A significant and concerning trend is emerging within the Governance, Risk, and Compliance (GRC) landscape, as nearly half of all GRC professionals report that Artificial Intelligence (AI) tools are, in fact, making their jobs more difficult. This counterintuitive finding, detailed in a recent survey by Drata, a prominent cybersecurity and compliance automation platform, challenges the widely held assumption that AI is primarily a tool for streamlining and simplifying complex operational tasks. The survey, which polled 300 IT and security professionals within large organizations, revealed that a substantial 43% of respondents believe their current AI implementations have actively increased the complexity and burden of their roles.
This data point has sent ripples through the industry, prompting urgent re-evaluations of GRC strategies and investments. Researchers behind the Drata report emphasized the profound implications of this finding, stating, "That number alone should reset every conversation happening in GRC procurement, board meetings, and vendor briefings right now. The technology that was supposed to absorb the manual load, accelerate the judgment work, and free teams from compliance drudgery is, for a substantial share of practitioners, doing the opposite." The expectation was that AI would act as a powerful accelerant, automating repetitive tasks, identifying potential risks with greater precision, and freeing up human capital for more strategic endeavors. Instead, for a significant portion of the GRC workforce, AI has introduced new layers of complexity, requiring specialized skills to manage, validate, and integrate, thus paradoxically increasing workload.
Further analysis of the Drata survey data reveals that the perception of AI’s difficulty is not uniform across all organizations. A notable disparity exists based on company revenue. Professionals at higher revenue-generating firms appear to be navigating the AI integration with less perceived difficulty. Specifically, among respondents at companies earning $250 million or more annually, only 36% reported that AI makes their work more challenging. This contrasts sharply with the 55% of professionals at companies earning less than $250 million per year who voiced similar concerns. This suggests that larger enterprises, potentially with greater resources for AI implementation, training, and dedicated AI governance teams, might be better equipped to harness the intended benefits of AI, or perhaps have more mature strategies for its deployment. Smaller organizations, facing tighter budgets and fewer dedicated resources, may be struggling more with the integration and management of these advanced technologies.
The Drata survey’s findings paint a broader picture of AI’s less-than-stellar performance in the GRC domain. Beyond the perceived increased difficulty, a staggering 90% of all respondents admitted that some of their AI investments have fallen short of their initial expectations. This widespread underperformance indicates a potential disconnect between the promise of AI and its practical application within GRC functions. Even more concerning is the statistic that nearly three-quarters (71%) of GRC professionals reported that an AI tool they used for GRC functions has directly contributed to a failed audit or a lapse in regulatory compliance. This raises serious questions about the reliability, accuracy, and efficacy of current AI solutions when applied to critical compliance tasks. The implications of such failures can be severe, ranging from significant financial penalties and reputational damage to loss of operational licenses and increased scrutiny from regulatory bodies.
The challenges observed in GRC are mirrored, albeit with a different emphasis, in the realm of Mergers and Acquisitions (M&A). A new survey conducted by Datasite, a leading platform for M&A information, reveals that a majority of senior dealmakers do not believe that the ultimate decision to sign a merger or acquisition deal should remain solely a human responsibility. This sentiment underscores a growing acceptance, and perhaps even an expectation, of AI’s role in high-stakes corporate transactions.
The Datasite survey, which encompassed 1,000 executives, directors, and senior leaders across 27 countries, found that 45% of respondents still believe that the decision to proceed to signing should be exclusively human-driven. However, a significant portion, 33%, expressed that the decision should be an AI recommendation that humans then approve. Another 22% believe that AI should inform human decisions, leading to an AI-informed human call. This indicates a clear shift towards a more hybrid decision-making model, where AI plays a consultative or advisory role. Despite this openness to AI involvement, a robust 58% of dealmakers indicated that they still require human validation or review of AI-generated outputs, highlighting a persistent need for human oversight in critical financial and strategic decisions.
The survey further highlights the perception of AI’s indispensability in modern M&A. A substantial majority, nearly two-thirds (62%) of respondents, stated that relying solely on human decision-making is no longer a defensible strategy in complex M&A scenarios. This sentiment suggests a growing recognition of AI’s capacity to process vast amounts of data, identify patterns, and potentially uncover insights that might elude human analysts, especially under the time pressures inherent in deal-making. Furthermore, 43% of dealmakers believe that AI already makes better deal decisions than humans in certain situations, and a compelling 71% predict that firms failing to adopt AI within the next five years will face significant viability challenges. This forward-looking perspective suggests that AI is not merely a tool but a fundamental enabler of competitive advantage in the M&A arena.
Adding another layer to the complex picture of AI adoption, a recent survey by TrustedTech, a Microsoft cloud solution provider, sheds light on the prevalence of "shadow AI" – the use of unauthorized AI tools within organizations. The findings reveal a striking disparity in shadow AI usage between company leaders and lower-level employees, with decision-makers being twice as likely to engage with these unapproved tools.
The TrustedTech survey, which surveyed approximately 2,000 US and UK companies, found that nearly two-thirds (65%) of senior decision-makers reported using shadow AI. This figure stands in stark contrast to the 31% of non-decision-making employees who admitted to similar practices. The trend is even more pronounced at the executive level, with 73% of C-suite executives reporting the use of shadow AI, a rate nearly double that of entry-level employees, 36% of whom use unapproved AI tools. This phenomenon raises significant concerns for IT and security departments, as shadow AI often operates outside of official security protocols and data governance frameworks, creating potential vulnerabilities for data breaches and intellectual property theft.
Paradoxically, the very individuals most likely to be using shadow AI are also more likely to express concerns about its use within their organizations. The survey indicates that 56% of decision-makers are concerned about shadow AI, compared to 31% of other employees. This suggests a nuanced understanding among leaders about the risks associated with these unauthorized tools, even as they themselves engage with them. Furthermore, the decision-making group exhibits a more optimistic outlook on AI in general. They are more confident in their ability to use AI effectively (78% compared to 43% of others) and more celebratory of its integration into the workplace (51% compared to 25% of others). This could stem from their direct experience with the perceived benefits of AI in their roles, or perhaps from a belief that they can manage the associated risks more effectively due to their position and access to information.
Implications and Future Outlook
The collective findings from these surveys present a complex and evolving narrative around AI’s integration into the corporate world, particularly within GRC and M&A. The initial promise of AI as a universal solution for efficiency and accuracy appears to be encountering significant friction points. In GRC, the reported increase in job difficulty and the high rate of unmet expectations suggest that organizations are struggling with the practical implementation and management of AI tools. This could be due to a lack of adequate training, insufficient integration strategies, or the inherent complexity of compliance regulations themselves, which may not always translate cleanly into algorithmic logic. The direct link between AI tools and failed audits is a particularly alarming indicator that requires immediate attention from both AI developers and compliance professionals. A critical area for future development will be creating AI solutions that are not only powerful but also inherently transparent, explainable, and easier to integrate into existing workflows, with robust safeguards to prevent compliance failures.
In the M&A sphere, the trend towards AI-informed decision-making signifies a fundamental shift in how deals are conceived, evaluated, and executed. While human judgment remains crucial, the ability of AI to analyze vast datasets and identify potential risks and opportunities is becoming increasingly indispensable. The concern for firms that do not adopt AI is palpable, suggesting a competitive imperative to embrace these technologies. However, the continued need for human validation underscores the importance of a balanced approach, where AI serves as a powerful analytical engine supporting, rather than replacing, human strategic insight and ethical consideration. The development of robust AI governance frameworks for M&A will be paramount to ensure that these tools are used responsibly and ethically.
The issue of shadow AI adds another layer of complexity, highlighting a disconnect between official policies and employee behavior, particularly among those in leadership positions. The fact that decision-makers are both more likely to use unauthorized AI and more concerned about its risks points to a significant governance challenge. Organizations need to address the underlying reasons for shadow AI adoption, which may include a perceived lack of adequate official tools or a desire for agility. This requires a proactive approach to AI policy development, clear communication of risks and benefits, and the provision of secure, approved AI solutions that meet the needs of all employees. Failure to address shadow AI could lead to significant security vulnerabilities, data integrity issues, and compliance breaches, undermining the very goals that AI is intended to support.
Collectively, these insights suggest that the journey of AI integration is still in its nascent stages, marked by both significant potential and considerable challenges. As AI technology continues to mature, it will be crucial for organizations to invest not only in the technology itself but also in the strategic planning, skilled personnel, and robust governance frameworks necessary to harness its power effectively and responsibly. The future of GRC, M&A, and broader corporate operations will undoubtedly be shaped by AI, but achieving its full benefits will require a more nuanced, strategic, and human-centric approach than is currently being realized. The onus is on industry leaders, technology providers, and regulatory bodies to collaborate and ensure that AI serves as a true enabler of progress, rather than a source of unintended complications.
