Your team is already using AI. Your board is starting to ask about it. How will you answer? 72% of C-suite executives say AI is integrated across most or all of their organization’s initiatives. Only 14% of their CEOs believe those AI systems actually comply with regulations. That gap has a name, a cost, and a closing window.
Your employees started this without asking permission. By the time most organizations launched an official AI strategy, their finance team was already using AI to analyze contracts, their sales team was drafting proposals with tools IT hadn’t approved, and their operations staff had found three applications that cut hours off weekly reporting. If that sounds familiar, you’re in the majority.
The problem isn’t that your people are using AI. The problem is that 92% of organizations are at some stage of adoption while only 43% have a formal governance framework in place (BDO, 2025). The tools are live. The accountability isn’t.
If you’ve been following the Shadow AI discussion in other Sagacent articles or on our Facebook page, you already know your employees are further ahead on adoption than your IT policies. This piece is the next chapter: what the governance gap means at the executive level, how fast the scrutiny is closing in, and what a workable framework looks like for businesses without a Fortune 100 compliance team.
Here’s your quick read brief:
- 72% of organizations have AI integrated into most or all of their business initiatives, yet only 14% of CEOs believe their AI systems actually comply with regulations, the lowest confidence figure in the entire C-suite (EY Responsible AI Pulse Survey, 2025).
- 45% of US technology executives reported a confirmed or suspected sensitive data leak in the past 12 months from employees using unauthorized AI tools, and 39% reported confirmed proprietary IP leaks (EY Technology Pulse Poll, March 2026).
- Companies that implement more advanced, responsible AI governance are measurably pulling ahead in revenue, employee satisfaction, and cost savings; while those without governance stall (EY, 2025).
The CEOs Who Know the Most Are Saying They’re the Least Confident
The most important finding from 2025 AI-governance research is an accountability gap at the top, and the people most aware of it are the ones ultimately responsible for it.
In early 2025, EY surveyed 975 C-suite leaders across 21 countries for its Responsible AI Pulse Survey. The headline: 72% of organizations have AI integrated into most or all of their business initiatives, yet only a third of companies have proper governance controls across the full range of AI responsibility criteria.
The breakdown by role is where it gets instructive.
CEOs are consistently the least confident member of their own C-suite when it comes to AI governance. Only 14% of CEOs believe their AI systems comply with regulations, compared to 29% of their broader C-suite peers. Only 18% say their organizations have strong controls for AI fairness and bias, versus a C-suite average of 33% (EY Responsible AI Pulse Survey, 2025).
My read on this isn’t that CEOs are more pessimistic by nature. It’s that the people ultimately accountable for organizational risk have the clearest view of what’s missing. The same pattern showed up in the BDO 2025 survey of senior finance leaders at US companies with revenues between $250M and $10B: 92% had implemented AI or were planning to within 12 months. Only 43% had a formal governance framework in place (BDO, 2025). Adoption is moving in weeks. Governance is moving in quarters, if at all.
The funny thing is that most organizations aren’t unaware of the risk. AuditBoard’s 2025 survey found that 86% of respondents were aware of upcoming AI regulations, yet most effort remained concentrated on policy drafting rather than execution. Only 25% had fully implemented AI governance programs (AuditBoard, 2025). Awareness without action is exactly where most organizations are sitting.
Boards Are Catching Up Faster Than Most Executives Realize
When AI governance becomes a formal board agenda item, “we’re working on it” stops being an acceptable answer. That moment is closer than most executives have planned for.
Something shifted in US boardrooms in 2025. The number of S&P 500 companies that designated a committee with explicit AI oversight responsibilities more than tripled in a single proxy season (EY, 2025). Nearly half of Fortune 100 companies now include AI governance experience in their criteria for new board directors, almost double the 26% who did so in 2024 (EY, 2025). Boards don’t move that fast without investor pressure behind them.
There’s a reason for the shift among investors and board members: The cost of exposure is becoming quantifiable. EY’s March 2026 survey of 500 US technology executives found that 45% reported a confirmed or suspected sensitive data leak in the past 12 months from employees using unauthorized generative AI tools. 39% reported confirmed or suspected proprietary IP leaks for the same reason (EY Technology Pulse Poll, March 2026). These aren’t organizations with casual security cultures. They’re companies with 5,000-plus employees and dedicated security teams.
The pattern is consistent with what we’ve seen for years from Shadow IT use. When employees find tools that make them more productive and no approved alternative exists, they use those tools. The intent isn’t to create risk, but the outcome sometimes is.
For mid-sized businesses that don’t have a Fortune 100 legal team managing AI-related fallout, the scale of any incident may be smaller, but the proportional impact is larger. Legal and reputational risks from AI governance failures rank as the second-highest AI concern among executives, cited by 56% of respondents in Gallagher’s 2025 risk-management survey (Gallagher, 2025). The fastest path from potential to actual is continuing to let adoption run riot without clear accountability for what happens when something goes wrong.
Governance That Keeps Pace with Adoption
You don’t need a perfect AI strategy. You need a working first version, built in parallel with adoption, not after it.
The MIT Project NANDA research found 95% of enterprise AI deployments produced no measurable return on investment. The common thread: no expectations set, no governance structure, no user training (MIT Project NANDA, 2025). The businesses generating real AI returns aren’t spending more on technology. They’re investing in the framework that makes technology produce outcomes.
Here are four questions your governance framework needs to answer:
1. What tools are approved?
Maintain a short, explicit approved list—not because every other tool is definitively unsafe, but because governance without defined boundaries isn’t governance. Employees need to know which tools are sanctioned, not which ones to guess about.
2. What data is permitted?
Define clear data categories in language everyone understands. Public information: generally fine. Internal business data: restricted. Client data, patient data, legal-matter information, financial records: prohibited in unsanctioned tools. Most employees won’t know this line unless you draw it explicitly.
3. Who is accountable when something goes wrong?
This is the question boards are now asking directly. Someone in your organization needs to own AI governance, not necessarily as a full-time role, but as a named responsibility. “IT handles it” is not a governance structure.
4. How will you know if it’s working?
Do quarterly reviews of tool usage patterns and measured outcomes. The organizations generating real AI returns are the ones measuring results and adjusting. One practical starting point: run an AI tool inventory before building policy. Ask every department what tools they currently use for work tasks. Most businesses discover three to five tools in active use that leadership wasn’t aware of.
The technical side: monitoring for data flows to unauthorized services, managing approved tool access, flagging unusual data transfer patterns is the right job for a co-managed IT partner. That frees your team to focus on the governance decisions without getting pulled into infrastructure management.
The Organizations That Build Governance Now Won’t Be the Ones Explaining Themselves Later
The governance gap between AI adoption and AI accountability is closing. The question is whether it closes because your organization built the framework proactively, or because a board meeting, a client inquiry, or an AI-related incident forces the issue.
When was the last time you asked your team which AI tools they’re actually using? That’s often where the conversation needs to start.
Assess Your AI Governance
The organizations that will define competitive advantage over the next three years are the ones building governance now, not after the fact. If you’re unsure where your organization currently stands, Sagacent Technologies will be glad to walk through what a baseline AI governance assessment looks like for businesses your size. Contact us to start now.
Glossary of Terms
- Agentic AI: AI systems that can take autonomous actions without a human approving each step: browsing the web, writing and executing code, sending emails. Where current AI tools assist, agentic AI acts. 97% of US technology executives say pursuing autonomous AI is a high or essential strategic priority (EY, March 2026), meaning the risk profile of AI governance is about to become significantly more complex.
- AI Governance Framework: The documented policies, roles, and controls that determine how AI is used in your organization. It answers: who can use which tools, with what data, for what purposes, and who is accountable when something goes wrong. Without one, governance exists only in the absence of incidents.
- Responsible AI (RAI): A set of operating principles covering accountability, fairness, transparency, security, and regulatory compliance that organizations apply to how they develop and deploy AI. EY’s Responsible AI Pulse Survey found only a third of companies have strong controls across all RAI criteria, with CEOs consistently the least confident their organizations meet the standard (EY, 2025).
Extra Reading
- EY Responsible AI Pulse Survey Phase 1, June 2025
- EY Responsible AI Pulse Survey Phase 2, October 2025
- EY Technology Pulse Poll: Autonomous AI Adoption, March 2026
- BDO Finance AI Governance Gap, via Corporate Compliance Insights, November 2025
- AuditBoard AI Governance Implementation Report, August 2025
- Your Team’s Already Using AI. Here’s How to Make That Work for You, Ed Correia