AN Ernst & Young (EY) survey says organisations are deploying artificial intelligence (AI), including autonomous “agentic” systems, faster than they can update governance and oversight. The study questioned 202 US senior AI decision-makers at publicly traded companies with annual revenue of at least $1 billion between 28 May and 15 June 2026; its margin of error was plus or minus 7 percentage points.
Although 98% said their organisation had formal AI governance policies, 47% said those processes had not been followed during urgent deployments. In addition, 69% cited insufficient expertise to evolve governance controls, while 63% reported difficulties implementing or designing them.
Agentic AI was in active pilots or enterprise deployment at 91% of respondents’ organisations. Among those users, 49% said their governance framework did not yet specifically cover agentic AI risks, 85% said at least some systems acted without real-time human involvement, and 26% said they could not detect unauthorised AI agents operating internally.
The survey found that 89% had encountered AI-related risks in the previous year, including cybersecurity, human and shadow-AI risks, while 36% reported an AI incident or failure causing material harm such as data loss, financial damage, operational disruption or brand damage.
EY said formal assurance reviews are helping organisations respond. Nearly all respondents had conducted one at least annually; those reviews identified data-quality problems in 57% of cases, model drift in 48% and shadow AI in 39%. They led organisations to modify, pause or stop some AI systems, although the survey does not establish that the reported incidents were caused by agentic AI specifically.