Skip to main content

On-demand webinar coming soon...

On-demand webinar coming soon...

On-demand webinar coming soon...

The OneTrust 2026 AI-Ready Governance Survey Report

Has AI Outgrown Governance?

AI adoption is creating a governance gap.

Organizations are moving AI into business functions while employees continue to adopt new tools and agents. Governance has advanced alongside that adoption, but not at the same pace or consistency organizations need.

More than half of business leaders say AI governance is integrated into the AI lifecycle, but 47% describe their programs as reactive, fragmented, slow, or manual. Just 17% say governance is embedded by design.

New research highlights where AI governance is advancing and where disconnected execution is creating risk. 

AIG Surye report cover thumbnail

OneTrust and Sapio Research surveyed 1,200 senior business decision-makers across eight markets, including CPO, CDO, CISO, and CMO leaders.

The Market Has Built Foundations

The Next Test Is Connection

AI adoption has moved beyond isolated pilots for most organizations. Nearly three-fourths (74%) report departmental report departmental or scaled AI adoption, and 52% use AI across multiple business functions or have embedded it into business processes and operations.

Governance has also moved forward. But only 5% say coordination and accountability are clear across the AI lifecycle.

AI Governance Statistics
74%

Departmental or scaled AI adoption

52%

Use AI across multiple business functions

5%

Clear coordination and accountability
across the AI lifecycle

On-demand webinar coming soon...

Agent Adoption Is Exposing the Next Governance Gap 

AI agents provide the survey’s clearest comparison between adoption and governance readiness.

87% of respondents say their organizations encourage agent use, while only 47% say that use is supported by clear governance, oversight, and controls. Another 40% encourage use while governance and controls continue to develop.

Organizations are opening access to agents while they continue to define the rules that surround agent activity.

Agent Encouragement is Outpacing Clear Governance

AI Agent Use Statistics

87%

Encourage AI agent use

47%

Have clear governance in place

On-demand webinar coming soon...

Shadow AI and Coordination Gaps Are Defining Operating Risks 

Shadow AI is a defining visibility challenge for enterprise AI governance. Most organizations can see their approved AI. Far fewer can see everything else.

Nearly half (48%) report clear visibility into sanctioned and unsanctioned AI use. Another 46% have good visibility into approved AI, but limited visibility into employee-led or unsanctioned use.

That gap creates operating risk. One-third experienced employees using unapproved AI tools because approved options or processes were not available quickly enough. Thirty-one percent identified use cases for review after they were already in use.

Organizations are doing the work, but ownership, context, controls, and evidence do not always move consistently from intake through deployment and ongoing use.

Organizations can see their approved AI

Horizontal Percentage Pills
48%

Clear visibility into sanctioned and unsanctioned AI use

46%

Good visibility into approved AI with limited visibility elsewhere

On-demand webinar coming soon...

Shadow AI creates the operating risk

Unapproved AI Usage Statistics
33%

Experienced employees using unapproved AI tools

31%

Identified use cases for review after they were already in use

On-demand webinar coming soon...

AI Incidents Are Now Baseline

Response Is Getting Stronger

AI incidents are no longer edge cases. They’ve moved from ‘if’ to ‘when.’

Eighty-six percent of organizations experienced at least one AI-related incident during the past year. Among those respondents, 99% took meaningful action.

Nearly half (45%) implemented formal AI review and approval processes, while 43% expanded monitoring or governance controls.

The response is moving toward stronger governance capacity—not simply slowing down AI. 

Percentage Pills
86%

Of organizations experienced at least one AI-related incident during the past year

45%

Implemented formal AI review and approval process

On-demand webinar coming soon...

What This Means for Security and Risk Leaders

AI governance is starting to move into operations, but a significant gap remains. Organizations have built governance activities and controls, yet those efforts are not consistently connected across business functions, third parties, and agents as AI scales.

Continuous Visibility

See where AI is being used and how that use changes over time.

Scalable Governance

Keep reviews moving at the pace of adoption.

Enforced Guardrails

Carry governance decisions into active AI workflows.

Connected Accountability

Give teams clear ownership across the AI lifecycle.

Go Deeper Into the Data 

The full 2026 AI-Ready Governance Survey Report provides the detail needed to benchmark your organization and plan the next phase of governance.

Explore the full findings on:

  • AI governance maturity
  • Agent adoption and oversight
  • AI-related incidents and response actions
  • Governance investment priorities

Download the 2026 OneTrust AI-Ready Governance Survey Report

Complete the form to access the full report and explore how organizations are moving from individual governance activities to connected operations as AI scales.


Frequently Asked Questions

This report is designed for CISOs and other senior leaders responsible for security, risk, privacy, data, AI, and enterprise governance.

OneTrust and Sapio Research surveyed 1,200 senior business decision-makers in June and July 2026 across Australia, Canada, France, Germany, Singapore, Spain, the United Kingdom, and the United States.

The sample included equal representation from CPO, CDO, CISO, and CMO audiences. All respondents worked at organizations with at least $100 million in annual revenue.

Organizations have established many AI governance activities, but those activities are not yet consistently connected across teams, systems, vendors, and lifecycle stages.

Shadow AI refers to AI tools and agents adopted by employees or teams outside formal approval and oversight processes. It is the AI equivalent of shadow IT.

The risk is not the tools themselves. It is the lack of visibility, controls, and accountability around how they are used. When security and risk teams cannot see unapproved AI activity, they cannot assess exposure, enforce policy, or respond to incidents.

AI-ready governance means having the visibility, processes, controls, and accountability structures across the entire business to manage AI at the pace and scale of the business.

It requires continuous monitoring of AI use across functions, vendors, and agents, along with the ability to adapt as adoption changes.

AI agents introduce specific governance challenges because they can act autonomously, initiate processes, and interact with third-party systems in ways that are harder to monitor than traditional AI use.

Governance programs need clear policies for agent use, approval workflows before deployment, and ongoing monitoring after deployment. The gap between agent adoption at 87% and clear governance and controls at 47% reflects how quickly organizations are opening access without first defining the rules that should surround it.