Skip to content
Tech News
← Back to articles

EY Survey Finds Autonomous AI Implementation Outpaces Oversight

read original more articles
Why This Matters

This EY survey highlights a widening gap between how fast companies are deploying autonomous AI agents and how well they're actually governing them, even as nearly all claim to have formal policies in place. That disconnect matters because it raises real risks around data loss, financial and brand damage, and unauthorized 'shadow AI' operating without oversight—issues that could affect both businesses and the consumers who rely on their services.

Key Takeaways

PRESS RELEASE

About half (47%) of respondents say their organization has previously not applied its AI governance process for urgent deployments, despite 98% having formal AI governance policies in place.

Agentic AI adoption is creating new governance challenges, with 26% of respondents whose organization uses agentic AI admitting that their organization cannot detect unauthorized AI agents operating internally.

About a third (36%) have experienced an AI incident or failure that caused a materially negative impact to their organization, including data loss, financial damage, brand damage and operational disruptions.

NEW YORK, September 15, 2026 — Although organizations are formalizing AI governance while rapidly deploying AI and autonomous AI agents, many are still struggling to keep policy and practice aligned, according to the new Ernst & Young LLP (EY US) AI Risk and Governance Survey. By surveying 202 senior AI executives (including board members, C-suite, VP+ leaders) at organizations generating at least $1 billion in annual revenue, the study explores how leaders govern AI, including: how quickly governance frameworks are adapting to agentic AI, the extent and impact of AI-related risk, and the role of formal assurance reviews in identifying and correcting issues.

Related:AI Agent Breaches Spanish Organization, Modifies Personal Data

The survey found that while almost all senior AI executives (98%) report having formal AI governance policies in place, about two-thirds of senior AI executives expressed concern over a lack of internal expertise to effectively evolve (69%), implement (63%) or design (63%) AI governance controls at their organization. About half (47%) of the respondents have even admitted that their organization has previously not followed its AI governance process for urgent deployments, even as AI-related incidents, cyber risk and shadow AI have become more common.

“Organizations are applying yesterday’s governance rules to today’s interactions with AI,” said Richard Jackson, EY Americas Assurance Chief Technology Officer and EY Global and Americas Assurance AI Leader. “Boards and C-suites are under immense pressure to accelerate their AI adoption and implement agentic AI systems. Moving fast and applying appropriate governance are not mutually exclusive — both are needed to avoid creating the risks of reputational, financial and operational damage.”

Agentic AI Is Outpacing Governance Frameworks

Agentic AI is being rapidly adopted across enterprises, with 91% of senior AI executives reporting their organization uses agentic AI, either through active pilot programs or full enterprise deployment. However, governance practices have not kept pace with adoption. Roughly half (49%) of respondents whose organization uses agentic AI say their organization’s existing governance framework has not yet been updated to specifically include agentic AI requirements and risks. While agentic AI systems are already executing critical actions — from detecting cybersecurity threats to running code — 85% of senior AI executives whose organization uses agentic AI admit that at least a handful of these systems execute actions without real-time human involvement.

... continue reading