
Enterprise AI governance has reached an uncomfortable stage.
The problem is no longer that organizations have no policies.
Most do.
The problem is that AI is evolving and spreading faster than those policies can be consistently applied.
EY’s September 2026 AI Risk and Governance Survey describes this as a growing confidence gap between governance design and governance execution. Most organizations have established policies, controls, review processes and oversight mechanisms. But the harder question is whether those mechanisms can keep pace with enterprise AI adoption and increasingly autonomous systems.
That distinction matters.
A governance framework can exist on paper while operational control remains incomplete.
And according to EY’s findings, that is exactly what is happening.
The Probl
em Is No Longer Policy. It Is Execution.
EY found that 98% of surveyed senior AI decision-makers reported having some form of AI governance policy in place.
Yet 47% said their organization had previously bypassed its AI governance process for an urgent deployment.
That is a significant gap.
It suggests that the challenge is no longer primarily about defining responsible AI principles.
It is about making governance work when the business is moving quickly.
Organizations may have:
AI policies,
approval processes,
risk committees,
model registers,
assurance programmes,
and responsible AI frameworks.
But if teams can bypass them under deployment pressure, governance is not fully operational.
The more useful question therefore becomes:
Can governance operate at the same speed as AI?
EY identifies an even more basic question organizations should be able to answer:
Can we provide a complete inventory of AI systems, models, agents and third-party tools?
That question goes to the foundation of enterprise AI governance.
Because governance starts with knowing what exists.

You Cannot Govern an AI Estate You Cannot See
Enterprise AI is no longer limited to a small number of centrally purchased tools.
AI can enter the organization through:
enterprise platforms,
developer tools,
APIs,
embedded AI capabilities,
third-party applications,
models,
and increasingly autonomous agents.
This creates a visibility problem.
EY found that 41% of surveyed senior AI decision-makers said they did not have visibility into all AI tools operating inside their organization.
That is important because governance depends on visibility.
If an organization does not know an AI service exists, it cannot reliably determine:
who owns it,
who uses it,
what data it accesses,
whether it has been approved,
which policies apply,
what it costs,
or what risk it introduces.
This is where AI inventory needs to evolve from a static registry into a continuously updated management capability.
An annual list of approved AI providers is no longer enough.
The enterprise needs to understand the broader AI estate.
Agentic AI Raises the Stakes
Agentic AI makes the governance challenge more difficult because organizations are no longer governing only AI-generated content.
They are beginning to govern AI-generated actions.
EY notes that organizations are deploying autonomous agents capable of executing portions of business processes on their own.
Among respondents whose organizations use agentic AI, 85% said at least some agents were already executing actions without real-time human involvement.
At the same time, 49% said their governance frameworks had not yet been specifically updated to address agentic AI risks and requirements.
This changes the governance model.
A traditional AI system may generate a recommendation.
An agent may:
execute code,
call an API,
trigger a workflow,
interact with another system,
access enterprise data,
or perform an action.
Governance therefore needs to move beyond asking:
“Is this AI approved?”
It must also ask:
“What is this AI allowed to do?”
Shadow AI Is Becoming Shadow Agentic AI
EY’s findings reveal another emerging problem.
26% of senior AI decision-makers whose organizations use agentic AI said their organization could not detect unauthorized AI agents operating internally.
This extends the traditional Shadow AI problem.
Shadow AI has generally referred to AI applications or services being used without sufficient organizational approval or visibility.
Agentic AI adds a more consequential form of the same problem.
An unmanaged AI application may process information.
An unmanaged AI agent may also take action.
That means enterprises increasingly need visibility not just into providers and applications, but also into:
agents,
their owners,
their permissions,
their tools,
their executions,
and their actions.
If an unauthorized agent cannot be detected, it cannot be effectively governed.

Ownership Is Becoming a Post-Deployment Problem
Agent governance is also exposing weaknesses in accountability.
EY found that 56% of respondents whose organizations use agentic AI said there was a perception that no single person or group was solely responsible for agentic AI after deployment.
Another 39% said accountability for maintaining or monitoring agentic AI after deployment was undefined.
This is different from traditional software ownership.
A team may build an agent.
Another team may approve it.
Security may review it.
A business unit may use it.
But once that agent begins interacting with systems and taking actions, ownership can become unclear.
Who is accountable for:
a failed action?
a model update?
a policy violation?
unexpected tool usage?
an incident?
a change in permissions?
a business outcome?
Agentic AI requires lifecycle ownership, not just deployment ownership.
The Risks Are Already Material
These governance gaps are not theoretical.
EY found that 89% of respondents had encountered AI-related risks during the previous 12 months.
Reported categories included:
52% cybersecurity risk
47% human risk
46% Shadow AI risk
More significantly, 36% said their organization had experienced an AI incident or failure that caused materially negative consequences, including data loss, financial damage, operational disruption or brand damage.
The research also found that:
72% were concerned about failing to comply with new or emerging AI-specific regulation.
72% were concerned about their ability to accurately trace or audit the data lineage and inputs feeding critical AI decision models.
These findings change the governance conversation.
It is no longer enough to ask:
Do we have controls?
The better question is:
What evidence proves that those controls are actually working?
Governance Is Also Becoming a Cost Problem
The EY research also points to a connection between governance and AI economics.
59% of respondents were concerned about overspending on AI tokens.
That matters because AI visibility and financial visibility increasingly overlap.
An organization may have:
multiple AI subscriptions,
duplicate provider capabilities,
unused licenses,
unattributed token consumption,
business-led AI purchases,
or agents consuming APIs without clear cost ownership.
An AI system that is invisible to governance may also be invisible to financial management.
This means AI governance, FinOps and software asset management are beginning to converge.
Enterprises increasingly need to understand not only:
What AI exists?
but also:
Who owns the spend?
Who is using it?
What business purpose does it support?
And is the value worth the cost?
Assurance Is Finding What Governance Misses
One of the strongest findings in the EY research concerns AI assurance.
98% of respondents said their organization conducts a formal AI assurance review at least annually, and 80% conduct those reviews monthly or quarterly.
More importantly, those reviews are finding real problems.
Among organizations conducting formal AI assurance reviews, 92% found issues.
Those findings resulted in significant action:
64% said at least one-quarter of reviewed AI systems were significantly modified.
29% said at least one-quarter were paused.
25% said at least one-quarter were stopped entirely.
The most common findings were:
57% data quality problems
48% AI model drift
39% Shadow AI
These numbers demonstrate why AI assurance cannot be treated as a one-time approval exercise.
AI systems change.
Models change.
Providers change.
Data changes.
Agents gain new capabilities.
Business processes evolve.
Governance therefore needs a recurring evidence loop.

AI Governance Needs to Become an Operating Discipline
EY’s conclusion is particularly important.
Organizations need to move beyond treating governance as a framework and begin treating it as an operating discipline.
That means:
maintaining visibility across the AI estate,
clarifying ownership throughout the lifecycle,
embedding controls into the pace of deployment,
and making assurance a recurring source of evidence rather than a periodic checkpoint.
The distinction is simple.
A framework describes what should happen.
An operating discipline helps an organization understand what is happening now.
That requires continuous discovery, context, ownership, evidence and action.
Where AssetUno AI Fits
This is the management problem AssetUno AI is designed to address.
AssetUno AI approaches enterprise AI governance as a connected management environment rather than a static policy exercise.
The objective is to bring together evidence across AI providers, applications, security sources and organizational context so enterprises can understand and manage their AI estate.
That includes several connected areas.
AI Discovery and Shadow AI help identify known, unmanaged and insufficiently governed AI activity.
Agentic AI Governance extends visibility toward agents, executions, tools and actions as autonomous AI becomes part of enterprise operations.
Organizational Context connects AI activity to users, teams, departments, projects, cost centers and responsible owners.
Usage & Cost Optimization provides context around provider usage, tokens, requests, licenses and cost.
Governance and Assurance connect evidence with ownership, policies, risk, exceptions and remediation.
AI Value & Outcomes move the conversation beyond adoption by connecting AI activity to work output and measurable business outcomes.
The goal is not to replace security platforms, AI providers or assurance teams.
It is to create the management context that connects their evidence.
Because AI governance becomes much more useful when an enterprise can answer three questions together:
What exists?
Is it governed?
Is it creating value?
The Next AI Governance Gap Is Operational
EY’s 2026 survey shows that enterprise AI governance has progressed significantly.
Policies exist.
Review structures exist.
Controls exist.
But operational effectiveness remains uneven.
The next stage of AI governance therefore will not be defined by how many policies an organization has created.
It will be defined by whether the organization can:
see its AI estate,
identify unauthorized AI and agents,
assign ownership,
monitor activity,
produce evidence,
manage cost,
respond to risk,
and connect AI investment to measurable value.
The central issue is no longer whether governance exists.
It is whether governance can keep pace with AI.
That is the gap enterprises now need to close.
Primary Reference: EY US, Realizing Potential: Confidence in AI, AI Risk and Governance Survey, September 2026
The survey included 202 US senior AI decision-makers at publicly traded companies with annual revenue of at least $1 billion. Respondents had direct oversight of AI systems, governance or audit processes. The survey was conducted between May 28 and June 15, 2026, with a reported margin of error of ±7 percentage points at the 95% confidence level.



