Security · Governance & Compliance

The Governance Gap:
Adoption Has Outrun Its Guardrails

m2m2-consultingAugust 20268 min read
adoptionpolicyoversightauditcontrol

Adoption is a board topic. Governance isn't.

There is no shortage of executive enthusiasm for AI. What is scarce is executive ownership of its risks. McKinsey's global survey found that only 28% of organisations using AI say their CEO oversees AI governance, and just 17% report oversight at board level [1]. The technology is discussed at the top of the house; the responsibility for it, mostly, is not held there.

The consequences are already visible. In McKinsey's late-2025 wave, 51% of organisations reported experiencing at least one negative consequence from their AI use [2]. And as agentic systems — AI that takes actions, not just answers questions — move into production, the guardrails are lagging further behind: Deloitte's 2026 research found that only around one in five organisations has a mature governance model for agentic AI, meaning roughly 80% are deploying systems that act on their behalf without clear approval boundaries, monitoring, or audit trails [3].

The evidence

28% CEO / 17% board: the share of AI-using organisations with executive-level governance oversight (McKinsey) [1].

~80% lack a mature governance model for agentic AI (Deloitte, 3,235 leaders, 2026) [3].

362 AI incidents in 2025, up from 233 in 2024 — a 55% year-over-year rise (Stanford HAI AI Index) [4].

Harms are rising, and they're being counted

This is not a governance gap in the abstract. Stanford's AI Index — the most rigorous independent tracker in the field — recorded 362 documented AI incidents in 2025, up from 233 the year before, itself a jump of more than half over 2023 [4]. As deployment scales, the number of things going measurably wrong scales with it. Governance is the discipline of making that curve bend the other way; the data says most organisations have not yet started.

Compliance retrofitted after deployment costs a multiple of compliance designed in. The organisations discovering this are doing so during audits, not before them.

The regulatory clock is specific

For any organisation operating in or selling into the EU, the governance gap now has hard deadlines attached. The EU AI Act entered into force on 1 August 2024, and its obligations phase in on a fixed schedule:

DateWhat applies
2 Feb 2025Prohibited AI practices banned; the Article 4 AI-literacy obligation for staff applies
2 Aug 2025Obligations for general-purpose AI models; governance provisions; penalty regime
2 Aug 2026High-risk systems under Annex III; the general date of application
2 Aug 2027High-risk AI as a safety component under existing product law

The penalties are calibrated to be felt. Prohibited practices carry fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher; other breaches up to €15 million or 3%; supplying misleading information to authorities up to €7.5 million or 1% [5]. These are not GDPR-adjacent numbers — for the most serious category, they exceed GDPR's ceiling.

What good governance actually requires

Governance that survives contact with engineering is not a committee and a slide deck. It is a small set of concrete artefacts and controls:

The gap between adoption and governance is not evidence that AI was a mistake. It is evidence that the operational discipline has not yet caught up with the enthusiasm. That is a solvable problem — but the solving has a deadline now, and the penalty for missing it is written into law.