Governance · September 18, 2026
By David Monahan · Data Defenders, LLC · companion piece to the AI Governance Lifecycle graphic
Two independent 2026 surveys asked organizations roughly the same question — do you have a formal AI usage policy? — and landed within two points of each other.
ISACA's AI Pulse Poll found 25% of organizations have no AI policy at all, 30% have a limited or informal one, 7% aren't sure, and about 38% have a formal policy in place. Aona, sampling separately, found 60% of organizations have no formal AI usage policy. Add ISACA's first three buckets together and you get 62%.
Different samples, different methodologies, same answer: roughly six in ten organizations are using AI without a formal policy governing it, and a quarter have nothing at all.
A second pair of surveys corroborates the other end. Compliance Week found 25% of organizations report an adequate AI governance framework; Optro found 25% have comprehensive visibility into their AI use. That gives a clean line: about 74% of organizations sit on the ungoverned side, 26% on the governed side.
We mapped those numbers onto a seven-stage maturity curve — Investigation, Experimentation, Sanctioned, Governed, Managed (AIMS), Certifiable, Optimized — and shaded each stage by the severity band our assessment platform uses when it scores an organization.
What the curve shows:
The pill labeled "The Gap" spans the first three stages. All of the companies in this area have a significant amount of unmanaged or shadow AI — 74% of organizations. This can have a material effect on their business, depending on the information they collect and process using AI.
Curious where your organization falls on the curve?
Pick the framework that fits your situation and take a free 15-question snapshot. On-screen results plus a PDF to take away — no signup.
See the snapshots →The rush to adopt did this. Boards asked, "Can we leverage AI to improve the business?" Teams reacted, identifying use cases and applying AI; employees started using consumer AI without asking; vendors embedded AI into tools companies were already using. All of it before governance processes could react.
That matters because Investigation is where the critical exposure begins. Employees and teams investigate with whatever is in front of them — real customer records on a desktop, a production database, a live application — and nobody has told them not to, because there is no formal policy. Data is leaving the organization's control before anyone has decided whether it should. That is why the graph paints the first stage Critical: the risk is already real and completely unmanaged.
Experimentation carries the Jeopardy band for a different reason. The organization now knows AI is in play and is building on it — a pilot becomes a workflow, a proof of concept gets a link on the intranet, a vendor toggles a "smart" feature on in the next release — but it still has no framework to catch what the pilot is doing with production data.
Sanctioned and Governed carry the Concern band. Approval and structure have arrived — leadership has blessed specific tools, and in the Governed stage a framework exists — but the controls and evidence that would let the organization prove it is managing the risk are not yet in place. The organization has moved from not knowing to knowing; it has not yet moved to showing.
Read left to right, the bands tell one story: unaware and exposed, then aware and building, then approved but unproven. Three-quarters of organizations are somewhere in that sequence.
1. Regulation is arriving faster than governance. In the United States, 27 states enacted 84 new AI laws in the first half of 2026 alone — more than all of 2025 — with Colorado's ADMT Act and Illinois's frontier-model audit requirement among the most demanding. Internationally, 33 countries now have AI-specific legislation on the books, led by the EU AI Act, whose high-risk obligations take effect on fixed deadlines in August 2026 and August 2027, and South Korea's AI Basic Act, in force since January 2026. Another 47 countries have national AI legislation in draft or moving through their legislatures, Brazil's PL 2338 chief among them. Nearly every one of these laws assumes the same three things: an AI inventory, a risk classification, and a named owner. Three-quarters of organizations can't produce any of the three.
2. Shadow AI is invisible to the people who would have to answer for it. IBM found only 37% of organizations even have a policy to manage AI or detect shadow AI use — and the employees aren't going to volunteer it. Microsoft's Work Trend Index found 52% of people who use AI at work are reluctant to admit using it for their most important tasks, and 78% bring their own AI tools rather than wait for the company to provide them. You cannot govern what you cannot see, and you cannot defend an incident response that starts with "we didn't know that tool was in use."
3. Sanctioned-but-ungoverned is the most dangerous stage, not the safest. Leadership approval without a framework creates an audit trail that says "we knew" without any evidence of "we managed." That is a worse position under most regulators than not having started.
4. The gap compounds. Every month adds more tools, more data flows, and more undocumented decisions that will have to be inventoried later. The cost of reaching Governed rises with time spent in the first three stages.
5. Almost no one has proven they're certifiable. With well under 1% of organizations holding an ISO/IEC 42001 certificate, the market has no way to tell a governed program from an audit-ready one. Being able to demonstrate certifiability — controls evidenced, gaps closed, package assembled — is a differentiator today; the certificate itself can follow when the business case calls for it.
Our assessment platform is built to move organizations rightward, faster, and to shrink the width of the first three stages.
The goal is not to get everyone certified. It's to move the mass of the curve from the first three stages to the fourth, make the fourth stage the normal place for an organization using AI to be, and give the ones who push further a clear view of what certifiable looks like.
Six in ten organizations have no formal AI policy. Three in four have no governance framework. Those aren't estimates; they are two pairs of independent surveys agreeing with each other. If your organization is in the first three stages, you're in the majority — and the majority is exactly where the exposure sits.
Find out which stage you're at. Then move.
Sources: ISACA AI Pulse Poll (2026); Aona (2026); Compliance Week (2026); Optro (2026); HFS Research / Infosys (2026); IBM Cost of a Data Breach (2025); Microsoft / LinkedIn Work Trend Index (2024); Transparency Coalition AI mid-year legislation report (July 2026); Comparitech, AI legislation in 178 countries (March 2026); Axis Intelligence, AI Laws by Country (July 2026); ISO/IEC 42001 certificate trackers (Atoro, ISMS.online, AI Compliance Vendors).
Free 25-minute consultation. Bring your questions.