Where Organizations Really Are With AI
Nearly every large organization is now somewhere on the AI journey, and most are further along than their org charts suggest. AI is arriving not as one thing, but as many. Assistants draft and summarize, models predict and classify, agents carry out multistep work, and AI features come embedded in software vendors already provide. There is no one-size-fits-all AI capability, and therefore no one-size-fits-all way to adopt it.
The pilot era of the past two years did exactly what it was supposed to do. It taught your people what these tools can and cannot do, surfaced the places where AI genuinely helps, and built a base of experience no planning document could have produced. What is happening now is not a retreat from that energy, but a maturation of it. Organizations are not shutting down their pilots. They are ready to organize around a more methodical approach. That is the moment governance earns its keep. To govern well, it helps to name the moment honestly. AI is rolling out along two tracks at once, and both are legitimate.
The First Track Is Decentralized, and It Should Stay That Way
Organizations are encouraging teams and employees to use generative AI to become more productive, and the best of these tools have become remarkably capable. Assistants such as Anthropic’s Claude, and its Cowork capability in particular (or Gemini Spark or ChatGPT Work), can now serve as general-purpose productivity partners, improving both the quantity of work employees complete and the quality of what they produce. Just as important, these tools allow individuals and departments to build small, custom solutions of their own. For example, one person may create a tool for herself, shaped around her particular blind spots and never intended for team-wide use, while a colleague with different strengths builds something else to complete the same task.
Multiplied across an organization, the result is a healthy proliferation of personal and departmental AI wherever work gets done. It is tempting for a leadership team to look at that spread and see disorder. We would encourage the opposite reading. This is what successful adoption of a general-purpose technology looks like. Its value concentrates in efficiency and stronger bottom-line margins, with a meaningful contribution to the top line as well.
This track has governance needs of its own, and they are modest but real. The organization should know what is in use, be clear about which data may never enter which tools, and ensure the sanctioned options are good enough that nobody needs to work around them. What this track does not need is heavy process. The task ahead is not to rein it in. It is to give it boundaries people can trust and legitimacy they can build on.
The Second Track Is Centralized, from Point Solutions to Transformation
Alongside the productivity wave, organizations are undertaking deliberate programs to redesign core workflows around what AI makes possible. These are enterprise efforts, demanding cross-functional coordination, sustained resources, and executive attention because they redefine how the business actually does its work. This is where AI most directly supports top-line growth, and where governance is most obviously nonnegotiable. A program that changes how work flows must be able to show whose rules it runs on.
This track is wider than the flagship transformation program, and it is worth saying so. Its most common form today is the point solution, a technology solution bought to put AI to work on one function’s problem. Think of a voice agent that handles tier-one customer calls and hands the rest to a human team. Nobody convenes an enterprise redesign program for it, yet it is no employee productivity tool either. It acts on the organization’s behalf, it faces customers, and it arrives carrying its vendor’s design choices. Most deliberately adopted AI arrives this way for now, bought rather than built. This second track is best pictured as a spectrum, running from a single purchased point solution serving one function to a full redesign of how the business works, with the same rules applying across it at a depth scaled to what is at stake.
The governance questions this track raises are different in kind, not simply in degree. When a redesigned workflow allows an AI system to approve transactions below a threshold, someone with real authority must have decided that threshold, or nobody did. When an agent interacts directly with customers, someone must set the boundaries of that interaction. Otherwise, the boundaries are whatever the technology happened to ship with. These are not questions a well-meaning project team should have to answer alone. Yet, in organizations without a governance program, that is exactly who ends up answering them, one team at a time, each doing its conscientious best without a shared frame.
One Governance Discipline Has to Hold Both Tracks
The point of naming both tracks is that one governance discipline has to hold them together. The scattered many need to be counted, welcomed into the light, and given clear boundaries without being smothered. The transformative few need real gates, named accountability, and enforcement built into the systems themselves. A governance program designed for only one track is blind to half of what the organization is doing, and the half it misses is usually the half growing fastest.
This is also why so many capable organizations feel unsettled about governance right now, and why that feeling is not a verdict on their leadership. Most governance approaches on offer were designed for one track or the other. Some are policy binders written for the careful few. Others are usage rules written for the scattered many. Very few were designed to hold both at once. If your current arrangement feels partial, that reflects the problem itself. It genuinely has two halves, and almost nobody has been handed a discipline built for both.
McKinsey’s 2026 State of AI Trust research puts the average organization’s responsible-AI maturity at 2.3 on a four-point scale. That figure is worth interpreting correctly. Nearly everyone is still early, the leaders are only modestly ahead, and the field is wide open for organizations that get organized now.1
Four Realities Make This the Right Moment
Timing questions deserve honest answers. A governance program is a real commitment, and “why now?” is the right challenge for any leadership team to raise. Four realities, taken together, make the case.
First, AI is beginning to act, not just answer. Agents use tools, touch data, and take actions, and systems that act need identities, permissions, and limits in much the same way people do. The habits that governed a chatbot answering questions do not stretch to cover an agent executing a workflow, and that shift is happening inside vendor products and internal builds alike. An organization that starts governing now gets to establish those habits while its agents are few. The same work, done after agents are everywhere, is harder in every dimension.
Second, an increasing share of AI arrives already built. It comes inside vendor products, sometimes added through a routine update, which means every organization inherits its suppliers’ governance choices unless it examines them. This is nobody’s oversight failure. It is simply how modern software ships. But it does mean the question, “What AI are we running?” now has an answer that can change monthly, whether or not anyone is watching.
Third, the regulatory clock now has fixed dates. The European Union's AI Act is law, and its 2026 amendment package reset the calendar without erasing the obligations. New prohibitions take effect December 2, 2026, and high-risk obligations phase in through December 2027 and August 2028, while state-level rules in the United States advance on their own schedules.2 The dates themselves will continue to move, as this year has already shown, which is precisely why a governance program should never be anchored to any single statute’s deadline. Organizations that build governance on their own foundations, i.e., their own risk appetite, accountability, and operating discipline, will meet whatever dates arrive as a matter of course rather than as a scramble. The discipline the regulations ask for is the discipline the program already runs.
Fourth, the evidence has caught up on both sides of the ledger. Documented AI incidents rose 55 percent in one year, reaching 362 in 2025 in Stanford’s AI Index count.3 On the value side, Gartner’s 2025 research found that organizations that conduct regular audits and assessments of their AI systems are more than three times as likely to achieve high value from generative AI.4 Governance is not the tax on AI value. On the evidence, it is one of its strongest predictors.
There is one more reading of the landscape worth having in hand for your next board conversation. ISS-Corporate’s 2026 study of the broad U.S. market found that fewer than one company in ten discloses board-level oversight of AI or an established AI policy.5 That figure describes the market, not any one company’s failing, and it carries an opportunity within it. Governance done visibly and well is still a differentiator, available to organizations that move deliberately now.
What Good Looks Like: Five Levels, Each Behind a Gate
Our answer to this moment is a level-by-level methodology. Clear rules are made by the right people, applied where work is designed, enforced inside the systems themselves, and kept honest year after year. It did not begin as a compliance exercise. It grew inside our AI Business Transformation methodology, the body of work focused on redesigning how organizations operate with AI, where governance proved to be among the first frameworks a transformation has to establish. The methodology now stands on its own, built for organizations that want AI governed well whether or not a broader transformation is underway.
Level 1
Strategy
The decisions only leadership can make
Who decidesCEO and executive team decide; the board of directors affirms.The Sponsorship Gate
Level 2
Decision Architecture
The rules, written as architecture
Who decidesThe chartered governance board decides; the board of directors ratifies the policy.The Policy Gate
Level 3
Design-Time Governance
Governance where the work is designed
Who decidesDomain owners decide inside the frameworks; the CIO’s team confirms it buildable.The Register Gate
Level 4
The Enforcement Layer
Where paper becomes physics
Who buildsCIO-side teams build and run it; security, counsel and procurement hold their pieces.The Enforcement Gate
Level 5
Continuous Governance
Governance that stays honest
Who keeps it honestThe governance board assures, the governance function operates, and the board of directors re-signs yearly.The Annual Gate
Level 1 secures the decisions only leadership can make. Governance does not begin with committees or tools. It begins with five decisions, made in a deliberate order and recorded in short, signed artifacts. The organization names one executive sponsor. It writes a risk appetite specific enough for an engineer to build to and a director to quote. It draws the hard lines it will not cross, with counsel’s review on record. It decides what the board of directors will see, how often, and through which committee. And it decides who will run governance day to day. Level 1 is short, inexpensive, and decisive. No new technology, no reorganization, just leadership putting its name to the questions only leadership can answer.
Level 2 writes the rulebook, and writes it as architecture. A chartered, cross-functional governance board with real decision rights. Risk-classification criteria that sort every AI system, present and future, into tiers of consequence, so a meeting notes assistant and a system that influences who receives aid are never governed in the same way. Named owners for every tier, with response times. A permissions table that settles in advance how much autonomy each tier of system may have. And one deliberately thin AI policy, formally ratified by the board of directors, readable by a regulator, a customer, or a donor. Level 2 is also where the rules reach the people already using AI, and they arrive as an invitation rather than an audit. The rules bring clear boundaries, sanctioned alternatives, and legitimacy for the personal solutions people build within them.
Level 3 carries the rules to the design table. This level exists for the transformational track, the workflow-redesign work, and it operates in the cheapest place governance will ever operate. A concern caught while a workflow is still on the whiteboard costs a conversation. Caught at deployment, it costs a rebuild. Caught in production, it costs an incident. The people who own the work make the calls, applying the Level 2 frameworks as constraints that shape the design rather than as reviews that reject it. The level closes with a written contract between the business and IT with every classified step delivered in a single register and confirmed as buildable.
Level 4 turns the rules into protections that work automatically. Every actor gets an identity, including the AI. Guardrails refuse out-of-bounds actions at the moment they are attempted. Every decision leaves a trail that can be reconstructed in minutes. And bought AI walks through the same door as anything built in-house, so one set of protections covers the entire AI estate: built, bought, and homegrown. For the people doing the work, remarkably little changes. Teams keep building, the checks run quietly in the background, and breaking the rules stops being a risk to manage because the systems simply do not allow it.
Level 5 keeps the whole arrangement honest. Governance left alone decays, not through anyone’s negligence but through ordinary drift. Controls settle into ceremony, and regulation moves while paperwork stands still. Level 5 is the annual operating loop that prevents this. A quarterly audit tests behavior rather than binders. A standing watch tracks regulatory change monthly and routes every change into the registers that govern daily work. Once a year, the board of directors re-signs the policy against the year’s actual evidence. The loop is deliberately permanent. This is the level that never ends.
Every level sits behind a gate. Each level states, in writing, what must exist before its work begins and what must be true before it ends. Each level’s exit list becomes the next level’s entry list, so nothing can fall between levels unnoticed. The plain version is simple. We check the foundation before we build the floor, at every floor. The gates carry one rule with real teeth. When something required is missing, the team building enforcement does not quietly invent the missing decision. A rule invented by the people it constrains is not governance. It is convenience. The gap is bridged with executive sanction, or the level does not begin. Most governance failures are quiet ones. Something upstream was never decided, everyone reasonably assumed someone else had decided it, and the gap surfaces in production as an incident with no owner. The gates exist to make that failure impossible, and they do it without blame. The discipline is structural rather than personal.
One more feature matters to almost every reader of this article. The methodology does not assume you are starting from zero. Most organizations are already mid-journey, with AI deployed and governance partial, and pretending otherwise would make any governance program useless to the majority of real organizations. This methodology is built for exactly that entry point, with an honest on-ramp that respects the work already done rather than asking organizations to restart. We will show how in the third article of this series.
What Doing This Well Buys Everyone
Step back, and a simple picture remains. Leadership makes the decisions only it can make. A chartered governance board turns them into workable rules. The people who own the work apply the rules where work is designed. IT builds them into the systems themselves. And once a year, everyone looks at the evidence and signs again.
Done well, this arrangement pays every stakeholder it touches. Shareholders get an organization where AI investment actually lands as value. The discipline that governs AI is the same discipline the research links to achieving high value from it, and incidents that never happen never reach the income statement. The board of directors gets oversight it can honestly attest to, through a policy it ratified, reporting it understands, and an annual re-signature grounded in evidence. Executives get decisions that stick, through clear ownership, faster approvals, and the freedom to move quickly precisely because the boundaries are known and enforced. Employees may gain the most of all. They inherit rules that arrive explained rather than announced, the safety to be open about the tools they already use, and the legitimacy of the personal AI solutions they build to do their own work better. And the people the organization serves inherit the benefit of all of it, an organization adopting AI boldly and remaining worthy of their trust while doing so.
That is the intention of AI governance done correctly. It is not the brake on what AI makes possible. It is the discipline that lets an organization say yes, again and again, safely, to what AI makes possible next. In the two articles that follow, we walk through the methodology as a client experiences it. First comes the deciding half, where leadership and the governance board write rules worth following. Then comes the enforcing half, where those rules become protections and governance stays current year after year.
A Note on Foundations
Plaster Group built this methodology on four foundations. ISO/IEC 42001 is the international standard for the management of AI. ISO/IEC 42005 is its companion standard for assessing how AI systems affect people. The European Union’s AI Act and the AI Risk Management Framework of the U.S. National Institute of Standards and Technology complete the set. These are the frameworks from which auditors and regulators already work, and the ones a board can name when asked what its AI governance is based on.
This series addresses “what” to do, not “how” to do it. If you are a business executive and would like help thinking through the “how,” please feel comfortable reaching out.
Sources
- 1.McKinsey, “State of AI Trust in 2026: Shifting to the Agentic Era,” March 2026 (approximately 500 organizations). Average responsible-AI maturity: 2.3 of 4.0. https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era
- 2.EU AI Act, Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744, in force July 27, 2026. New prohibitions effective December 2, 2026; high-risk obligations effective December 2, 2027, for Annex III and August 2, 2028, for Annex I. https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- 3.Stanford University Human-Centered Artificial Intelligence, “The 2026 AI Index Report,” April 2026. 362 documented AI incidents in 2025, up 55 percent in one year. https://hai.stanford.edu/ai-index/2026-ai-index-report
- 4.Gartner, “Gartner Survey Finds Regular AI System Assessments Triple the Likelihood of High GenAI Value,” November 4, 2025. https://www.gartner.com/en/newsroom/press-releases/2025-11-04-gartner-survey-finds-regular-ai-system-assessments-triple-the-likelihood-of-high-genai-value
- 5.ISS-Corporate, “Mind the Governance Gap: The State of Board Oversight and AI Policy in U.S. Companies,” 2026. Fewer than one company in ten across the broad U.S. market discloses board-level AI oversight or an established AI policy. https://insights.issgovernance.com/posts/mind-the-governance-gap-the-state-of-board-oversight-and-ai-policy-in-u-s-companies/
Frequently Asked Questions
Does AI governance slow down AI adoption?
No. The evidence points the other way. Gartner's 2025 research found that organizations conducting regular audits and assessments of their AI systems are more than three times as likely to achieve high value from generative AI. On the other side of the ledger, documented AI incidents rose 55 percent in a single year, reaching 362 in 2025 in Stanford's AI Index count. Governance is not the tax on AI value. On the evidence it is one of its strongest predictors, and it is the discipline that lets an organization say yes again and again, safely, to what AI makes possible next.
What is a gate in Plaster Group's AI Governance Methodology?
A gate is a written checkpoint at each end of a level. Every one of the five levels states what must exist before its work begins and what must be true before it ends, and each level's exit list becomes the next level's entry list, so nothing falls between levels unnoticed. The gates carry one rule with real teeth. When something required is missing, the team building enforcement does not quietly invent the missing decision, because a rule invented by the people it constrains is not governance. The gap is bridged with executive sanction, or the level does not begin.
Why does AI governance have to cover employee AI tools and enterprise AI projects at once?
Because one discipline has to hold both tracks, and a governance program designed for only one is blind to half of what the organization is doing. The decentralized track is the healthy spread of assistants and personal tools wherever work gets done; it needs to be counted, given data boundaries people can trust, and offered sanctioned options good enough that nobody works around them. The centralized track runs from a bought point solution serving one function to a full redesign of core workflows; it needs real gates, named accountability, and enforcement built into the systems. The half a partial approach misses is usually the half growing fastest.
How mature is AI governance at most organizations today?
Less far than most leadership teams assume. McKinsey's 2026 State of AI Trust research puts the average organization's responsible-AI maturity at 2.3 on a four-point scale, and ISS-Corporate's 2026 study of the broad U.S. market found that fewer than one company in ten discloses board-level oversight of AI or an established AI policy. Read those figures correctly. Nearly everyone is still early, the leaders are only modestly ahead, and neither number is a verdict on any single company. Governance done visibly and well is still a differentiator, available to organizations that move deliberately now.

About the author
Shawn Plaster
Founder & CEO, Plaster Group
Shawn is the author of Plaster Group's five-level AI Governance Methodology and its 3-article Insights series, and leads the firm's enterprise AI transformation work.
Next: Article 2: The Business Decides
© 2026 Plaster Group, LLC. All rights reserved. This article may not be reproduced, distributed, or transmitted in any form without prior written permission from Plaster Group. Brief excerpts may be quoted for review or commentary purposes with attribution to the author and a link to the original article.
Ready to move forward?
Let's discuss how your organization can build with AI — securely, strategically, and starting from where you are today.
Start a Conversation