TL;DR — Key Takeaways

  • EY found that 47% of surveyed AI decision-makers said their organizations had skipped governance processes during urgent AI deployments, even though 98% had formal policies.
  • Among organizations using agentic AI, 49% had not updated governance frameworks for agentic systems and 26% could not detect unauthorized AI agents operating internally.
  • EY recommends clearer accountability, controls built into deployment workflows, greater visibility into AI systems and recurring verification that agents behave as intended.

Companies are deploying AI faster than their governance processes can keep up, according to a new survey from Ernst & Young.

In EY’s inaugural U.S. AI Risk and Governance Survey, 98% of respondents said their organizations have formal AI governance policies, and 47% acknowledged that their companies had previously skipped their governance process during urgent deployments. The survey covered 202 senior AI decision-makers at US publicly traded companies with at least $1 billion in annual revenue.

Agentic AI adds another layer of difficulty to this uneven governance picture. Ninety-one percent of respondents said their organizations use agentic AI through either active pilot programs or full enterprise deployments, but 49% of those using the technology said their existing governance frameworks had not yet been updated to specifically address agentic AI risks and requirements. Another 26% said their organizations could not detect unauthorized AI agents operating internally.

These visibility problems can pose risks because some systems already take action without immediate human approval. Among organizations using agentic AI, 85% of respondents said at least a handful of their agentic systems execute actions without real-time human involvement, including detecting cybersecurity threats and running code.

Richard Jackson, a chief technology officer and AI leader in EY’s Assurance practice, said executives are under pressure to move quickly on AI, but “moving fast and applying appropriate governance are not mutually exclusive.” He warned that inadequate oversight can create real business risks.

The survey suggests the business risks Jackson warned about are already showing up in practice. Eighty-nine percent of respondents said their organizations encountered some form of AI-related risk during the previous year, while 36% reported an AI incident or failure that caused a materially negative impact, including data loss, financial damage, operational disruption or harm to the company’s brand.

Formal reviews are also finding problems significant enough to prompt changes to AI systems. EY said 98% of respondents reported conducting a formal AI assurance review at least annually, and 92% of organizations conducting those reviews found issues. Among companies that performed reviews, 64% significantly modified at least a quarter of their AI systems, while 29% paused at least a quarter and 25% stopped at least a quarter altogether.

The challenge now is translating governance policies into controls that hold up during deployment, and EY argues that addressing it requires more than visibility. It recommends that organizations establish clear accountability for autonomous activity, build controls into deployment workflows, maintain visibility into AI systems in use and regularly verify that those systems are behaving as intended. Read more about the survey here.