EY survey finds that autonomous AI implementation outpaces oversight, yielding an AI governance gap

EY survey finds that autonomous AI implementation outpaces oversight, yielding an AI governance gap

PR Newswire

New survey of senior AI executives shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace — despite mounting reputational, cybersecurity and shadow AI risk

  • About half (47%) of respondents say their organization has previously not applied its AI governance process for urgent deployments, despite 98% having formal AI governance policies in place.
  • Agentic AI adoption is creating new governance challenges, with 26% of respondents whose organization uses agentic AI admitting that their organization cannot detect unauthorized AI agents operating internally.
  • About a third (36%) have experienced an AI incident or failure that caused a materially negative impact to their organization, including data loss, financial damage, brand damage and operational disruptions.

NEW YORK, Sept. 15, 2026 /PRNewswire/ — Although organizations are formalizing AI governance while rapidly deploying AI and autonomous AI agents, many are still struggling to keep policy and practice aligned, according to the new Ernst & Young LLP (EY US) AI Risk and Governance Survey. By surveying 202 senior AI executives (including board members, C-suite, VP+ leaders) at organizations generating at least $1 billion in annual revenue, the study explores how leaders govern AI, including: how quickly governance frameworks are adapting to agentic AI, the extent and impact of AI-related risk, and the role of formal assurance reviews in identifying and correcting issues.

Building a better working world logo. (PRNewsFoto/Ernst & Young)

The survey found that while almost all senior AI executives (98%) report having formal AI governance policies in place, about two-thirds of senior AI executives expressed concern over a lack of internal expertise to effectively evolve (69%), implement (63%) or design (63%) AI governance controls at their organization. About half (47%) of the respondents have even admitted that their organization has previously not followed its AI governance process for urgent deployments, even as AI-related incidents, cyber risk and shadow AI have become more common.

“Organizations are applying yesterday’s governance rules to today’s interactions with AI,” said Richard Jackson, EY Americas Assurance Chief Technology Officer and EY Global and Americas Assurance AI Leader. “Boards and C-suites are under immense pressure to accelerate their AI adoption and implement agentic AI systems. Moving fast and applying appropriate governance are not mutually exclusive — both are needed to avoid creating the risks of reputational, financial and operational damage.”

Agentic AI is outpacing governance frameworks

Agentic AI is being rapidly adopted across enterprises, with 91% of senior AI executives reporting their organization uses agentic AI, either through active pilot programs or full enterprise deployment. However, governance practices have not kept pace with adoption. Roughly half (49%) of respondents whose organization uses agentic AI say their organization’s existing governance framework has not yet been updated to specifically include agentic AI requirements and risks. While agentic AI systems are already executing critical actions — from detecting cybersecurity threats to running code — 85% of senior AI executives whose organization uses agentic AI admit that at least a handful of these systems execute actions without real-time human involvement.

As organizations scale autonomous AI adoption, critical visibility gaps are emerging, with about a quarter (26%) of senior AI executives whose organization uses agentic AI reporting that their organization cannot detect unauthorized AI agents operating internally.

“The biggest agentic AI risk is that human oversight hasn’t evolved accordingly,” said John McLain, EY Americas Assurance Technology Risk AI Leader and EY Americas Assurance AI Deputy Leader. “AI governance provides the necessary guardrails that allow organizations to move quickly without losing control, especially when agentic AI is already making real business decisions.”

AI risk is widespread, with many already experiencing financial and reputational damage

Senior AI executives express significant concerns about AI risk, ranging from fear of third-party AI-enabled cyber attacks (81%) to high-profile AI failure publicly impacting their organization’s reputation (75%), their organization failing to comply with new or emerging AI-specific regulations (72%), and the inability to accurately trace or audit the data lineage and inputs that feed critical AI decision models (72%). These anxieties are grounded in real-world events. In the past year, 89% of respondents say they encountered AI-related risks, including cybersecurity risks (52%), human risk (47%) and shadow AI risk (46%).

These risks have materialized into tangible organizational harm. About a third (36%) of leaders surveyed report that their organization has experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, operational disruption and brand damage.

Companies are course correcting to address AI governance gaps

Enterprises are turning to formal AI risk and compliance reviews to bridge the AI governance gap. Nearly all (98%) respondents said their organization has conducted a formal AI assurance review at least annually, and among those who conducted a formal AI assurance review:

  • 64% significantly modified a quarter or more of their AI systems; 14% had to modify three-quarters or more of their AI systems
  • 29% paused a quarter or more of their AI systems; 9% paused three-quarters or more of their AI systems
  • 25% fully stopped a quarter or more of their AI systems; 5% fully stopped three-quarters or more of their AI systems

Among the most common issues organizations find in their formal AI assurance reviews include data quality problems (57%), AI model drift (48%) and shadow AI (39%).

“The fact that reviews so consistently uncover issues and lead to modifications, pauses or cancellations shows that AI governance and assurance work when implemented,” Jackson said. “It also reinforces the need to build these disciplines into how AI systems are designed, tested and governed, and to then operate them at a frequency that keeps pace with the technology.”

For additional survey findings, visit https://www.ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap.  

Methodology
EY Americas Assurance team commissioned an online survey among 202 US senior AI decision-makers (board members, C-suite, VP+) at publicly traded companies with at least $1 billion in annual revenue. Respondents hold direct oversight over their organization’s AI systems, governance or audit processes, with active deployment or pilot programs across Traditional, generative or agentic AI. The survey was fielded between May 28 and June 15, 2026. The margin of error (MOE) for the total sample is plus or minus 7 percentage points at the 95% confidence interval.

This research was conducted by human researchers among human respondents. The fielding process was thoroughly supervised and screened for bots and AI agents to confirm the highest quality of data in accordance with industry standards.

About EY
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multidisciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

All in to shape the future with confidence.

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients. Information about how EY collects and uses personal data and a description of the rights individuals have under data protection legislation are available via ey.com/privacy. EY member firms do not practice law where prohibited by local laws. For more information about our organization, please visit ey.com.

Ernst & Young LLP is a client-serving member firm of Ernst & Young Global Limited operating in the US.

Press Contact:
Lauren K. Hare
(212) 713-6431
lauren.k.hare@ey.com

 

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/ey-survey-finds-that-autonomous-ai-implementation-outpaces-oversight-yielding-an-ai-governance-gap-302878162.html

SOURCE Ernst & Young LLP