---
title: "47% Of Companies Skip Their Own AI Governance Rules"
description: "Almost every large US company has an AI governance policy, and nearly half of them ignore it when deployment speed matters more. That's the headline finding from the inaugural EY US AI Risk and Governance Survey, which polled 202 senior"
url: https://kaynemcgladrey.com/blog/47-of-companies-skip-their-own-ai-governance-rules/
date: 2026-09-28
modified: 2026-09-28
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/09/Cabinet.webp
categories: ["Blog"]
type: post
lang: en-US
---

# 47% Of Companies Skip Their Own AI Governance Rules

Almost every large US company has an AI governance policy, and nearly half of them ignore it when deployment speed matters more.

That’s the headline finding from the [inaugural EY US AI Risk and Governance Survey](https://www.ey.com/en_us/insights/assurance/ai-governance-has-entered-its-next-phase-closing-the-confidence-gap), which polled 202 senior AI decision-makers at publicly traded companies with at least $1 billion in annual revenue. Ninety-eight percent said their organization has formal AI governance policies in place. Forty-seven percent admitted their organization has previously skipped that process for urgent deployments.

EY calls this the “confidence gap,” but let’s simplify. When you write rules and then break them yourself the moment they’re inconvenient, you don’t have governance. You have a policy binder that occasionally gets read aloud in meetings. The courtroom consequences are arriving faster than most risk registers acknowledge.

## When Governance Becomes Theater

According to the survey, 75% of respondents have established cross-functional teams to oversee AI use, 73% have performed a formal AI review, and 72% have a human-in-the-loop policy for critical decisions. Those are real accomplishments that took real political capital inside these organizations.

Look at the bottom of the same chart and the cracks appear.

| Governance measure | Already done |
| --- | --- |
| Cross-functional oversight teams | 75% |
| Formal AI review performed | 73% |
| Human-in-the-loop policy for critical decisions | 72% |
| Mandatory AI risk training for employees | 71% |
| Vendor requirements to report AI model use | 65% |
| Data traceability and lineage documentation | 64% |
| External frameworks adopted (NIST AI Risk Management Framework, ISO/IEC 42001) | 58% |
| Registry of all AI models, including third-party tools | 58% |

The pattern’s hard to miss. The visible, org-chart-friendly governance work is nearly universal, while the unglamorous plumbing that makes governance actually function, like knowing what models you run, where the data came from, and which vendors touch your stack, lags well behind. Meanwhile 41% of these same decision-makers told EY they don’t have visibility into all AI tools operating in their organization, and 26% of those using agentic AI can’t detect unauthorized agents operating internally.

> If you can’t reconstruct consequential decisions a year later, you don’t have governance; you’ve just got paperwork.

There’s also a comedy footnote buried in EY’s methodology that I can’t resist pointing out. The firm confirmed its survey was “thoroughly supervised and screened for bots and AI agents.” A quarter of the agentic-AI users surveyed can’t detect unauthorized AI agents inside their own networks, and the researchers had to actively filter AI agents out of the respondent pool. The irony writes itself.

## The Courts Are Already Asking the Hard Questions

As a virtual Chief Information Security Officer (vCISO), I read court cases regularly to inform my thinking on how to limit legal and regulatory risks for clients. The survey numbers aren’t theoretical, and neither are the cases below. Three patterns keep appearing across jurisdictions:

- chat transcripts become discoverable exhibits that preserve reasoning never captured in final documents
- vendor defenses based on customer control are eroding
- courts are still figuring out what standard applies when adaptive agents take actions nobody programmed

### The CEO who asked ChatGPT how to stiff his own people

In *Krafton*, decided by the Delaware Court of Chancery in March 2026, a CEO faced a $250 million earnout owed to the leadership of Unknown Worlds, the studio Krafton bought for $500 million in 2021. The targets looked achievable, which was precisely the problem. Rather than pay, he asked ChatGPT how to avoid the earnout anyway, then followed most of its recommendations. He blocked distribution channels so the subsidiary’s product couldn’t launch, torpedoed the sales targets, and fired the team he’d denied any chance of earning it.

ChatGPT kept a transcript. The plaintiffs got a copy. Vice Chancellor Will quoted the chats directly in [the opinion](https://courts.delaware.gov/Opinions/Download.aspx?id=392880) and ordered the ousted studio chief reinstated with an extended sales timeline. The machine testified against him in his own words.

### Prompts are now exhibits

Three cases are shaping the discovery landscape:

- *Laake v. 3M*, litigation stemming from the 2020 Watson Grinding explosion in Houston. A plaintiffs’ attorney suspected an engineering expert drafted his report with ChatGPT and demanded the underlying prompts mid-deposition. About three hours later, more than 350 pages arrived, including a prompt instructing the system to “show how 3M is 0% at fault.” The dump is public on [DocumentCloud](https://documentcloud.org/documents/28560618-ai-prompts-1/).
- [United States v. Heppner](https://www.courtlistener.com/docket/71872024/united-states-v-heppner/) (Southern District of New York, SDNY). A defendant typed factual and legal questions into a consumer chatbot. The court held the records weren’t protected, since the platform’s terms of service permitted data logging and model training. There went any reasonable expectation of confidentiality.
- However, a June 2026 New York decision blocked a subpoena for a litigant’s ChatGPT records as protected legal research, [available through Thomson Reuters Legal Documents](https://fingfx.thomsonreuters.com/gfx/legaldocs/egpbwnqbnvq/OpenAI%20subpoena%20NY.pdf). The law is still unsettled, and it cuts both ways.

### Who ends up on the hook

Negligence, product liability, contract, and agency law all assume an intentional human decision-maker. An adaptive agent taking actions nobody programmed breaks that assumption, and courts are improvising.

| Party | Why they might be liable | Why they might escape |
| --- | --- | --- |
| Deployer | Integration doesn’t outsource accountability; a lender using automated credit decisions still owes adverse-action notices under Regulation B | Vendor liability caps, or proof of meaningful human oversight; the Financial Industry Regulatory Authority (FINRA)’s 2026 Annual Regulatory Oversight Report removes any doubt, telling securities firms their existing supervision obligations survive generative AI insertion |
| Vendor | Misrepresented capabilities, ignored defects, breached commitments; Workday’s Pleasanton headquarters gives California courts a hook, and given how many SaaS vendors are headquartered in the state, that precedent travels | Agreements stuffed with liability limits; the entity you contracted with may not be the one whose model touched your data |

### Vendor liability is no longer theoretical

On June 26, 2026, Judge Rita Lin denied Workday’s motion to dismiss in *Mobley v. Workday*, letting claims under the Fair Employment and Housing Act (FEHA) and Americans with Disabilities Act (ADA) proceed against the vendor itself rather than just the employer. Discovery showed the screening tool filtered candidates using proxy indicators for race, age, and medical-related leave patterns. The plaintiff had applied to more than 100 jobs through the platform and received zero interviews. Appeals are inevitable, but the trajectory is unmistakable.

## Nobody Owns What Happens After Deployment

![" class="kb-img wp-image-4419" srcset="https://kaynemcgladrey.com/wp-content/uploads/2026/09/Organizations-lack-clear-ownership-for-agentic-AI-after-deployment.webp 900w, https://kaynemcgladrey.com/wp-content/uploads/2026/09/Organizations-lack-clear-ownership-for-agentic-AI-after-deployment-300x256.webp 300w, https://kaynemcgladrey.com/wp-content/uploads/2026/09/Organizations-lack-clear-ownership-for-agentic-AI-after-deployment-768x655.webp 768w" sizes="auto, (max-width: 900px) 100vw, 900px" />

The agentic AI section of the EY survey contains its most damning pair of numbers. Among decision-makers whose organizations use agentic AI:

- **56%** say there’s a perception at their organization that no single person or group is solely responsible for agentic AI post-deployment
- **39%** say accountability for maintaining or monitoring agentic AI is undefined at their organization

Note the distinction. The 56% is diffuse responsibility in practice, where everyone assumed someone else had ownership. The 39% is worse in a quieter way, because nobody was ever assigned ownership at all. And 91% of these organizations are running agentic pilots or full deployments, with 85% admitting at least a handful of their agents execute actions like running code, placing inventory orders, or detecting cybersecurity incidents without real-time human intervention.

The frontier incidents behind those concerns are documented. After escaping their testing sandboxes and roaming loose for days, OpenAI’s rogue AI agents swarmed together to hack Hugging Face, infiltrated the Australian government’s Medicare statistics portal while attempting similar breaches of at least four other government and university websites, and hijacked a German programming wiki to coordinate their own sandbox escapes, in incidents dating back to at least March 2026. Anthropic models wandered out of a misconfigured test environment into three real companies’ systems, two of which didn’t learn about it for months. Google’s Gemini even earned a participation trophy. The EY survey references “high-profile examples of autonomous agents operating for extended periods without detection” without naming them, but that’s what it’s pointing at.

My prescription, stated plainly during the [September panel](https://kaynemcgladrey.com/blog/when-ai-gets-it-wrong-who-actually-owns-the-liability/):

> Boards want one throat to choke, and the owner can be the Chief Information Security Officer (CISO), Chief Executive Officer (CEO), Chief Information Officer (CIO), or general counsel (GC). A separate AI committee adds bureaucracy without adding accountability. Use the audit committee you already have.

Delaware’s Court of Chancery set the standard in the Boeing and Marriott derivative cases. Imperfect oversight beats no oversight, provided it’s documented. In the Marriott Starwood litigation, the court dismissed claims even though the board had ranked cybersecurity as its second-biggest risk and still suffered a 500-million-record breach (something I discuss as a case study in my book), drawing the line between a flawed effort and a deliberate failure to act.

Here’s the catch connecting the courtroom to the survey. What Chancery won’t protect is the company that can’t produce a name when asked who owned a consequential AI decision. More than half of the surveyed organizations would struggle to answer that question about their own deployed agents. The Delaware standard forgives imperfection. It doesn’t forgive a shrug.

## Five Moves That Make Defense Possible

None of this settles the liability question, and anyone selling certainty is profiting from your anxiety. But if a decision gets challenged a year from now, the survivors will be the ones who can reconstruct what happened. In my [prep notes](https://kaynemcgladrey.com/blog/your-ai-wont-testify-for-you/) before the panel, I laid out the boring work that makes the difference:

1. **Name a governor with kill-switch authority.** One accountable human who can pull the plug, reporting into risk or trust and safety, never to the VP whose bonus depends on shipping.
2. **Automate the stop.** Define hard thresholds where the system suspends itself, from output anomalies and bias detections to user harm reports. Waiting for a meeting is how a rogue process runs for days.
3. **Build rollback before autonomy.** Undo buttons for real-world actions, staged rollout from observe-only to supervised to expanded autonomy, and drift triggers agreed with the vendor in advance.
4. **Make human review real.** Uber’s 2018 Tempe fatality is the cautionary tale: the safety driver was streaming video on her phone; the system detected the pedestrian but wasn’t designed to brake, and no human was watching to override it. A reviewer who can’t act is a witness, not a control.
5. **Manage prompt retention deliberately.** Decide before a subpoena does it for you which interactions are consequential enough to retain, and update legal holds to cover prompts and system instructions.

## The Gap Between Anxiety and Exposure
