Your Cart
Loading

AI Governance Policies Look Great on Paper. EY Just Measured How Often Companies Actually Use Them.

202 senior leaders at billion-dollar companies told EY nearly the same thing: they have a policy, and they go around it anyway. Here's what that gap means for a business running AI with no policy at all.


What Happened


EY published survey results on September 15 from 202 senior AI decision-makers — board members, C-suite executives, and VP-level leaders — at publicly traded companies with at least $1 billion in annual revenue. Fieldwork ran from May 28 through June 15, 2026, with a margin of error of ±7 percentage points at a 95% confidence level.


The headline finding: 98% of these companies have a formal AI governance policy in place. But 47% of respondents admitted their organization has “previously not applied its AI governance process for urgent deployments” — in plain terms, when the pressure was on, they went around their own rules.

The gaps compound from there. 91% of these companies are already running agentic AI, in pilots or full deployment, but 49% haven't updated their governance frameworks to address what agents specifically can do. 85% admit their agentic AI systems take actions without real-time human oversight. Just over a quarter — 26% — say they can't detect unauthorized AI agents operating inside their own organization. And 36% reported an AI incident in the past year with a “materially negative impact,” including data loss and financial damage.


Richard Jackson, EY Americas Assurance CTO, summed up the disconnect: “Organizations are applying yesterday's governance rules to today's interactions with AI.”


Why It Matters


These aren't undercapitalized startups winging it. These are billion-dollar companies with board-level sign-off and, in nearly every case, an actual written policy. And the policy still isn't what's running the show day to day — when a deployment gets urgent, close to half the companies surveyed admit the process gets skipped.


That's the real finding here, more than any single statistic: a governance policy that exists on paper but isn't built into how the work actually gets done isn't governing anything. It's a document, not a system. The same survey found that most of these companies don't have the internal expertise to close that gap either — 63% said they lack the expertise to design or implement governance controls, and 69% are specifically worried about keeping up as agentic AI moves faster than their rules can adapt.


What It Means for a Small Business


It would be easy to read this and think, “that's an enterprise problem — we don't have agents running loose across a global org chart.” But scale it down instead of dismissing it, and the same shape of gap shows up, just without a survey to prove it:


A rule that isn't actually followed. Most small businesses don't have a written AI policy at all, but plenty of operators have an informal one — “always double-check anything client-facing,” say — that gets skipped exactly when things are busiest. That's the same moment EY's respondents said theirs breaks down too.


Not knowing what's actually running. If a company with dedicated IT and security staff can't account for a quarter of its own AI agents, an operator who's added a chatbot here, an automated email drafter there, and a bookkeeping tool somewhere else almost certainly can't give a clean answer either.


No one assigned to catch it. EY's finding that 85% of agentic AI acts without real-time oversight has a small-business version: AI drafts something, and there's no defined moment where a human actually reviews it before it goes out, because nobody decided whose job that is.


Finding out after it's already shipped. Enterprise incidents show up as data loss or financial damage. For a small business, the equivalent is a customer, a client, or a public post that reveals the mistake — after it's already out in the world, not before.


To be clear: EY surveyed billion-dollar companies, not small businesses — there's no matching data on how solo operators fare. But the structural gap they measured — a policy that exists without the operating habits to back it up — doesn't require a large org chart to happen. It just requires nobody having built the habit in yet.


What to Do Next


The fix EY's respondents are missing isn't more urgency about AI — it's structure that holds up under urgency, which is a different thing entirely. Three places to start:

  1. Write down which AI tools are actually touching your business right now, and who's responsible for checking each one's output. If you can't answer that in a sentence per tool, that's your gap.
  2. Decide, in advance, where a human has to look before something ships — not after a mistake makes that decision for you.
  3. Build that into something more durable than a mental note, so it survives being busy or distracted — the exact condition EY's own respondents said their governance broke down under.


That third step is the one almost nobody does on their own — not because it's complicated, but because there's rarely a template sitting around for it. That's what Scalable Studio System's Build Your AI Project God Mode — Complete Kit ($97, on Payhip) is built to install: a 7-stage framework — Ground, Organize, Define, Map, Operate, Direct, Evolve — plus the workbook, templates, and copy-paste files to set up real decision rights, quality gates, and a maintenance rhythm inside a ChatGPT or Claude project, instead of relying on a rule everyone agrees to and nobody follows once things get busy.


Governance that only holds up when nothing urgent is happening isn't governance. EY just measured how often that's the version most companies actually have.



Sources


EY — EY survey finds that autonomous AI implementation outpaces oversight, yielding an AI governance gap — https://www.ey.com/en_us/newsroom/2026/09/ey-survey-finds-that-autonomous-ai-implementation-outpaces-oversight-yielding-an-ai-governance-gap

Cybersecurity Dive — Companies' AI strategies don't account for agentic tools — https://www.cybersecuritydive.com/news/ai-governance-agents-ey/830282/

CIO Dive — Businesses sidestep AI governance policies as concerns mount — https://www.ciodive.com/news/EY-governance-AI-policies-sidestep/830561/