Fewer than 1 in 10 corporate ethics codes even mention AI
Digital Transformation

Fewer than 1 in 10 corporate ethics codes even mention AI

A new LRN survey of 2,000 employees finds AI rollouts have outrun the governance documents meant to constrain them, right as misconduct reports hit a multi-year high.

PublishedSeptember 22, 2026
Read time5 min read
Share

The document meant to set boundaries has not caught up

LRN's Code of Conduct Report 2026, based on a survey of 2,000 full-time employees, found that fewer than 1 in 10 corporate codes of conduct explicitly address AI or broader technology ethics. That gap exists even though the same employees report their employers require them to certify they have read and understood the code, a compliance ritual that increasingly certifies a document silent on the technology employees now use every day at work, from drafting emails to summarizing customer records.

The mismatch is not subtle. Enterprises have spent 2026 pushing generative AI and early agentic deployments into production workflows, from customer service to financial reporting, while the governance artifact meant to tell employees what is and is not acceptable use largely still reads as if none of that happened. LRN's own framing puts it plainly: the strongest codes will not simply add more content, they will help employees navigate emerging risks with guidance that is easy to find, understand and apply, a standard most current codes were never written to meet in the first place. Many of those documents were last substantively revised before generative AI tools existed in any recognizable enterprise form, which means the gap LRN measured is less a recent lapse than years of accumulated drift between policy and practice.

Misconduct is rising while confidence in reporting it falls

The survey's headline numbers on misconduct are the more uncomfortable finding. Fifty-five percent of employees experienced or witnessed misconduct in 2025, up sharply from 41% in 2024, and 38% of respondents reported multiple separate incidents rather than a single isolated event. That trajectory moves in the wrong direction at precisely the moment enterprises are layering new AI-driven decision points, and new AI-enabled ways to cut corners, into everyday work, compounding a problem that was already trending worse before generative tools entered the picture at scale.

Confidence in the reporting channel meant to catch that behavior is eroding at the same time. Just 66% of employees said they felt safe reporting misconduct without retaliation, down from 71% in prior LRN research, and nearly 1 in 5 said their code of conduct offers no practical guidance for situations they actually encounter day to day. A governance framework works only when employees trust it enough to use it, and LRN's numbers show that trust moving in the wrong direction across two consecutive survey cycles rather than stabilizing after the initial post-pandemic dip most compliance teams had assumed was temporary.

It is tempting to file code-of-conduct gaps under HR and compliance and move on, but the CIO owns the systems generating most of the new risk this survey describes. AI agents that summarize customer data, draft external communications, or make eligibility decisions all create behaviors that a pre-AI code of conduct was never written to address, and employees using those tools are, by LRN's own numbers, working from documents that never mention them or the risks specific to how they operate.

That gap becomes the CIO's problem the moment an AI-assisted decision goes wrong and the organization has to explain what policy governed it. A code of conduct that predates the AI deployment it is supposed to constrain gives a weak answer to a regulator, a board, or a plaintiff's attorney asking what guardrails were in place at the time. Technology leaders who assume governance documentation belongs entirely to someone else's workstream are underwriting risk they will eventually be asked to personally explain in front of an audit committee, often on a timeline they did not choose and with far less preparation than they would have liked.

The gap between policy on paper and policy in practice

This finding lands alongside a broader pattern we have tracked all year: enterprises that report having AI governance policies in place often have not updated those policies for how AI is actually being used, and employees frequently do not know the policy exists or applies to their specific tool. LRN's additional citations of HR Acuity and Adecco Group research reinforce the same conclusion from a different angle, that workplace governance infrastructure broadly has not kept pace with how work itself has changed over the past two years.

A code of conduct is the most visible governance artifact most employees ever encounter, which makes its silence on AI a leading indicator of governance maturity elsewhere in the organization. The practical fix requires the CIO's direct involvement rather than a legal team working in isolation on generic compliance language. Codes of conduct need specific, current guidance on acceptable AI use, clear escalation paths for AI-related concerns, and language written by people who understand what the tools actually do inside the business.

What this means for your governance roadmap

If your organization's code of conduct has not been revised since generative AI tools reached production use, treat that gap as a governance priority to close before your next audit cycle rather than waiting for an incident to force the question. The employees using your AI systems every day are, per LRN's data, mostly working without specific guidance on what responsible use looks like, and that silence functions as a decision the organization is effectively making by omission, whether or not anyone intended it that way.

Pair the document update with the reporting-confidence problem LRN also surfaced. A revised code that employees do not trust enough to invoke solves only half the problem this survey describes. Getting both pieces right, current guidance on AI use and a reporting channel people genuinely believe will protect them, is table stakes for any enterprise scaling AI deployment faster than it is scaling the governance meant to constrain it responsibly.

Tagged#news#digital-transformation#enterprise#cio#erp#strategy#governance#ethics#code-of-conduct#lrn#workplace-misconduct#compliance-culture