The core shift: governance is no longer a side process
The OneTrust survey points to a simple pattern: companies are encouraging AI agent use faster than they are building the systems to govern it well.
A large majority of respondents say their organizations encourage agents. But that encouragement splits into two camps:
- teams using agents with defined oversight and controls
- teams using agents while governance is still catching up
That second group is the interesting one. It signals that adoption pressure is outrunning process design. In plain English: “Use the tool, we’ll sort out the rules later.”
That usually works right up until it doesn’t.
Most governance is present, but not truly embedded
Many organizations are not ignoring governance. They are doing the work. Risk classification, impact assessments, employee usage controls, policy documentation, and incident management are all in play.
The problem is less about awareness and more about integration.
Only a small share report governance as embedded into the AI lifecycle at the highest maturity level. Far more describe it as either:
- defined, but slow and manual
- reactive and fragmented
That distinction is important. A documented policy is not the same thing as operational control. A review checklist is not the same thing as continuous oversight. And a manual approval process does not scale well when dozens of teams are testing copilots, automations, and third-party agents at once.
Why agents break older governance models
Traditional governance assumes a fairly stable system. You assess it, approve it, document the risks, and revisit later.
Agents are less polite.
They can operate across tools, make decisions in sequence, and produce different outcomes depending on context, data quality, access permissions, and prompt design. The same agent that saves an hour in one workflow can create a compliance headache in another.
That is why static governance looks increasingly flimsy. If oversight only happens before deployment, then most of the real risk shows up after deployment.
In other words, the problem is no longer just “Should we allow this AI system?” It is now “What is it doing right now, with what data, under whose authority, and can we prove it?”
The operating model is the real bottleneck
Governance delays are often framed as legal friction or compliance drag. The survey suggests something broader: the operating model itself is under strain.
Governance requirements are slowing or complicating AI initiatives across the board, including:
- agentic workflows
- data analysis
- third-party AI tools
- customer-facing experiences
- employee copilots
This is less a story about one stubborn risk team and more a story about missing coordination.
Only a very small minority say coordination and accountability are defined across the AI lifecycle. That means ownership is fuzzy, handoffs are inconsistent, and reviews often happen too late. Teams may know how to assess risk in isolation, but they struggle to align across procurement, security, legal, data, product, and operations.
That is how governance becomes everybody’s job and nobody’s workflow.
Shadow AI is not a rebellion. It’s a service design problem.
One of the clearest signals in the data is that employees use unapproved AI tools when approved options or processes are too slow.
This is usually labeled “shadow AI,” which sounds dramatic. Often it is less dramatic than that. People have work to do, the approved path is clunky, and the unapproved path is one browser tab away.
That does not make it harmless. It does make it predictable.
If access, review, or procurement takes too long, employees will route around the system. Then governance becomes retroactive: discovery after adoption, assessment after exposure, cleanup after risk.
A lot of AI governance pain is really a UX problem wearing a compliance badge.
Data integrity is becoming the quiet risk to watch
Data integrity stands out. Organizations appear especially concerned about data loss, corruption, and misclassification, while also feeling less prepared to handle them.
That makes sense. Agentic systems can move quickly through data-rich environments. If the underlying data is flawed, mislabeled, or accessed in the wrong way, the issue does not stay contained for long.
This matters for a few reasons:
- bad data can produce bad actions, not just bad outputs
- misclassification can trigger downstream workflow errors
- weak evidence trails make incidents harder to investigate
- third-party tools add visibility gaps many teams still struggle with
Data quality used to be a reliability issue. In agentic environments, it is also a governance issue.
Third-party AI is still not “set and forget”
Another pattern worth noticing: organizations are not only governing internally built or configured AI. They are also trying to monitor third-party AI tools throughout their use, not just at purchase.
That sounds obvious. In practice, it is hard.
Third-party AI changes frequently. Features evolve, models get swapped, permissions drift, and usage expands beyond the original review scope. A one-time vendor assessment may satisfy procurement, but it rarely gives teams enough visibility into real operational risk over time.
This is especially tricky with agents layered across multiple services. Once one tool can call another, governance has to follow the chain, not just the contract.
Confidence is high. Coordination is not.
One of the more telling contradictions in the survey is this: many respondents report confidence in their ability to perform governance activities, yet lifecycle-wide coordination remains weak.
Both can be true.
A company can be good at writing policies, running assessments, classifying risk, or documenting controls. But if those activities live in separate lanes, the organization still struggles when an agent crosses systems, teams, and responsibilities in one motion.
This is the 2026 governance problem in a sentence: competent parts, messy whole.
More budget is coming, but budget alone won’t fix the gap
Nearly all respondents plan to increase budget for AI governance technologies. That is notable, but not surprising. More AI use usually means more spend on oversight, monitoring, approvals, training, and evidence collection.
Also notable: organizations are spending more time managing AI-related risk than they were a year ago. Incidents are pushing companies toward more training, more formal review processes, and more monitoring.
That said, throwing money at the problem has limits.
Budget helps with tooling. It does not automatically solve:
- unclear accountability
- manual handoffs
- fragmented reviews
- weak runtime monitoring
- poor employee access to approved tools
If governance remains architected as a sequence of disconnected checkpoints, more software may simply make the waiting room nicer.
What this trend means for founders, operators, and buyers
For founders building AI tools, especially agentic ones, governance is no longer a “security page” add-on. Buyers increasingly need visibility, auditability, permission controls, monitoring hooks, and evidence they can actually use internally.
For enterprise operators, the lesson is sharper: policy maturity is not enough. If governance cannot keep pace with deployment speed, users will find workarounds and agents will outrun oversight.
For AI buyers comparing tools, a few questions are becoming more practical than flashy:
- How does this tool handle approvals and permissions?
- What can be monitored continuously, not just reviewed upfront?
- How visible are actions taken by agents?
- What evidence is available when something goes wrong?
- How does the vendor support ongoing third-party oversight?
These are not boring enterprise checkboxes. They are increasingly product selection criteria.
The bigger market signal
The market is moving from “Can we use AI?” to “Can we operate AI responsibly at scale?”
That sounds subtle, but it changes what matters.
In the first phase of adoption, capability wins attention. In the next phase, governability starts winning deals. Not because governance is glamorous, but because unmanaged agent adoption creates operational drag, review bottlenecks, and incident exposure.
The tools that fit cleanly into real governance workflows will have an advantage over the tools that assume enthusiasm is enough.
A practical takeaway
If your organization is encouraging agents while governance is still under construction, the main risk is not a lack of policy. It is the gap between where agents can act and where oversight can still see.
Start there.
Map where agents touch data, decisions, and external tools. Tighten the approval path for sanctioned options so employees do not default to shadow AI. And prioritize controls that work during runtime, not just before launch.
Because in 2026, the governance question is no longer whether AI is being used. It is whether oversight can keep up once the agent starts clicking.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!