AI Business TransformationBusiness Ops
Our ApproachInsightsStart a Conversation
Data & Research

AI Governance, by the Numbers

The defining fact of AI governance in 2026 is a gap: almost every organization now uses AI, most say they govern it, and only a fraction can show a director what that governance holds. AI is arriving on two tracks at once, a decentralized wave of tools on every desk and a centralized push that now includes agents that act and vendor products with AI already inside. Below is a curated set of statistics on that gap, organized the way our AI Governance Methodology walks it: where organizations really are, how mature governance is, why the moment is now, the regulatory clock, the decisions the business must make, the enforcement layer, and the governance that keeps everything honest. Each figure is labeled and linked to its primary source so you can verify it.

Where organizations really are: AI on two tracks

AI arrives on two legitimate tracks at once. A decentralized wave of productivity tools wherever work gets done, and a deliberate centralized push that now includes redesigning workflows with agents that act and vendor software that ships with AI already inside. The numbers show both tracks moving faster than the governance around them.

~60%

of workers are now equipped with sanctioned AI tools, up from fewer than 40% a year earlier. The decentralized track is now the majority of the workforce, and it is the track most governance approaches were never designed for.

3,235 business and IT leaders, fielded August to September 2025.

40%

of respondents at large organizations report scaling AI agents, up from 27% a year earlier, and 44% now say AI is scaling across their enterprise, up from 38%. Nearly nine in ten report regular use of AI in at least one business function. Systems that act need identities, permissions and limits in much the way people do.

1,719 participants, fielded May 4 to June 8, 2026.

150,000

AI agents in use at the average global Fortune 500 enterprise by 2028, up from fewer than 15 in 2025, in Gartner’s forecast. Agent sprawl is the centralized track’s next governance problem, and it arrives inside vendor products as well as internal builds.

How mature AI governance really is

Most organizations now say they have something. Far fewer have something a director could quote or an engineer could build to. The surveys measure maturity differently, so the range is shown with each figure’s scope rather than collapsed into one number.

2.3 of 4

is the average responsible AI maturity score across roughly 500 organizations, up from 2.0 a year earlier. Only about one-third report level three or higher in strategy, governance and agentic AI governance. Nearly everyone is still early, and the leaders are only modestly ahead.

Fielded December 2025 to January 2026; maturity scored on a four-level scale.

85% / 25%

of companies have implemented a responsible AI program, but only 25% have fully mature frameworks. Having a program and having one that holds are different findings, and the distance between them is where most of the work is.

1,221 respondents in 70 countries and 29 industries, fielded in 2025.

38%

of organizations have a formal, comprehensive AI policy, and 25% have no active policy at all, while 90% of the same respondents believe employees in their organization are using AI.

More than 3,400 digital trust professionals across IT audit, governance, cybersecurity, privacy and emerging technology roles.

8%

of 3,048 U.S. public companies disclosed board-level oversight of AI, and 9% acknowledged having established policies on AI, as of January 2026. Only 16% disclosed a director with specialized AI skills. Governance done visibly and well is still a differentiator.

Russell 3000 and S&P 500 disclosures, published March 3, 2026.

Why now: AI is beginning to act, and incidents are rising

The evidence has caught up on both sides of the ledger. Documented incidents are climbing, breaches now reach the models themselves, and the analysts expect governance gaps in autonomous agents to be found the expensive way: after production incidents.

362

documented AI incidents in 2025, up from 233 in 2024, a 55% rise in one year, in the AI Incident Database count reported by Stanford’s AI Index.

1 in 5

organizations reported a breach targeting their AI models or applications. Of those, 92% lacked proper AI access controls. Across all breaches studied, one in four malicious breaches was AI-enabled, a 56% increase over the prior year.

Research by Ponemon Institute, sponsored and analyzed by IBM; 602 organizations with breaches between March 2025 and February 2026.

40% by 2027

of enterprises will demote or decommission autonomous AI agents because of governance gaps identified only after production incidents occur. The prediction is the case for settling classification and autonomy before agents multiply, not after.

The regulatory clock now has fixed dates

The dates will keep moving, as 2026 has already shown, which is exactly why governance should stand on an organization’s own foundations rather than on any single statute’s deadline. The clock is real all the same, on both sides of the Atlantic.

2 Dec 2027

is when the EU AI Act’s rules for stand-alone high-risk systems (Annex III) apply, after the Digital Omnibus on AI, in force since July 27, 2026, deferred them from August 2026. Rules for AI embedded in regulated products (Annex I) follow on August 2, 2028, and new prohibitions apply from December 2, 2026. Fines for prohibited practices reach EUR 35 million or 7% of worldwide annual turnover, whichever is higher.

150

AI-related bills passed by U.S. states in 2025, up from fewer than 10 in 2020, with California alone enacting 20. Federal agencies issued 58 AI-related regulations in 2025, against one recorded action in 2016.

75% by 2030

of the world’s economies will be covered by fragmented AI regulation, a fourfold expansion, with spending on AI governance platforms expected to reach $492 million in 2026 and pass $1 billion by 2030. The compliance clock is becoming a line item.

The business decides: accountability starts at the top

Governance does not begin with committees or tools. It begins with named ownership, a board that can attest to what it oversees, and a settled answer to how much autonomy each tier of system may have. The research puts a number on each.

2.6 vs 1.8

is the responsible AI maturity gap, on a four-point scale, between organizations that assign clear ownership for responsible AI and those without a clearly accountable function. Ownership is where the maturity gap opens.

1.5x

as likely to operate a cross-functional AI governance board embedded in development and deployment decisions: the AI leaders who capture most of AI’s value, compared with other companies. The board that decides is a feature of the organizations that win, not a cost they carry.

1,217 senior executives, director level and above, across 25 sectors; released April 13, 2026.

4 levels

of agent autonomy in Gartner’s proportional governance model: observe, advise, act with approval, and act autonomously within defined guardrails. Uniform controls fail in two directions, over-restricting simple agents and under-restricting autonomous ones. It is the same logic as a permission table that binds each risk tier to an autonomy level in advance.

Enforcement: rules that live in systems, not in memory

Written rules are half of governance. The other half runs at machine speed: every actor with an identity, guardrails that refuse out-of-bounds actions as they are attempted, an audit trail, a tested way to stop a system, and one door for bought and built AI alike. The numbers show how much of that is still missing.

40%

of organizations report using access controls on AI models and data, and fewer than half are actively securing non-human identities, even as agents create new identities that interact with applications and data.

56%

of digital trust professionals do not know how long it would take to halt an AI system in a security incident, and 39% do not know whether their organization has a documented process for shutting down or overriding AI systems.

58 to 40

is how far the average Foundation Model Transparency Index score fell in 2025, after rising from 37 to 58 between 2023 and 2024. AI companies grew less transparent, which is why bought AI has to walk through the same classification and vendor gate as anything built in-house.

Governance that stays honest, and what it buys

Governance left alone decays, and the organizations that audit, assess and re-sign against evidence are the ones capturing value. On the evidence, governance is not the tax on AI value. It is one of its strongest predictors, and it pays the people it touches.

1.7x

as likely to have a Responsible AI framework in place: the one company in five that captures 74% of AI’s economic value, compared with the rest. Their employees are twice as likely to trust AI outputs. Governance is what the winners have in common, and trust is what it buys them.

1,217 senior executives, director level and above, across 25 sectors; released April 13, 2026.

2x

as likely to realize business benefits from their responsible AI efforts: the responsible AI leaders in BCG and MIT Sloan Management Review’s global survey, compared with non-leaders.

3.4x

more likely to achieve high effectiveness in AI governance: organizations that deployed AI governance platforms, giving centralized oversight, risk management and continuous compliance across all AI assets including third-party and embedded systems, compared with those that did not. Governance that runs continuously outperforms governance that runs once.

Gartner survey of 360 organizations, fielded second quarter 2025, reported February 2026.

48% vs 30%

is the employee engagement rate where managers actively support their team’s use of AI, against where they do not, and a clear organizational plan for integrating AI adds 15 points on its own. Rules that arrive explained, by role, are what turn the decentralized track into a strength.

43,262 U.S. employees, fielded February and May 2026.

What the numbers add up to

Read together, these figures tell one story, and the academic, regulatory and industry sources tell it in unison. Adoption is universal and governance is partial: most organizations have a policy, a quarter to a third have governance that is mature by their own measure, and fewer than one public company in ten discloses board oversight of AI. Meanwhile the estate is changing under the governance that exists. Agents act, vendors ship AI inside the software already running, documented incidents rose 55% in a year, and the regulatory clock has dates on it. What separates the organizations capturing value is not more caution. It is named ownership, rules made once at the right altitude, enforcement built into the systems themselves, and governance that runs continuously rather than once. The one company in five that captures three-quarters of AI’s economic value is the one most likely to have a responsible AI framework and a governance board that decides.

That is exactly what our five-level AI Governance Methodology is built to do: the business decides, technology and security enforce, and every level sits behind a gate. It is built on ISO/IEC 42001, ISO/IEC 42005, the EU AI Act and the NIST AI Risk Management Framework, and it is designed for organizations that are already mid-flight, which is nearly everyone. Read the three-article series for how a client experiences it.

Start a conversation