What's Happening?
A new survey conducted by Ernst & Young LLP (EY US) indicates that while U.S. organizations are rapidly deploying Artificial Intelligence (AI) and autonomous AI agents, their governance frameworks are not keeping pace. The 'EY US AI Risk and Governance
Survey' polled 202 senior AI executives from organizations with at least $1 billion in annual revenue. The findings show that 98% of these executives report having formal AI governance policies, yet nearly half (47%) admit their organizations have bypassed these processes for urgent deployments. This oversight is occurring despite 89% of respondents encountering AI-related risks in the past year, including cybersecurity risks (52%), human risk (47%), and shadow AI risk (46%). A significant portion, 36%, reported experiencing an AI incident or failure that led to negative impacts such as data loss, financial damage, brand damage, or operational disruptions. The survey highlights a critical gap between the rapid adoption of AI technologies, particularly agentic AI, and the development of robust governance to manage associated risks.
Why It's Important?
This governance gap poses substantial risks to U.S. industries, potentially leading to significant financial, reputational, and operational damage. The rapid deployment of agentic AI, which can execute critical actions without real-time human involvement, amplifies these concerns. The survey reveals that 91% of senior AI executives in the U.S. are using agentic AI, but roughly half (49%) have not updated their governance frameworks to address its specific requirements and risks. Furthermore, 26% of organizations using agentic AI cannot detect unauthorized AI agents operating internally, creating critical visibility gaps. This lack of oversight can expose companies to increased cybersecurity threats, regulatory non-compliance, and an inability to trace data lineage for AI decision models. The findings underscore the urgent need for U.S. businesses to align their AI governance with their AI implementation strategies to mitigate these growing risks and protect their assets and public trust.
What's Next?
U.S. organizations are beginning to address these AI governance gaps by implementing formal AI risk and compliance reviews. The survey indicates that nearly all respondents (98%) have conducted such reviews annually. These reviews have led to significant modifications, pauses, or even complete cessation of AI systems, with 64% modifying a quarter or more of their AI systems, 29% pausing a quarter or more, and 25% fully stopping a quarter or more. Common issues identified during these reviews include data quality problems (57%), AI model drift (48%), and shadow AI (39%). This suggests a trend towards more rigorous internal auditing and adjustment of AI systems. Moving forward, organizations are expected to integrate these governance and assurance practices into the design and testing phases of AI systems, operating them at a frequency that matches the pace of technological advancement. This proactive approach aims to build confidence in AI systems and prevent future incidents.
Beyond the Headlines
The findings from the EY US survey point to a deeper challenge beyond mere technical implementation: the ethical and cultural integration of AI within organizations. The struggle to adapt governance frameworks reflects a broader societal learning curve in understanding and controlling advanced AI. The emergence of 'shadow AI'—unauthorized AI agents operating internally—highlights a potential breakdown in organizational control and accountability, raising questions about data privacy, intellectual property, and the potential for unintended biases or harmful outcomes. The emphasis on formal assurance reviews and the subsequent modifications or pauses of AI systems suggest a growing recognition of the need for human oversight and ethical considerations in AI development. This shift could lead to the development of new industry standards, regulatory pressures, and a greater demand for AI ethics professionals, ultimately shaping the future of responsible AI deployment in the U.S. and globally.













