Digital Transformation

Only 27 percent of companies call their AI governance program mature, Schellman finds

A new survey of 525 governance professionals shows most enterprises are funding AI oversight without building programs that would hold up under audit. The gap between activity and maturity is the real risk.

PublishedAugust 3, 2026
Read time5 min read
Share

A survey built to test confidence against readiness

Compliance firm Schellman surveyed 525 U.S.-based governance professionals for its 2026 State of AI Governance report, and the headline number is a clean gap between funding and maturity. Ninety percent of organizations say they have allocated budget to AI governance. Only 27 percent describe their program as fully mature. That 63-point spread is the story. Money is moving toward AI oversight across the enterprise, but the programs it is funding have not caught up to the pace at which AI is actually being deployed.

The gap gets more concerning when you look at what organizations believe about themselves. Seventy three percent of respondents said they believe their organization could pass an AI compliance audit today. Set next to the 27 percent maturity figure, that confidence looks misplaced. Schellman managing principal Danny Manimbo put the core problem plainly: the challenge is turning individual governance activities into a mature, operationalized program that can withstand regulatory scrutiny. Isolated policies and one-off reviews are not the same thing as a program.

Agents are already in production, ahead of the controls

The most operationally relevant figure in the report is this: 86 percent of organizations are testing AI agents, and nearly half already have agents running in production. Agents that take actions on a company's behalf, not just chatbots that answer questions, are the highest-risk category of enterprise AI because they can execute transactions, modify records, or trigger downstream processes without a human in the loop for every decision. Deploying that category of system ahead of governance maturity is a much bigger exposure than deploying a generative AI writing assistant ahead of governance maturity.

The report puts a number on exactly how far behind the controls are: only 20 percent of companies have mature governance models specifically for autonomous agents. That means roughly half of enterprises running agents in production are doing so without a governance framework built for the risk profile of autonomous systems. Sixty four percent do have formal AI acceptable use policies they actively communicate to staff, and 44 percent have AI-specific incident response procedures, but general-purpose AI policy is not the same control as agent-specific oversight.

The accountability gap sitting on the CIO's desk

Perhaps the most uncomfortable figure for the CIO audience specifically: two thirds of CIOs and CTOs report being accountable for AI systems they do not fully control. That is a direct description of the shadow AI and vendor-embedded AI problem that governance teams have been flagging for two years, now quantified from the technology leadership side rather than the compliance side. When a SaaS vendor ships an AI feature inside an existing contract, or a business unit stands up an agent using a self-service platform, the CIO inherits the accountability without necessarily having approved the deployment or having visibility into how it behaves.

This is the practical argument for why governance maturity needs to be a CIO-owned metric, not solely a compliance or legal function's responsibility. Schellman CEO Avani Desai framed the upside directly: organizations that build trust through mature governance programs will be better positioned to scale AI and create long-term value. That is fundamentally a deployment velocity argument dressed up in compliance language. Programs that can prove control over their AI systems can move faster into new use cases because they do not need to relitigate risk approval for every new agent.

Regulatory pressure is only part of the motivation

The survey found a majority of companies preparing for U.S. state and federal AI regulation, and nearly a third preparing specifically to comply with the EU AI Act. Regulatory readiness is a real driver of the governance spending increase, but the report's own numbers suggest it is not sufficient on its own. Companies can build policies aimed at satisfying a specific regulation and still lack the operational maturity to manage agent behavior day to day, because regulatory compliance and operational governance solve different problems. One protects the company from legal exposure. The other prevents an agent from doing something costly before anyone notices.

That distinction matters for how a CIO should read this report. Passing an audit and running a mature governance program are not interchangeable goals, and the 73 percent confidence figure against the 27 percent maturity figure shows many organizations are optimizing for the former. A governance program built primarily to satisfy an external audit checklist will miss the agent-specific controls, like scoped permissions, action logging, and rollback procedures, that actually prevent an autonomous system from causing damage in production.

What this means for the CIO roadmap

The direct implication is to treat agent governance as its own budget line and its own maturity metric, separate from general AI policy. If your organization is among the 86 percent testing agents or the nearly 50 percent already running them in production, the 20 percent maturity figure for agent-specific governance should be read as a warning that most peer organizations, and quite possibly yours, have not built the controls the deployment already requires. Funding alone will not close that gap; the 90 percent funding figure sitting next to the 27 percent maturity figure proves that.

Practically, that means auditing which agents are live today, who owns their permissions, and whether an incident response procedure exists that names AI-specific failure modes rather than reusing a generic security playbook. The two thirds of CIOs accountable for systems they do not control should treat that statistic as a mandate to demand visibility into every AI feature embedded in vendor contracts and every agent stood up by a business unit, not just the ones IT deployed directly. Governance maturity is becoming a competitive input, not just a compliance cost.

Tagged#news#digital-transformation#enterprise#cio#erp#strategy#governance#schellman-survey#ai-governance-maturity#audit-readiness#governance-professionals-survey