Legal & Compliance

Survey: AI Policies in Place, but They Are Often Short-Circuited

As artificial intelligence shifts from an experimental novelty to a cornerstone of enterprise operations, a worrying trend has emerged: organizational speed is increasingly prioritized over institutional integrity. A recent survey by EY, encompassing 202 senior decision-makers at US-based firms with annual revenues exceeding $1 billion, confirms that 47% of organizations have intentionally circumvented established AI governance protocols to expedite deployment. This occurs despite the fact that 98% of these same organizations maintain formal AI policy frameworks, suggesting that internal controls are being treated as flexible guidelines rather than mandatory safety requirements.

The Governance Gap and the Rise of Agentic AI

The disconnect between policy and practice is widening, particularly as firms move beyond basic generative AI toward more autonomous systems. The integration of "agentic AI"—systems capable of performing complex tasks with minimal human intervention—has outpaced existing compliance frameworks. Nearly half (49%) of organizations utilizing these advanced tools admit that their governance frameworks have not been updated to reflect the unique risks posed by autonomous agents.

Furthermore, the issue of accountability remains nebulous. In 39% of organizations using agentic AI, there is no clear definition of who is responsible for monitoring these agents once they are deployed. This creates a "black box" scenario where automated systems operate without sufficient oversight, increasing the likelihood of operational errors, security breaches, or non-compliance with regulatory standards.

The primary concerns surfacing during post-deployment assurance reviews highlight the fragility of these rapid implementations. Data quality issues remain the leading challenge, cited by 57% of respondents, followed by AI model drift at 48% and the proliferation of "shadow AI"—unauthorized or unvetted tools—at 39%. While companies are beginning to prioritize remediation, with 64% reporting significant modifications to their AI systems following an assurance review and 25% opting to fully terminate underperforming or risky deployments, the cost of these retrofitting efforts is significant.

The Diminishing Visibility of Enterprise Risk

The operational difficulties are not limited to AI deployment; they permeate the broader landscape of corporate risk management. According to a Gartner survey of 108 audit leaders, 64% report that identifying risks before they materialize into material impacts has become significantly harder than in previous years. This inability to forecast threats is driven by a convergence of rapid AI integration, a shifting global regulatory environment, and heightened geopolitical instability.

The implications for leadership are profound. Despite the heightened risk profile of modern enterprise, there is a clear breakdown in the communication pipeline between assurance functions and executive decision-making. Only 30% of business leaders indicate that their risk management strategies are substantially influenced by insights derived from internal audit, compliance, or enterprise risk management (ERM) departments.

Tegan Gebert, vice president in the Gartner assurance practice, noted that this environment has significantly raised the stakes for modern leadership. "What it takes for them to fulfill their risk responsibilities is not only harder to achieve, but also even more critical to get right," Gebert stated. The failure to integrate risk intelligence into strategic planning suggests that while organizations are collecting data on threats, they are struggling to convert that data into actionable business resilience.

A Global Divergence in AI Return on Investment

Beyond the challenges of governance and oversight, the economic performance of AI investments appears to be geographically polarized. Research from IDC and Expereo, covering 800 multinational enterprises, reveals a stark disparity in ROI expectations. Only 15% of US businesses reported that their AI initiatives exceeded initial ROI expectations, a figure that pales in comparison to the 40% of organizations in the Asia-Pacific (APAC) region that reported similar success.

This data suggests that while US firms may be moving faster in terms of raw deployment, their strategy may lack the refinement seen in other regions. In Europe, the trend leans toward correction; 22% of companies are actively downscaling AI initiatives due to failed expectations, compared to just 10% in the US and 6% in the APAC region.

The motivation behind these investments also differs significantly. In the US, the "fear of missing out" (FOMO) accounts for only 10% of the drive toward AI investment. By contrast, 37% of leaders in the Asia-Pacific region cite the fear of falling behind competitors as a primary catalyst for their adoption strategy. This suggests that while US firms may be experimenting with AI as a discretionary tool, APAC firms are viewing it as a defensive necessity, potentially leading to more deliberate and structured integration efforts.

The Training Deficit and the Human Factor

Underpinning these systemic challenges is a pervasive lack of workforce readiness. A survey conducted by TrustedTech, involving 2,001 employees across the US and the UK, found that 44% of workers believe their organizations do not provide adequate training for the safe and secure use of AI. Perhaps more concerning is that 53% of company leaders share this assessment, acknowledging that their own organizations are failing to equip staff with the necessary skills.

The current landscape of AI literacy is largely self-directed, which introduces significant risks to intellectual property and data security. Nearly one-third of decision-makers and 41% of workers rely on self-teaching methods, such as personal research or online tutorials, rather than structured corporate training. When employees turn to platforms like YouTube or independent blogs for professional AI training, they are likely bypassing company-specific security protocols and ethical guidelines.

The "IT Paradox" provides further evidence of this disconnect. In the IT and telecommunications sectors, where workforce confidence in using AI is highest (87%), there is simultaneously a profound concern regarding shadow AI (68%). Julian Hamood, founder of TrustedTech, summarized the situation: "IT and telecoms should theoretically be the industry best prepared for AI, but our data shows that confidence and readiness are two different things. You can have a workforce that knows how to use AI and still lack the guardrails for safe adoption."

Implications for Future Governance

The current state of AI adoption is characterized by a "move fast and break things" mentality that is increasingly ill-suited for the corporate environment. The reliance on informal learning, the circumvention of governance protocols, and the struggle to translate audit insights into strategy create a high-risk environment.

For organizations to bridge these gaps, several steps appear necessary:

  1. Formalizing Governance: Moving away from treating AI policies as mere formalities and integrating them into the core IT infrastructure.
  2. Standardizing Education: Replacing self-taught, platform-reliant skill development with rigorous, organization-wide training that emphasizes security and ethics.
  3. Closing the Communication Loop: Bridging the gap between audit leaders and executive management to ensure that risk assessments are not just stored in reports, but are active components of the corporate strategy.
  4. Active Oversight of Agents: Establishing clear, assigned accountability for autonomous agents, ensuring that every algorithmic action can be traced back to an internal stakeholder.

As the technology matures, the competitive advantage will likely shift from those who deploy AI the fastest to those who deploy it the most securely and effectively. The findings from these recent surveys indicate that while the first wave of AI adoption has been marked by rapid, often uncoordinated growth, the next phase will require a fundamental shift toward accountability and systematic integration. Failure to achieve this maturity could result in a long-term erosion of trust, financial losses from failed ROI, and significant exposure to both regulatory and security threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button