Recent research underscores a significant gap between the rapid adoption of Artificial Intelligence (AI) within enterprises and the maturity of their governance frameworks, raising concerns about potential risks and hindering the realization of tangible benefits. While a majority of organizations are actively integrating AI into their operations, a substantial portion admits to lagging behind in establishing comprehensive oversight and control mechanisms. This disparity, highlighted by two independent surveys, suggests a critical need for organizations to prioritize the development and implementation of robust AI governance strategies to navigate the evolving technological landscape responsibly.

A new survey conducted by Smarsh and FTI Consulting reveals that 55% of enterprises are currently deploying AI technologies. However, a striking disconnect emerges when examining governance readiness: only 26% of these organizations reported that their AI governance frameworks are fully aligned with the pace of this rapid implementation. While this figure indicates a majority, 57%, believe their governance practices are keeping pace, the existence of acknowledged gaps points to areas where oversight may be insufficient or reactive rather than proactive.

Jonathan Roberts, senior director of risk and compliance at FTI Technology, articulated the potential ramifications of this governance lag. "With continuing AI adoption, individual employees will seek to upskill on their own to adapt," Roberts stated in the report. "For some organizations, this may lead to increased risks to data privacy, data protection, and corporate governance through shadow IT apps, uneducated use, and hallucinated outcomes that result in liability implications." This underscores the dual challenge of managing both the intended and unintended consequences of AI deployment, particularly as individual employees leverage AI tools without explicit organizational guidance or oversight. The rise of "shadow IT" applications, where employees utilize unauthorized software or platforms, is a well-documented concern that AI adoption can exacerbate, potentially bypassing established security protocols and data handling policies.

The Smarsh and FTI Consulting survey involved 114 decision-makers and leaders responsible for digital communications monitoring and archiving solutions across enterprise, corporate, and public sector organizations in the United States. The insights were further refined by focusing on 47 enterprise-level decision-makers operating within the financial services, insurance, and banking sectors, industries that are often at the forefront of technological adoption and subject to stringent regulatory scrutiny. This specific focus on highly regulated sectors provides a critical lens on the challenges of AI governance in environments where compliance and risk management are paramount.

The AI Governance Conundrum: A Widening Chasm

The Smarsh and FTI Consulting findings paint a picture of an industry grappling with the speed of AI innovation. The survey, released in early 2024, builds upon a growing body of research indicating that while the allure of AI’s transformative potential is undeniable, its practical integration is outpacing the development of commensurate governance structures. This imbalance poses significant challenges, ranging from data security vulnerabilities and privacy breaches to ethical dilemmas and potential legal liabilities.

The concept of "shadow AI," mirroring the well-established threat of shadow IT, is a significant concern highlighted by the report. As employees independently explore and utilize AI tools to enhance productivity or perform tasks, they may inadvertently expose sensitive corporate data to external platforms or generate outputs that are factually inaccurate or biased. This can occur through the use of publicly available AI models that lack enterprise-grade security or through the misuse of AI-generated content that is not adequately vetted. The "hallucination" phenomenon, where AI models generate plausible-sounding but factually incorrect information, is a particularly potent risk, capable of leading to flawed decision-making and significant reputational damage.

For organizations in sectors like financial services and banking, where data integrity and customer trust are foundational, the implications of inadequate AI governance are particularly severe. Regulators are increasingly scrutinizing the use of AI in these industries, demanding clear accountability and robust risk management frameworks. The gap identified in the Smarsh and FTI Consulting survey suggests that many organizations may be operating with a false sense of security, believing their existing governance structures are sufficient to manage the complexities of AI.

The GRC Landscape: Hesitation Amidst High Adoption

Compounding these concerns, a separate survey by Onspring further illuminates the challenges organizations face in deriving tangible value from AI in Governance, Risk, and Compliance (GRC) operations. The "2026 GRC Benchmark Study," which surveyed 126 GRC practitioners across North America in IT, risk and compliance, finance, operations, and legal roles, indicates that while AI adoption in GRC is high, the realization of return on investment (ROI) remains a significant hurdle.

According to the Onspring survey, a substantial 85% of companies have adopted AI in some capacity within their GRC functions. However, the majority of these adopters, 44%, are still in the experimental phase, meaning the technology has not yet been deeply integrated into core workflows. Only about 14% of companies have successfully embedded AI across their GRC workflows, suggesting a slow and cautious approach to full-scale implementation.

Despite this widespread adoption, the path to demonstrable ROI is proving to be a significant point of hesitation. The study found that 44% of respondents have not yet seen a return on investment from AI in their GRC programs. Even more telling, less than a fifth (17%) reported seeing demonstrable ROI from their AI investments in GRC. This stark contrast between high adoption rates and low ROI realization suggests that organizations may be investing in AI for GRC without a clear strategy for measuring its impact or a well-defined plan for leveraging its full capabilities.

Only 26% of Companies Say Governance Frameworks Are Fully Aligned With AI Adoption

Key Concerns Hindering AI Integration in GRC

The Onspring survey also identified specific concerns that are slowing the progression towards full AI integration in GRC. Chief among these are data privacy and accuracy, cited by 29% of respondents, and the phenomenon of AI hallucinations, identified by 25%. These concerns directly echo the risks highlighted by the Smarsh and FTI Consulting report, underscoring a consistent set of challenges across the AI implementation spectrum.

The interconnectedness of these concerns is critical. For AI to be effectively utilized in GRC, it must operate on accurate and secure data. When AI models generate inaccurate information or when the data they process is compromised or violates privacy regulations, the entire GRC framework is undermined. The fear of data breaches, non-compliance with regulations like GDPR or CCPA, and the potential for AI-generated misinformation to lead to incorrect risk assessments or compliance decisions are significant deterrents to broader adoption.

The Timeline of AI Adoption and Governance Challenges

The current situation reflects a broader trend in technological adoption. Historically, new technologies often outpace the development of regulatory frameworks and governance best practices. AI, with its rapid evolution and broad applicability, represents a particularly acute example of this phenomenon.

  • Early 2020s: The proliferation of generative AI tools and increased accessibility of AI technologies for businesses. This period saw a surge in experimentation and initial deployments across various industries.
  • Mid-2020s (Present): As organizations move beyond initial experimentation, the limitations of existing governance structures become apparent. Surveys like those from Smarsh/FTI Consulting and Onspring emerge, quantifying the gap between AI adoption and effective governance. Concerns around data privacy, accuracy, and ethical implications rise.
  • Late 2020s and Beyond (Projected): A critical period where organizations will need to mature their AI governance strategies. This will likely involve increased regulatory scrutiny, the development of industry-specific AI standards, and a greater emphasis on building AI ethics and responsible AI frameworks. Organizations that fail to adapt risk significant legal, financial, and reputational consequences.

Broader Implications and the Path Forward

The findings from both surveys have significant implications for businesses, regulators, and the broader technological ecosystem.

For Businesses:
The primary takeaway for organizations is the urgent need to move beyond simply adopting AI and to actively develop and implement comprehensive governance frameworks. This includes:

  • Establishing Clear Policies: Defining acceptable use of AI, data handling protocols, and ethical guidelines.
  • Investing in Training: Ensuring employees understand the capabilities and limitations of AI tools, as well as the associated risks.
  • Implementing Robust Monitoring: Continuously monitoring AI usage, outputs, and potential impacts on data privacy and security.
  • Developing Risk Assessment Frameworks: Creating specific processes for identifying, assessing, and mitigating AI-related risks.
  • Focusing on ROI Measurement: Clearly defining metrics for AI success in GRC and other operational areas to ensure investments are yielding tangible benefits.

For Regulators:
The ongoing governance gap presents a clear mandate for regulators to develop and adapt existing regulations to address the unique challenges posed by AI. This might involve:

  • Issuing AI-Specific Guidance: Providing clarity on how existing data privacy, security, and financial regulations apply to AI deployments.
  • Developing New Standards: Exploring the creation of AI-specific regulatory frameworks and compliance requirements, particularly in high-risk sectors.
  • Promoting Best Practices: Encouraging the adoption of responsible AI principles and frameworks through incentives or collaborative initiatives.

For the Technology Sector:
AI developers and providers have a role to play in supporting responsible AI adoption. This could involve:

  • Building Security and Privacy by Design: Integrating robust security and privacy features into AI platforms from the outset.
  • Enhancing Transparency and Explainability: Developing AI models that are more transparent and whose decision-making processes can be understood and audited.
  • Providing Governance Tools: Offering integrated tools and solutions that help organizations manage AI governance effectively.

The consistent findings from these independent surveys underscore a critical juncture in the evolution of AI adoption. While the potential benefits of AI are vast, organizations must prioritize the establishment of strong governance structures to mitigate risks, ensure compliance, and ultimately unlock the full, responsible value of this transformative technology. The "yet" in the Onspring survey’s ROI finding is a crucial qualifier, suggesting that with the right strategic approach and governance, the expected returns may still be attainable. However, without addressing the fundamental governance deficits, the pursuit of AI adoption could lead to unforeseen liabilities and hinder the very progress it aims to achieve. The call to action is clear: organizations must bridge the gap between AI innovation and AI governance before the risks outweigh the rewards.

By