountability chain that can be activated in the event of failure or drift.
As regulatory bodies globally move toward stricter oversight—such as the EU’s AI Act and emerging US federal guidance—the organizations that have neglected governance will likely face significant legal and financial exposure. The challenge for 2026 and beyond will not be the adoption of AI, but the maturation of the frameworks that allow these powerful tools to operate within the bounds of corporate responsibility and safety. Organizations that fail to reconcile their drive for speed with the necessity of control will find that the "confidence gap" is not just a management hurdle, but a fundamental threat to their long-term viability.







