State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.

Last Updated: 5 October 2026
State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.
div{flex:1 1 170px;border-top:3px solid #0284c7;padding-top:10px}
.aig-time .aig-grid>div span{display:block;font-size:14px;line-height:1.

State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.

State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.

Last Updated: 5 October 2026
State of AI Governance 2026: Everyone Sees the Risk. Almost No One Can See the AI.
Survey report477 respondents6 findings9 min read

Everybody is talking about AI governance. Regulators are writing the rules. Boards are asking questions. And most organizations still cannot answer the most basic question in governance: what AI are we actually running?

Over recent months I asked security, risk and technology leaders what they actually have in place. Not what their policy says. What exists today. 477 people answered. The short version: AI governance has moved from awareness to triage. Almost everyone recognizes the risk. Very few can show evidence that they have it under control.

Key takeaways
  • Only 1 in 9 respondents can see all the AI they run.
  • Shadow AI is widespread: 42.3% think over a quarter of their AI is unsanctioned.
  • EU AI Act readiness averages 2.77 out of 5, and the Digital Omnibus delay is planning time, not a reprieve.
  • Nearly 2 in 3 boards get no regular AI risk reporting.
  • The fix is fundamentals: inventory, literacy, board reporting, a framework.

The headline numbers

11.5%have a complete and current AI inventory
42.3%estimate more than a quarter of their AI tools are unsanctioned
2.77 / 5average self-rated EU AI Act deployer readiness
64.2%give their board no regular AI risk reporting
33.3%have no AI governance framework
26.6%had an AI-related incident in the last 12 months (11.1% are not sure)

Who answered

The sample leans toward the people who own AI risk day to day. Most respondents work in organizations with more than 1,000 people (66.6%).

GRC / Risk / Compliance23.9%
VP / Director of Security19.3%
Consultant / Advisor13.8%
DPO / Privacy counsel9.4%
CIO / CTO9.2%
Technology21.6%
Financial services18.0%
Healthcare16.4%
Manufacturing / Critical infra13.2%
Government / Public sector12.4%
Higher education8.2%
Other10.3%

Finding 1: You cannot govern what you cannot see

Only 55 of 477 respondents (11.5%) report a complete and current inventory of their AI systems. Another 43.4% say theirs is partial: they know the big ones, and the rest is fog. 34.2% have no inventory at all, and 10.9% have not started. That means nearly nine in ten respondents are trying to govern an AI estate they cannot fully see.

Do you have an inventory of the AI your organization uses?
Yes, complete and current11.5%

Partial (we know the big ones)43.4%

Have not started10.9%

n = 477 respondents

Every governance framework starts with scoping. NIST AI RMF does. ISO/IEC 42001 does. The EU AI Act starts with knowing which systems you deploy. If your inventory is partial, your risk assessments are partial, your controls are partial, and your board reports are describing an estate that does not match reality.

A 30-day inventory sprint: discover, classify, assign owners. It does not need budget. It needs someone willing to ask every department uncomfortable questions.

Finding 2: Shadow AI is not a rounding error

When asked what share of their AI tools are unsanctioned, the largest group (33.3%) estimated 11 to 25 percent. Nearly as many (31.0%) said 26 to 50 percent, and 11.3% said more than half. Another 6.9% said they had no idea, which is an answer in itself.

Roughly what share of AI tools in your organization are unsanctioned?
0 to 10%17.4%

11 to 25%33.3%

26 to 50%31.0%

More than 50%11.3%

No idea6.9%

n = 477 respondents · highlighted: more than 25% unsanctioned (42.3% combined)

These are estimates, not measurements, and that is part of the point. If leaders are guessing, the inventory gap from Finding 1 is showing up again from a different angle.

This is also where incidents come from. In the last 12 months, 16.1% of respondents reported a data exposure through an AI tool, and 10.5% reported another AI-related incident. How many of those involved tools the security team did not know existed? This survey did not ask. The next one will.

Have you had an AI-related incident in the last 12 months?
Yes, data exposure via an AI tool16.1%

Yes, another AI-related incident10.5%

Not sure11.1%

n = 477 respondents

Shadow AI is a usability problem wearing a security costume.

Erdal Ozkaya

Employees are rarely being malicious. They are being productive. They found a tool that writes their report faster, and nobody explained where the data they pasted into it goes. Solve it with sanctioned alternatives and clear guardrails, not with bans nobody enforces.

Finding 3: EU AI Act readiness sits at 2.77 out of 5

54.1% of respondents identify as deployers under the EU AI Act: they buy and use AI. 8.4% are providers only, and 14.5% are both, so 68.6% carry deployer obligations. Another 13.2% are not sure whether the Act applies to them at all.

How ready are you for your EU AI Act deployer obligations? (self-rated)
1 (lowest)5.9%

5 (fully ready)1.5%

n = 477 respondents · mean 2.77 · highlighted: scores of 1 or 2 (37.9%)
Where the EU AI Act timeline stands
Already appliesProhibited practices, AI literacy, general-purpose AI rules (since Aug 2025)
2 Dec 2026New prohibitions added by the Digital Omnibus
2 Dec 2027Stand-alone high-risk systems (Annex III)
2 Aug 2028High-risk AI embedded in products (Annex I)

The Digital Omnibus, in force since July 2026, moved the main high-risk deadlines. Do not read that as a reprieve. The extra time is planning time, and most respondents have a lot of planning to do.

If you are a deployer and do not know where you stand, start with the basics: inventory, classify your use cases by risk tier, close the literacy gap, and document everything. Regulators do not grade intentions. They grade evidence. [Link to EU AI Act 90-day deployer action plan]

Finding 4: Most boards are flying blind on AI risk

35.0% of respondents give their board no AI risk reporting. Another 29.1% report only ad hoc, when something happens. Combined, 64.2% of boards get no regular, structured view of AI risk, while they approve AI budgets, strategies and transformation programs.

How often does your board receive AI risk reporting?
No reporting35.0%

Ad hoc, when something happens29.1%

Annually18.7%

Quarterly17.2%

n = 477 respondents

Annual reporting is barely better. AI risk moves in weeks, not fiscal years. Quarterly is the minimum credible cadence, and only if the underlying metrics mean something. Board reporting is a translation exercise, and AI makes it harder because many boards still treat AI as a technology topic rather than a business risk.

The quarterly AI risk board report
  1. What AI decisions did we make?
  2. What risks did we accept?
  3. What incidents did we have?
  4. How ready are we for the regulation that can fine us?
Four slides. Every quarter. No jargon.

Finding 5: Generic awareness training does not cover AI

Only 21.4% of respondents run role-based AI literacy training. The largest group (34.0%) relies on generic security awareness alone. 22.4% have something planned but not launched, and 22.2% have nothing.

Do you have an AI literacy program?
Yes, role-based training21.4%

Generic security awareness only34.0%

Planned, not launched22.4%

n = 477 respondents

Generic phishing training does not teach a marketing manager why pasting customer data into a public chatbot is a data protection problem. It does not teach developers about prompt injection or model abuse, or teach HR about bias in screening tools. AI risk is role-specific, so AI literacy has to be role-specific.

Regulatory note

Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy among the people using their AI systems. A once-a-year slide deck is unlikely to meet that bar, and it will not protect you either.

Finding 6: A third of organizations have no framework

Which AI governance framework do you use?
None yet33.3%

Built our own24.5%

NIST AI RMF20.3%

Vendor-provided framework9.2%

ISO/IEC 420018.6%

Ozkaya AIGF*4.0%

n = 477 respondents · *AIGF is the author’s own framework, see the note below

There is no single right answer here. NIST AI RMF is the most mature public option. ISO/IEC 42001 gives you certifiability. A homegrown framework is fine if it is actually implemented, and many are not. What is not fine is nothing. “We are figuring it out” is not a framework. Pick one, adapt it, implement it imperfectly if you must, then improve it.

A note on transparency: AIGF is my own framework, and part of this sample came through my own network and readers. I included it as an option because people ask me about it, but I would not read the 4.0% as a market adoption figure.

What this means

Strip away the percentages and the story is simple. Everyone knows AI governance matters. Very few have it under control. Organizations are adopting AI faster than they can see it and reporting on it slower than the risk moves.

The good news is that none of this needs exotic technology. Inventory, classification, literacy, board reporting and a framework are disciplines, not products. The organizations that close the gap will not be the ones with the biggest AI budgets. They will be the ones that did the boring fundamentals first.

Your 90-day fix

1DAYS 1 TO 30

See it

Run the inventory sprint. Discover every AI tool in use, sanctioned or not. Classify by risk tier. Assign an owner to each one. No owner, no governance.

2DAYS 31 TO 60

Tame it

Stand up your framework, close the worst shadow AI gaps with sanctioned alternatives, and launch role-based literacy for your highest-risk groups first.

3DAYS 61 TO 90

Prove it

Start quarterly board reporting on AI risk, document your EU AI Act deployer obligations with evidence, and run a tabletop exercise on an AI incident. If you cannot evidence it, you cannot claim it.

The full deployer playbook is in my EU AI Act 90-day action plan, and the governance model underneath it is the Ozkaya AI Governance Framework link. Both are free.

Methodology and limitations

Responses were collected in 2026 through an online survey. Respondents were reached through a QR code distributed at a CIO summit, through this blog, and by respondents sharing the survey with peers. 477 responses were included in the analysis.

This is a convenience sample, not a random one. People who attend CIO events, read my work, or were referred by colleagues are likely more engaged with AI governance than the average organization, so the wider picture may be worse than these numbers suggest. Readiness and shadow AI figures are self-reported estimates. Some sectors, including higher education (39 respondents), are too small to analyze on their own.

Frequently asked questions

What is the state of AI governance in 2026?

Widely recognized, poorly operationalized. In a 2026 survey of 477 security, risk and technology leaders, only 11.5% reported a complete and current AI inventory, average self-rated EU AI Act deployer readiness was 2.77 out of 5, and 64.2% said their board receives no regular AI risk reporting.

How much AI use is shadow AI?

Among survey respondents, 42.3% estimated that more than a quarter of their AI tools are unsanctioned, and 11.3% estimated more than half. Another 6.9% said they had no idea, which is itself a governance finding.

How ready are organizations for the EU AI Act?

Not ready enough. 68.6% of respondents carry deployer obligations, average self-rated readiness was 2.77 out of 5, only 1.5% rated themselves fully ready, and 13.2% were unsure whether the Act applies to them.

How often should boards receive AI risk reporting?

Quarterly at minimum. AI risk moves too fast for annual reporting. Each report should cover AI decisions made, risks accepted, incidents, and regulatory readiness.

Which AI governance framework should we adopt?

NIST AI RMF is the most mature public option, ISO/IEC 42001 offers certifiability, and a well-implemented homegrown framework is legitimate. What matters most is picking one and implementing it. A third of respondents currently have none.

Shape the next reportThe 2027 survey will ask the question this one missed: how many AI incidents came from tools security did not know existed. Add your organization to the sample, or tell me where these numbers do not match what you see.
Take the survey

Erdal Ozkaya is a CISO, author and keynote speaker. He writes about AI governance, board-level cybersecurity, and the realities of running security in large organizations.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.