Almost half of US companies skip their AI governance policies to speed up deployment - EY study

Survey finds that while majority of companies have AI governance policies, many are willing to ignore them
Prefer the Global Legal Post on Google

Shutterstock

While a majority of US companies have put in place an AI governance policy, almost half of respondents in an EY survey said their organisations had ignored those policies to fast-track AI deployment.

The inaugural EY US AI Risk and Governance Survey found that 98% of organisations now have some form of AI governance policy, though 47% of senior AI decision-makers said their organisations had bypassed AI governance processes to more urgently deploy AI tools.

At the same time, 72% of respondents believe their organisation is failing to comply with new or emerging AI regulations, with another 72% saying they are worried about their inability to trace or audit the data lineage and inputs that underpin AI decision models. 

More than a third of respondents (36%) said their organisation had suffered an AI incident or failure that caused a ‘materially negative impact’, such as data loss, financial damage, operational disruption or reputation damage.

The advance of agentic AI is adding to these risks, given that governance must now take into consideration actions taken autonomously by the technology. While EY said most respondents have established controls to monitor AI agents, 26% of respondents said they are unable to detect if unauthorised AI agents are operating internally. Another 49% of respondents said their existing governance framework has not been specifically updated to include agentic AI risks and requirements.

Organisations also lack clear accountability around agentic AI use. Just over half of respondents (56%) who are using agentic AI said there is a perception within their organisation that no single person or group is responsible for agentic AI once it is deployed, with another 39% saying accountability is undefined.

EY said: “That distinction matters, because agentic AI does not simply produce an output for a human to review. It can trigger workflows, make decisions and take actions that create downstream business, compliance and reputational consequences.”

The report noted that cybersecurity issues tend to expose gaps in AI governance. Some 52% of respondents cited cybersecurity as their biggest AI risk in the past 12 months, followed by human risk (47%) and shadow AI risk (46%). As many as 41% of respondents said they don’t have visibility into all AI tools being used at their organisation.

EY said: “If leaders cannot see every tool, model or workflow operating in the business, they cannot fully assess what data is being entered, whether vendors meet internal standards or whether the use case aligns with policy. This is why cybersecurity is such a useful lens for understanding the broader AI governance challenge.”

The survey was based on responses from more than 200 AI decision-makers at public companies in the US with at least $1bn in annual revenue.

Email your news and story ideas to: [email protected]

The Global Legal Post

© 2026 The Global Legal Post. All Rights Reserved

Top