Data Defenders LLC — Protecting Your Most Valuable Business Asset
← No Hallucinations

Governance · September 18, 2026

The Governance Gap: Where 74% of Organizations Are Stuck With AI

By David Monahan · Data Defenders, LLC · companion piece to the AI Governance Lifecycle graphic

Two surveys, one number

Two independent 2026 surveys asked organizations roughly the same question — do you have a formal AI usage policy? — and landed within two points of each other.

ISACA's AI Pulse Poll found 25% of organizations have no AI policy at all, 30% have a limited or informal one, 7% aren't sure, and about 38% have a formal policy in place. Aona, sampling separately, found 60% of organizations have no formal AI usage policy. Add ISACA's first three buckets together and you get 62%.

Different samples, different methodologies, same answer: roughly six in ten organizations are using AI without a formal policy governing it, and a quarter have nothing at all.

A second pair of surveys corroborates the other end. Compliance Week found 25% of organizations report an adequate AI governance framework; Optro found 25% have comprehensive visibility into their AI use. That gives a clean line: about 74% of organizations sit on the ungoverned side, 26% on the governed side.

The AI Governance Lifecycle

We mapped those numbers onto a seven-stage maturity curve — Investigation, Experimentation, Sanctioned, Governed, Managed (AIMS), Certifiable, Optimized — and shaded each stage by the severity band our assessment platform uses when it scores an organization.

AI Governance Lifecycle curve — share of organizations at each stage from Investigation through Optimized, shaded by severity band

What the curve shows:

  • Investigation (22–24%) — AI is in use, nobody owns it, and there is no policy. This is ISACA's 25%.
  • Experimentation (18–21%) — pilots and proofs of concept, often with an informal policy on paper and no sanctioned tooling.
  • Sanctioned (22–25%) — leadership has approved specific tools or use cases, but there is no governance framework wrapped around them.
  • Governed (14–16%) — a real framework exists: roles, risk assessment, an inventory, an approval process.
  • Managed (AIMS), Certifiable, Optimized (7–13% combined) — an AI management system in the ISO/IEC 42001 sense: operated, audited, and improved. Certifiable means the organization could pass a certification audit today, whether or not it has chosen to pursue one. Fewer than 500 ISO/IEC 42001 certificates exist worldwide, so completed certifications are a floor for this stage, not a ceiling.

The pill labeled "The Gap" spans the first three stages. All of the companies in this area have a significant amount of unmanaged or shadow AI — 74% of organizations. This can have a material effect on their business, depending on the information they collect and process using AI.

Curious where your organization falls on the curve?

Pick the framework that fits your situation and take a free 15-question snapshot. On-screen results plus a PDF to take away — no signup.

See the snapshots →

Why the front of the curve is so crowded

The rush to adopt did this. Boards asked, "Can we leverage AI to improve the business?" Teams reacted, identifying use cases and applying AI; employees started using consumer AI without asking; vendors embedded AI into tools companies were already using. All of it before governance processes could react.

That matters because Investigation is where the critical exposure begins. Employees and teams investigate with whatever is in front of them — real customer records on a desktop, a production database, a live application — and nobody has told them not to, because there is no formal policy. Data is leaving the organization's control before anyone has decided whether it should. That is why the graph paints the first stage Critical: the risk is already real and completely unmanaged.

Experimentation carries the Jeopardy band for a different reason. The organization now knows AI is in play and is building on it — a pilot becomes a workflow, a proof of concept gets a link on the intranet, a vendor toggles a "smart" feature on in the next release — but it still has no framework to catch what the pilot is doing with production data.

Sanctioned and Governed carry the Concern band. Approval and structure have arrived — leadership has blessed specific tools, and in the Governed stage a framework exists — but the controls and evidence that would let the organization prove it is managing the risk are not yet in place. The organization has moved from not knowing to knowing; it has not yet moved to showing.

Read left to right, the bands tell one story: unaware and exposed, then aware and building, then approved but unproven. Three-quarters of organizations are somewhere in that sequence.

Why this shape is a problem

1. Regulation is arriving faster than governance. In the United States, 27 states enacted 84 new AI laws in the first half of 2026 alone — more than all of 2025 — with Colorado's ADMT Act and Illinois's frontier-model audit requirement among the most demanding. Internationally, 33 countries now have AI-specific legislation on the books, led by the EU AI Act, whose high-risk obligations take effect on fixed deadlines in August 2026 and August 2027, and South Korea's AI Basic Act, in force since January 2026. Another 47 countries have national AI legislation in draft or moving through their legislatures, Brazil's PL 2338 chief among them. Nearly every one of these laws assumes the same three things: an AI inventory, a risk classification, and a named owner. Three-quarters of organizations can't produce any of the three.

2. Shadow AI is invisible to the people who would have to answer for it. IBM found only 37% of organizations even have a policy to manage AI or detect shadow AI use — and the employees aren't going to volunteer it. Microsoft's Work Trend Index found 52% of people who use AI at work are reluctant to admit using it for their most important tasks, and 78% bring their own AI tools rather than wait for the company to provide them. You cannot govern what you cannot see, and you cannot defend an incident response that starts with "we didn't know that tool was in use."

3. Sanctioned-but-ungoverned is the most dangerous stage, not the safest. Leadership approval without a framework creates an audit trail that says "we knew" without any evidence of "we managed." That is a worse position under most regulators than not having started.

4. The gap compounds. Every month adds more tools, more data flows, and more undocumented decisions that will have to be inventoried later. The cost of reaching Governed rises with time spent in the first three stages.

5. Almost no one has proven they're certifiable. With well under 1% of organizations holding an ISO/IEC 42001 certificate, the market has no way to tell a governed program from an audit-ready one. Being able to demonstrate certifiability — controls evidenced, gaps closed, package assembled — is a differentiator today; the certificate itself can follow when the business case calls for it.

What Data Defenders does to the curve

Our assessment platform is built to move organizations rightward, faster, and to shrink the width of the first three stages.

  • Find the stage you're actually at. Each of Data Defenders' AI Maturity Assessments places every control on the same severity scale used in the graphic. An organization learns where it is, from Critical to Exemplar, based on individual controls and combinations of controls.
  • Turn findings into a sequenced path to Governed. Every finding carries a remediation recommendation anchored to benchmark research, so the output is a prioritized program, not a list of gaps.
  • See how far you are from the certification bar. Each assessment maps its controls to the underlying standard or regulation, so an organization can see which requirements it already meets, which it doesn't, and what closes the distance — before it spends money on a registrar.
  • Keep moving — coming soon. A subscription option will improve customers' ability to re-assess on their own cadence and measure improvement stage over stage, so Governed becomes Managed, and Managed becomes Certifiable, on a timeline the organization controls.

The goal is not to get everyone certified. It's to move the mass of the curve from the first three stages to the fourth, make the fourth stage the normal place for an organization using AI to be, and give the ones who push further a clear view of what certifiable looks like.

The takeaway

Six in ten organizations have no formal AI policy. Three in four have no governance framework. Those aren't estimates; they are two pairs of independent surveys agreeing with each other. If your organization is in the first three stages, you're in the majority — and the majority is exactly where the exposure sits.

Find out which stage you're at. Then move.

Related

Take one of our free AI Maturity Snapshots — 15 questions, no signup.

See the snapshots →

Sources: ISACA AI Pulse Poll (2026); Aona (2026); Compliance Week (2026); Optro (2026); HFS Research / Infosys (2026); IBM Cost of a Data Breach (2025); Microsoft / LinkedIn Work Trend Index (2024); Transparency Coalition AI mid-year legislation report (July 2026); Comparitech, AI legislation in 178 countries (March 2026); Axis Intelligence, AI Laws by Country (July 2026); ISO/IEC 42001 certificate trackers (Atoro, ISMS.online, AI Compliance Vendors).

← Back to No Hallucinations

Talk to Us Directly

Free 25-minute consultation. Bring your questions.

Schedule the consultation Ask a question +1 720-739-1583

©2026 Data Defenders, LLC · Home · Privacy · FAQ

AI Governance · Fractional CISO · Cyber Programs · GRC