Rapid Adoption of Autonomous AI Leaves Governance in the Dust
A new survey of senior artificial intelligence (AI) executives has revealed a stark disconnect between the rapid deployment of autonomous AI systems and the oversight processes designed to manage them. Despite nearly all organizations having formal AI governance policies in place, many are struggling to keep pace with the increasingly complex risks associated with agentic AI.
The Ernst & Young LLP (EY US) AI Risk and Governance Survey polled 202 senior AI executives at large enterprises, finding that while 98% reported having formal AI governance policies, about two-thirds expressed concern over a lack of internal expertise to effectively implement or design AI governance controls. Moreover, nearly half (47%) admitted that their organization has previously not followed its AI governance process for urgent deployments.
Agentic AI is being rapidly adopted across enterprises, with 91% of senior AI executives reporting their organization uses agentic AI, either through active pilot programs or full enterprise deployment. However, governance practices have not kept pace with adoption. Roughly half (49%) of respondents whose organization uses agentic AI say their organization’s existing governance framework has not yet been updated to specifically include agentic AI requirements and risks.
The issue lies in the fact that agentic AI systems are already executing critical actions without real-time human involvement, including detecting cybersecurity threats and running code. While this may bring benefits such as increased efficiency and productivity, it also introduces new risks that many organizations are struggling to manage. As one senior AI executive noted, “AI governance provides the necessary guardrails that allow organizations to move quickly without losing control.”
The survey found that 36% of respondents have experienced an AI-related incident or failure that caused a materially negative impact on their organization, including data loss, financial damage, brand damage, and operational disruptions. Moreover, about a quarter (26%) of senior AI executives whose organization uses agentic AI reported that their organization cannot detect unauthorized AI agents operating internally.
The findings highlight the pressing need for organizations to reassess their AI governance frameworks and ensure they are equipped to manage the increasingly complex risks associated with autonomous AI systems. As Richard Jackson, EY Americas Assurance Chief Technology Officer and EY Global and Americas Assurance AI Leader, noted, “Boards and C-suites are under immense pressure to accelerate their AI adoption and implement agentic AI systems. Moving fast and applying appropriate governance are not mutually exclusive — both are needed to avoid creating the risks of reputational, financial, and operational damage.”
Ultimately, the survey’s findings serve as a wake-up call for organizations to prioritize AI governance and ensure that they have adequate controls in place to manage the risks associated with autonomous AI systems. As you consider implementing agentic AI at your organization, it is essential to take a step back and assess whether your current governance framework is equipped to handle the new challenges posed by these increasingly sophisticated systems.
Practical takeaway: Don’t let the rush to adopt autonomous AI leave your organization exposed to unnecessary risks. Take time to reassess your AI governance framework and ensure that you have adequate controls in place to manage the complex risks associated with agentic AI. This may involve updating your existing governance policies, investing in additional expertise, or implementing new technologies designed specifically for AI risk management. By doing so, you can unlock the full potential of autonomous AI while minimizing the risks of reputational, financial, and operational damage.
Source: Dark Reading — 2026-09-18