EY survey: 47% of companies bypass AI governance despite policies
Serge Bulaev
An EY survey suggests that almost half of companies may be skipping AI safety checks even though most have formal rules in place. Many leaders admitted they struggle to find unauthorized AI systems in their networks and worry their teams lack the skills to keep up with needed controls. The gap seems to exist because executives feel pressure to launch AI tools quickly, making it hard to follow all rules closely. Experts recommend more frequent and detailed checks inside the development process, instead of occasional reviews. This governance problem may now be a common risk for companies, not just a special ethical issue.

A new EY survey reveals that 47% of companies bypass AI governance policies despite nearly all having them, creating a significant risk gap. This oversight failure stems from intense pressure to deploy AI features quickly, a widespread lack of skilled personnel, and an inability to detect unauthorized "shadow AI" systems. The findings signal a shift where AI governance has become a mainstream operational risk, moving beyond a niche ethical concern.
What did the EY survey actually find about AI governance?
The latest EY survey finds that autonomous AI implementation outpaces oversight, revealing a critical policy-practice gap. While 98% of organizations have formal AI policies, 47% of senior AI leaders admit to bypassing these controls for urgent deployments. This creates an "AI governance gap," further highlighted by the fact that 26% cannot detect unauthorized AI agents on their networks. Compounding the issue, two-thirds of executives worry their teams lack the expertise to manage AI controls effectively.
Companies bypass their own AI governance policies primarily due to intense pressure to accelerate speed-to-market. When competitive urgency conflicts with formal review processes, leaders often prioritize rapid deployment over exhaustive vetting, leading to the use of unapproved tools and creating significant gaps in operational oversight.
Why are companies bypassing their own AI governance policies?
The primary driver is the relentless pressure for speed. An earlier EY poll confirmed that 85% of tech leaders prioritize rapid market entry over thorough vetting, and over half of departmental AI projects run without formal approval, as detailed in a report on how autonomous AI adoption surges at tech companies. This dynamic fosters a "shadow AI" environment where unapproved tools proliferate. The fundamental issue is that having a policy document is not equivalent to operational control; organizations lack the real-time enforcement and monitoring needed to ensure compliance.
What specific risks emerge from this governance gap?
This governance gap exposes companies to severe operational, regulatory, and reputational risks:
- Regulatory & Compliance Failures: Inadequate controls and poor documentation can lead to significant fines under maturing frameworks like the EU AI Act.
- Security Vulnerabilities: Lacking visibility into AI agents creates security blind spots. Industry reports indicate that many CIOs doubt they could contain a compromised agent, turning poor governance into an active threat.
- Eroding Accountability & Reputation: When autonomous AI systems cause data leaks or biased outcomes, the incident becomes a public failure of management oversight, making it nearly impossible to assign liability.
How quickly do governance controls degrade in practice?
AI governance controls can degrade with alarming speed. Operational data shows that governance rules embedded in system prompts can be forgotten by an AI agent in as little as nine days - a phenomenon known as "memory drift." This rapid decay proves that static, one-time policy configurations are insufficient. Without continuous monitoring and reinforcement, initial safety constraints will inevitably fail in dynamic operational environments.
What practical steps can organizations take to close this gap?
To effectively close the AI governance gap, experts recommend an operational approach built on continuous oversight rather than static policies. The emerging playbook focuses on several key pillars:
- Establish Full Visibility: Create and maintain a comprehensive inventory of all models, agents, data sets, and shadow AI tools before expanding.
- Implement Risk-Tiered Controls: Classify all AI systems by their potential impact and autonomy, applying the strictest governance to high-stakes use cases.
- Integrate Enforcement into Workflows: Embed automated policy checks, approval gates, and logging directly into the development and deployment lifecycle.
- Adopt Continuous Verification: Shift from annual audits to quarterly reviews, and implement ongoing monitoring for model drift, bias, and policy violations.
Mature governance programs treat AI as a core operational risk, demanding documented ownership, measurable controls, and a complete audit trail.