Live Webinar | Building AI Governance That's Audit Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

2026 State of AI Governance: Closing the Readiness Gap

Artificial Intelligence

Published: Sep 9, 2026

AI governance has become one of the most consequential disciplines impacting enterprise-level organizations today. It determines not only whether organizations can manage AI-related risks, but whether they can build and prove the trust, accountability, and operational confidence needed to use AI effectively. Despite its importance, governance is often treated as a supporting function focused on policies, checkbox compliance procedures, and assigned responsibility.

Schellman’s 2026 State of AI Governance report, “Bridging the Gap Between AI Governance Confidence and AI Governance Maturity,” exposes the consequences of that mindset: despite significant investment and widespread confidence in existing governance programs, fewer than one in three organizations have reached operational maturity. At the same time, nearly half already have autonomous AI agents in production, creating a widening gap between the governance organizations have established and the governance their AI capabilities increasingly require.

AI Governance Is a Business Capability, not a Compliance Exercise

For many organizations, AI governance has often been associated with restrictions and additional layers of approvals, policies, and controls that seemingly slow innovation. But rather than holding innovation back, governance should protect it and create the conditions for it to flourish. As AI becomes more capable and impactful, effective governance in practice helps organizations understand and avert not only what could go wrong, but also how to move forward responsibly.

Schellman’s research suggests that many organizations have established the foundations of strong AI governance but have failed to translate them into operational readiness. While 57 percent of respondents maintain a formal AI governance policy, only 44 percent have documented AI-specific incident response procedures. Even where policies exist, 28 percent of organizations with a formal acceptable-use policy still handle violations informally on a case-by-case basis.

A policy can establish expectations, but effective governance makes those expectations actionable through defined ownership, repeatable processes, monitoring, escalation, and evidence that controls are working. Rather than creating more friction around AI, the goal is to give organizations enough visibility and control to move forward with confidence and be able to defend their AI operations.

The research offers an encouraging indication of what mature governance can enable. Organizations with mature AI governance are more than three times as likely to have AI agents in production as those with developing governance—78 percent compared to 22 percent. Strong governance, in other words, may signal that an organization is better equipped to use AI, not more hesitant to use it.

The More Autonomous AI Becomes, the More Governance Matters

Schellman found that 46 percent of surveyed organizations already have AI agents in production, while 86 percent have tested or piloted them. Yet governance controls around those agents remain inconsistent: only 52 percent of organizations with agents in testing or production have defined human oversight and escalation requirements, while 54 percent have assigned clear roles and accountability for agent decisions.

When AI advances from generating an answer to taking an action, governance must answer fundamentally different questions. What can an agent do independently? Which actions require approval? Who can intervene? What does human oversight look like? Can an action be reversed? And can the organization demonstrate what happened after the fact?

The broader policy debate is grappling with similar questions. In January, White House Office of Science and Technology Director Michael Kratsios urged Congress to work toward a federal AI standard, while pushing back against global AI governance. Meanwhile, NIST continues to frame AI risk management and standards as a foundation for governance that can enable innovation. Internationally, ISO/IEC 42001 has been established as the first certifiable standard for AI management systems, giving organizations a voluntary framework to demonstrate responsible AI governance even as governments debate whether and how to mandate one. Elsewhere, AIUC-1 has emerged as a certification standard aimed specifically at governing AI agents.

Although these examples highlight how the regulatory and policy environments may continue to evolve, it’s still important for organizations to not outsource governance while they await clarity. They need internal controls that can adapt to changing requirements and increasingly autonomous systems.

Executive Ownership Shouldn’t Operate in Isolation

Another structural weakness was identified through Schellman’s research: accountability remains concentrated, but without the cross-functional input to back it up. Forty-two percent of respondents say the CIO or head of IT is primarily responsible for AI purchasing decisions, while 37 percent say the CIO is ultimately accountable when AI creates risk or something goes wrong. Only 54 percent regularly report AI governance to their boards or equivalent executive leadership.

Concentrating responsibility may create a clear point of contract, but it can also create a single point of failure. A single leader, whether that’s a CIO, Chief AI Officer, or equivalent role, should still hold ultimate accountability for AI governance, but AI risk increasingly crosses IT, security, legal, compliance, procurement, data, and individual business units. Mature governance involves routing that expertise up to a single accountable executive through controls and governance functions, so the person at the top is making an informed call rather than an isolated one.

Third-party AI makes this especially important. Only 36 percent of boards regularly discuss third-party or vendor AI risk, even though nearly every enterprise relies on software and services containing embedded AI. Just 69 percent of respondents are confident in their ability to govern AI embedded in third-party tools. In other words, organizations may be spending significant effort governing the AI they build while overlooking the AI they buy.

Governance is Becoming a Measure of Trust

Regulation will continue to shape how organizations govern AI, but compliance should not be the ultimate objective. The more important question is whether governance creates the conditions for people to trust AI enough to use it responsibly. Schellman’s research provides evidence that mature governance can deliver business value beyond risk reduction.

Fifty-seven percent of respondents say effective AI governance improves internal efficiency; 43 percent say it makes AI scaling and innovation easier, and 49 percent say it improves readiness for new regulations. Organizations are finding that governance clears the path for faster, safer scaling, rather than slowing it down. The report also identifies governance certifications and independent assessments as increasingly important in customer due diligence, RFPs, and vendor evaluations, and the market is starting to reward that proof over promises.

That suggests a fundamental shift in how organizations think about governance. The question is moving from “Do we have an AI governance program?” to “Can we prove that it works?” In practice, that means governance is becoming less of an internal checkbox and more of a competitive credential that customers and partners increasingly expect to see documented.

Readiness is the Next AI Governance Test

The challenge facing organizations goes beyond establishing AI principles or anticipating the next regulation. It involves building governance that can operate effectively as technology, business use cases, and regulatory expectations evolve.

Schellman’s findings show that awareness and investment are already widespread. Ninety-four percent of respondents are aware of regulations that may apply to their organizations, and 89 percent have taken action to prepare for U.S. requirements. But preparation drops sharply for other jurisdictions: only 29 percent have taken action related to the EU AI Act and 12 percent for requirements across Asia-Pacific markets.

The organizations that close this readiness gap will be better positioned to demonstrate accountability, respond to regulatory change, and scale AI with greater confidence. The most effective governance programs will be the ones that make responsibility visible, controls demonstratable, and human oversight meaningful.

About Joe Sigman

Joe Sigman is a Manager with Schellman based in Denver, Colorado. Prior to joining Schellman in 2021, Joe worked as a Senior Associate at a management consulting firm specializing in IT strategy and compliance, solution architecture, and enterprise digital transformation. Joe has led and supported AI Assessments, Cybersecurity Assessments, Information Security Architecture Solutioning, Information Technology Gap Analysis, and Cloud Migration Roadmaps. Joe has over 6 years of experience comprised of serving clients in various industries, including Information Technology, Professional Services, Healthcare, and Energy. Joe is now focused primarily on ISO Certifications for organizations across various industries.

About Jessica Nguyen

Jessica Nguyen is a writer for Government Technology Insider specializing in digital transformation.