State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.
State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.
State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.
Everybody is talking about AI governance. Regulators are writing the rules. Boards are asking questions. And most organizations still cannot answer the most basic question in governance: what AI are we actually running?
Over recent months I asked security, risk and technology leaders what they actually have in place. Not what their policy says. What exists today. 477 people answered. The short version: AI governance has moved from awareness to triage. Almost everyone recognizes the risk. Very few can show evidence that they have it under control.
- Only 1 in 9 respondents can see all the AI they run.
- Shadow AI is widespread: 42.3% think over a quarter of their AI is unsanctioned.
- EU AI Act readiness averages 2.77 out of 5, and the Digital Omnibus delay is planning time, not a reprieve.
- Nearly 2 in 3 boards get no regular AI risk reporting.
- The fix is fundamentals: inventory, literacy, board reporting, a framework.
The headline numbers
Who answered
The sample leans toward the people who own AI risk day to day. Most respondents work in organizations with more than 1,000 people (66.6%).
Finding 1: You cannot govern what you cannot see
Only 55 of 477 respondents (11.5%) report a complete and current inventory of their AI systems. Another 43.4% say theirs is partial: they know the big ones, and the rest is fog. 34.2% have no inventory at all, and 10.9% have not started. That means nearly nine in ten respondents are trying to govern an AI estate they cannot fully see.
Every governance framework starts with scoping. NIST AI RMF does. ISO/IEC 42001 does. The EU AI Act starts with knowing which systems you deploy. If your inventory is partial, your risk assessments are partial, your controls are partial, and your board reports are describing an estate that does not match reality.
Finding 2: Shadow AI is not a rounding error
When asked what share of their AI tools are unsanctioned, the largest group (33.3%) estimated 11 to 25 percent. Nearly as many (31.0%) said 26 to 50 percent, and 11.3% said more than half. Another 6.9% said they had no idea, which is an answer in itself.
These are estimates, not measurements, and that is part of the point. If leaders are guessing, the inventory gap from Finding 1 is showing up again from a different angle.
This is also where incidents come from. In the last 12 months, 16.1% of respondents reported a data exposure through an AI tool, and 10.5% reported another AI-related incident. How many of those involved tools the security team did not know existed? This survey did not ask. The next one will.
Shadow AI is a usability problem wearing a security costume.
Erdal Ozkaya
Employees are rarely being malicious. They are being productive. They found a tool that writes their report faster, and nobody explained where the data they pasted into it goes. Solve it with sanctioned alternatives and clear guardrails, not with bans nobody enforces.
Finding 3: EU AI Act readiness sits at 2.77 out of 5
54.1% of respondents identify as deployers under the EU AI Act: they buy and use AI. 8.4% are providers only, and 14.5% are both, so 68.6% carry deployer obligations. Another 13.2% are not sure whether the Act applies to them at all.
The Digital Omnibus, in force since July 2026, moved the main high-risk deadlines. Do not read that as a reprieve. The extra time is planning time, and most respondents have a lot of planning to do.
If you are a deployer and do not know where you stand, start with the basics: inventory, classify your use cases by risk tier, close the literacy gap, and document everything. Regulators do not grade intentions. They grade evidence. [Link to EU AI Act 90-day deployer action plan]
Finding 4: Most boards are flying blind on AI risk
35.0% of respondents give their board no AI risk reporting. Another 29.1% report only ad hoc, when something happens. Combined, 64.2% of boards get no regular, structured view of AI risk, while they approve AI budgets, strategies and transformation programs.
Annual reporting is barely better. AI risk moves in weeks, not fiscal years. Quarterly is the minimum credible cadence, and only if the underlying metrics mean something. Board reporting is a translation exercise, and AI makes it harder because many boards still treat AI as a technology topic rather than a business risk.
- What AI decisions did we make?
- What risks did we accept?
- What incidents did we have?
- How ready are we for the regulation that can fine us?
Finding 5: Generic awareness training does not cover AI
Only 21.4% of respondents run role-based AI literacy training. The largest group (34.0%) relies on generic security awareness alone. 22.4% have something planned but not launched, and 22.2% have nothing.
Generic phishing training does not teach a marketing manager why pasting customer data into a public chatbot is a data protection problem. It does not teach developers about prompt injection or model abuse, or teach HR about bias in screening tools. AI risk is role-specific, so AI literacy has to be role-specific.
Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy among the people using their AI systems. A once-a-year slide deck is unlikely to meet that bar, and it will not protect you either.
Finding 6: A third of organizations have no framework
There is no single right answer here. NIST AI RMF is the most mature public option. ISO/IEC 42001 gives you certifiability. A homegrown framework is fine if it is actually implemented, and many are not. What is not fine is nothing. “We are figuring it out” is not a framework. Pick one, adapt it, implement it imperfectly if you must, then improve it.
A note on transparency: AIGF is my own framework, and part of this sample came through my own network and readers. I included it as an option because people ask me about it, but I would not read the 4.0% as a market adoption figure.
What this means
Strip away the percentages and the story is simple. Everyone knows AI governance matters. Very few have it under control. Organizations are adopting AI faster than they can see it and reporting on it slower than the risk moves.
The good news is that none of this needs exotic technology. Inventory, classification, literacy, board reporting and a framework are disciplines, not products. The organizations that close the gap will not be the ones with the biggest AI budgets. They will be the ones that did the boring fundamentals first.
Your 90-day fix
See it
Run the inventory sprint. Discover every AI tool in use, sanctioned or not. Classify by risk tier. Assign an owner to each one. No owner, no governance.
Tame it
Stand up your framework, close the worst shadow AI gaps with sanctioned alternatives, and launch role-based literacy for your highest-risk groups first.
Prove it
Start quarterly board reporting on AI risk, document your EU AI Act deployer obligations with evidence, and run a tabletop exercise on an AI incident. If you cannot evidence it, you cannot claim it.
The full deployer playbook is in my EU AI Act 90-day action plan, and the governance model underneath it is the Ozkaya AI Governance Framework link. Both are free.
Methodology and limitations
Responses were collected in 2026 through an online survey. Respondents were reached through a QR code distributed at a CIO summit, through this blog, and by respondents sharing the survey with peers. 477 responses were included in the analysis.
This is a convenience sample, not a random one. People who attend CIO events, read my work, or were referred by colleagues are likely more engaged with AI governance than the average organization, so the wider picture may be worse than these numbers suggest. Readiness and shadow AI figures are self-reported estimates. Some sectors, including higher education (39 respondents), are too small to analyze on their own.
Frequently asked questions
What is the state of AI governance in 2026?
Widely recognized, poorly operationalized. In a 2026 survey of 477 security, risk and technology leaders, only 11.5% reported a complete and current AI inventory, average self-rated EU AI Act deployer readiness was 2.77 out of 5, and 64.2% said their board receives no regular AI risk reporting.
How much AI use is shadow AI?
Among survey respondents, 42.3% estimated that more than a quarter of their AI tools are unsanctioned, and 11.3% estimated more than half. Another 6.9% said they had no idea, which is itself a governance finding.
How ready are organizations for the EU AI Act?
Not ready enough. 68.6% of respondents carry deployer obligations, average self-rated readiness was 2.77 out of 5, only 1.5% rated themselves fully ready, and 13.2% were unsure whether the Act applies to them.
How often should boards receive AI risk reporting?
Quarterly at minimum. AI risk moves too fast for annual reporting. Each report should cover AI decisions made, risks accepted, incidents, and regulatory readiness.
Which AI governance framework should we adopt?
NIST AI RMF is the most mature public option, ISO/IEC 42001 offers certifiability, and a well-implemented homegrown framework is legitimate. What matters most is picking one and implementing it. A third of respondents currently have none.
Take the survey
Erdal Ozkaya is a CISO, author and keynote speaker. He writes about AI governance, board-level cybersecurity, and the realities of running security in large organizations.
