Policy vs. Practice

98% of surveyed senior AI decision-makers say their organization has formal AI governance policies. 47% say theirs has bypassed the process for urgent deployments. Here is what that means for enterprise buyers.

Policy vs. Practice


98% Report AI Governance Policies. 47% Report Bypassing the Process for Urgent Deployments.

EY's new survey finds 47% of senior AI decision-makers at large US public companies say their organization has previously bypassed its AI governance process for urgent deployments, even though 98% say formal policies are in place. Agentic AI adds a visibility problem: 26% of respondents whose organizations use it say they cannot detect unauthorized AI agents operating internally.

By the numbers

  • Among respondents whose organizations use agentic AI, 49% say their governance framework has not been updated for agentic AI requirements and risks, and 85% say at least a handful of agentic systems act without real-time human involvement.

  • 41% say senior leaders lack visibility into all AI tools operating in their organization.

  • 36% report an AI incident or failure with materially negative impact, including data loss, financial damage, operational disruption or brand damage.

  • Of respondents whose organizations ran formal AI reviews, 92% found issues and 64% significantly modified a quarter or more of their AI systems.

Why it matters

EY's Richard Jackson says moving fast and applying appropriate governance are not mutually exclusive. Two gaps stand out in the data: urgent deployments that skip the process, and agents leaders cannot detect. A policy cannot govern what leaders cannot see.

Yes but

The sample is 202 senior AI decision-makers at US public companies with at least $1 billion in annual revenue, and every figure reflects what respondents told EY. The margin of error is plus or minus 7 percentage points. EY's Assurance team commissioned the survey, and EY also offers AI risk services.

What buyers should ask

The survey covers organizations governing their own AI, not vendors, but the question carries over. Buyers evaluating AI vendors should ask what happens to the governance process when a deployment is urgent. A vendor who can answer that gives buyers evidence a written policy alone does not.

What to watch

EY says the next phase of AI governance is less about writing policies and more about demonstrating that they work: visibility across the full AI estate, clear accountability for autonomous activity, and controls built into deployment workflows. Watch which vendors and organizations can show that in practice.

Works Cited

  • "EY Survey Finds That Autonomous AI Implementation Outpaces Oversight, Yielding an AI Governance Gap." EY, 15 Sept. 2026, ey.com/en_us/newsroom/2026/09/ey-survey-finds-that-autonomous-ai-implementation-outpaces-oversight-yielding-an-ai-governance-gap.

  • "AI Governance Has Entered Its Next Phase: Closing the Confidence Gap." EY, 15 Sept. 2026,

  • ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap.

Related briefs

  • AI Agent Governance: Trust Without Control — AI agents are gaining organizations’ trust faster than the controls needed to manage them. A new Harness survey shows a gap between confidence in AI agents and the systems in place to test, secure, and stop them when things go wrong.
  • AI Is Running Government. Accountability Is Not Keeping Up. — More than half of government organizations are using AI. Less than half have a formal policy for it. That is not a planning failure. It is an accountability gap that is already producing consequences.
  • What Happens When You Add AI Into Education — 85% of teachers feel unprepared to manage AI in their classrooms. 86 percent of students are already using it. That gap does not close on its own. Here is what it actually requires.

← Back to Knowledge Hub