top of page

AI Security Governance Is Losing to AI Adoption

2 days ago
7 min read
ai-governance-gap

By Yonatan Hoorizadeh CISSP, CISM, CRISC, AAISM

Published By: Purple Shield Security

Published: September 15, 2026 | Last updated: September 15, 2026


Seventy-four percent of organizations now run AI at the department level or wider, but only 5% have coordination and accountability defined across the AI lifecycle, according to OneTrust's 2026 AI-Ready Governance Report. Adoption is finished. Oversight has barely started. That gap is where most AI risk now sits.

What did the OneTrust 2026 report actually find?


OneTrust's 2026 AI-Ready Governance Report, covered by Help Net Security on September 15, 2026, found that 74% of respondents report departmental or scaled AI adoption. That means AI is running inside individual teams, across business functions, or embedded in operating processes. Only 1% report no AI use at all. Everyone else is planning, evaluating, or experimenting.


Agent use is further ahead than most governance programs. According to the report, 87% of respondents say their organizations encourage the use of AI agents, software that takes actions on a person's behalf rather than just answering questions. Of those, 47% encourage agent use with defined governance, oversight, and controls in place. The other 40% encourage it while controls are still being built.

The consequences are already showing up. Nearly half of respondents reported at least one incident during the past year in which AI systems or agents took unapproved actions. Only 17% of organizations place themselves at the highest maturity level, where governance is embedded by design.


Blake Brannon, Chief Innovation Officer at OneTrust, framed the underlying problem in the report's commentary: “Static rules worked for governance when a person made every decision.” That is the shift. A policy written for human approval steps does not hold up when software is making the calls.


Spending is following the pressure. Eighty percent of respondents say their function spends more time managing AI-related risk than it did 12 months ago, and 98% plan to increase budgets for technologies used to govern AI during the next financial year.


Why 5% is the number that should worry you, not 74%


Only 5% of respondents say coordination and accountability are defined across the AI lifecycle, according to the OneTrust report. That is the finding that should change a leadership conversation. Most companies already run governance activities: risk classification, impact assessments, usage controls, policy documentation. What they cannot produce is a single clear answer to who decides, who approves, and who carries the consequence when an AI system does something unexpected.

Two other numbers in the report explain how companies got here. Thirty-three percent said employees used unapproved AI tools because approved options or processes were not available quickly enough. And 96% said at least one AI initiative was slowed, paused, or complicated by governance, risk, or review requirements.


Read those together and the picture is uncomfortable. Companies are already paying the full cost of governance friction, with 96% reporting delays, while only 5% collect the benefit of clear accountability. That is the worst position available: slow enough to frustrate the business, loose enough that nobody owns the outcome.

Shadow AI is usually treated as a discipline problem. The data suggests it is a procurement speed problem. When a marketing manager waits three weeks for a decision on a $20 per month tool, the tool gets bought on a personal card and the company finds out during an audit. Fixing approval latency removes more risk than another policy document, and it is the cheapest piece of AI security governance a mid-market firm can put in place.


How do AI agents change who is accountable?


An AI agent acts under a credential, and that credential belongs to a person or a service account. When an agent sends an email, moves a file, updates a record, or approves a transaction, the audit log shows that identity, not the agent. So the gap between 87% of companies encouraging agent use and 47% having defined controls is really a gap in who answers for the actions taken.


The OneTrust report ranks data integrity as a top risk in incident preparedness. Respondents are most likely to experience, and least prepared to manage, data loss, corruption, or misclassification. Unvetted automation and agentic actions come next.


Both risks share a root cause. An agent inherits whatever access its credential carries, and most credentials were scoped for a human who exercises judgment about which records to touch. Software does not exercise that judgment. It does what it was asked to do, at the speed and volume of software, against every record the credential can reach.


What does this look like at a 40 to 200 person company?


The OneTrust data comes from organizations large enough to have governance functions and dedicated risk teams. At a 40 to 200 person firm there is no AI committee, no model risk group, and often no full-time CISO. The work still has to happen, but it compresses into three decisions rather than a program.

First, inventory before policy. You cannot govern tools you cannot name. The identity provider's application list, two months of card statements, and the browser extension inventory will surface most of what is actually in use.

Second, approval speed over approval rigor. A two business day lane for low risk tools prevents more shadow AI than a twenty page standard nobody finishes reading.


Third, one named owner per approved tool and per agent that holds a credential. Not a committee. A person whose name sits next to the thing, who can be asked what it does and what it can reach.


This is the work that vCISO services and fractional CISO services are built to absorb. Someone senior enough to make the approval call and defend it to a client or an auditor, at a cost that makes sense for a company that cannot justify a full-time security executive. At Purple Shield Security, this is how we build AI governance for firms in healthcare, legal, and financial services, where the compliance obligations usually arrive before the AI budget does.


Sector changes the first move. If you are a HIPAA-covered entity and any AI tool touches protected health information, the business associate agreement question comes before the security question. If you are a law firm, client confidentiality terms and outside counsel guidelines often already restrict sending client material to third-party processors, and those terms predate AI. If you are preparing for a SOC 2 audit, your vendor inventory and change management process already cover most of what the auditor will ask about AI.


What to do in the next 30 days

None of this requires a new program. The fastest path for a mid-market firm is to attach AI to the controls that already exist, then close the two gaps that create the most exposure: unknown tools and unowned credentials. Five concrete steps, in order:

  1. Pull the application list from your identity provider (Microsoft Entra ID, Okta, or Google Workspace) and flag anything with an AI feature. Cross-check it against the last two months of card statements for subscriptions under $50 per month, which is where unapproved tools usually hide.

  2. List every AI agent, assistant, or automation that holds a credential. Next to each, write the owner's name and what the credential can reach. If nobody can name an owner, disable the credential and wait to see who calls.

  3. Re-scope those credentials the way you would scope a service account. Read-only where read-only will do, and no standing access to systems the agent only needs occasionally.

  4. Put the approval lane in writing with a deadline attached. Request in, answer within two business days, and a documented reason on any denial. The deadline is the control, not the form.

  5. Add two questions to every vendor review: does this product send our data to a model provider, and is our data used for training. Get the answer in writing and file it with the contract.


Firms that already buy compliance services for SOC 2, HIPAA, or CMMC work should fold AI into those programs rather than starting a parallel one. The NIST AI Risk Management Framework and ISO/IEC 42001 are useful reference points, but neither is a prerequisite for the five steps above.


One more item belongs on the list, and it is the one leadership tends to postpone. Decide now how you answer the AI questions on client security questionnaires and insurance renewal forms. An accurate yes with named controls is a far better position than a no that a later audit contradicts.


Frequently asked questions


Do we need an AI policy if we only use ChatGPT and Microsoft Copilot?

Yes, though it can fit on one page. The controls that matter are which data types may go into a prompt, which account is used (the company tenant, never a personal login), and whether output gets human review before it reaches a client, a regulator, or a contract. A short standard naming approved tools and prohibited data does more than a long policy nobody finishes. If you handle protected health information, settle the business associate agreement question before anything else.


Who should own AI governance if we do not have a CISO?

One named executive, not a committee. In most mid-market firms it lands with the COO, the general counsel, or whoever already owns vendor risk, with technical input from IT. The OneTrust report found only 5% of organizations have coordination and accountability defined across the AI lifecycle, and diffuse committee ownership is a common reason. A fractional CISO can hold the decision rights and the documentation burden without a full-time hire.


Does employee AI use affect our SOC 2 or HIPAA obligations?

Usually yes, through paths you already maintain. An AI vendor that processes customer data is a subprocessor question for SOC 2 and a business associate question under HIPAA when protected health information is involved. Auditors are already asking where AI tools sit in the vendor inventory and how they entered the change management process. Adding AI to the systems you already track is faster and cheaper than building a separate program next to them.


What do we do if an AI agent already took an action nobody approved?

Treat it as a security incident, because that is what it is. Establish which identity the agent used, what that identity could reach, and what it actually did, then revoke or re-scope the credential before debating root cause. Nearly half of respondents in the OneTrust survey reported at least one such incident in the past year, so this is now routine rather than exotic. Document it the way you would document any unauthorized change, because that record is what an auditor, a client, or an insurer will ask to see.


Adoption already happened at most firms. The open question for leadership is whether anyone can say, in one sentence, who approves an AI tool and who owns the agent holding credentials to your systems. If that answer is not clear today, Purple Shield Security's AI security services cover exactly that ground: inventory, ownership, approval lanes that people actually use, and the evidence your auditors and clients will eventually ask for.



Sources

 
 
bottom of page