Almost Everyone Has AI Governance. Almost No One Is Ready.
Seventy percent of large companies have stood up an AI risk committee. Fourteen percent say they are ready to deploy AI. Both numbers come from the same Sedgwick survey of 300 Fortune 500 leaders, published this year, and the distance between them is the most important measurement in enterprise risk right now.
Read that gap carefully, because it is not a governance gap. The governance exists. The committees meet, the policies are filed, the approval gates are documented. What the executives inside that 70 percent are admitting, five out of six of them, is that none of it has made their organization ready to run AI. A policy on file is not the same as showing a control works once the model is live. The gap between the two has a name, and it is exposure.The Workforce Nobody Hired
The reason the gap is so hard to close is that most leaders cannot see how much AI is already at work inside their companies. Wall Street Journal reporting describes employees at large companies creating dozens of new AI agents a day, with one workforce having built more than ten thousand. An agent here means software that takes actions on its own, not software that only answers questions. That distinction matters, because this is no longer AI that says things. It is AI that does things, acting inside production systems with whatever access its creator happened to hold.
Speaking in Riskonnect's Risk@Work webinar series this week, Wheelhouse Advisors founder and CEO John A. Wheeler put a sharper frame on it: this is a workforce nobody hired. No one interviewed these agents. There is no record of them. No one knows what they can touch or who they answer to. When anyone in the building can create one in minutes, an organization does not have an AI strategy. It has an AI population, growing faster than anyone is tracking it.
The practitioner data confirms the population is already out of containment. ISACA's 2026 AI Pulse Poll of more than 3,400 digital trust professionals found 90 percent reporting employee AI use inside their organizations, while only 38 percent have a formal, comprehensive AI policy. Adoption is running 52 points ahead of the governance meant to contain it. The same poll located the finding that should end any remaining complacency: 56 percent of practitioners cannot say how quickly their organization could halt an AI system during a security incident, and 39 percent have no documented shutdown procedure at all. The question of who holds the kill switch has no settled answer in most organizations, because the answer is an operating model decision that no single function can make alone.Governance Sets Expectations. Management Delivers Proof.
The pattern underneath all of these numbers is the same one. Organizations funded the half of the work that produces documents and skipped the half that produces evidence. Governance sets the expectations: who is accountable, what must be true before approval, how much risk the organization will accept, when someone has to step in. Management delivers the proof: a current list of what is running, checks before go-live, monitoring after, and the ability to show on any given day that a control is working. Most programs invest in the first and assume the second follows. It does not. A document signed at approval proves intent, not performance.
The cost of that assumption is now being priced into the market. Gartner expects more than 40 percent of AI agent projects to be canceled by 2027, naming inadequate risk controls among the reasons. Those cancellations will not come from organizations that lacked policies. They will come from organizations that could not answer an auditor's basic questions: who created which agent, what can each one touch, and does the control that was approved eighteen months ago still work today.
The way out is not another policy cycle. It starts with a current inventory of the AI actually running, including what arrived through engineering rather than procurement, and a sorting discipline that matches rigor to stakes so approval takes minutes rather than weeks. It continues with proof that refreshes while models run, rather than documents that age quietly in a repository. And it ends with the question every board should now be asking its risk leaders, the one Wheeler left with the Risk@Work audience: if you froze your systems today, could you tell your board how many AI systems are acting on the company's behalf, and whose side they are on?
Seventy percent of large companies can answer with an organization chart. Fourteen percent can answer with evidence. Until those numbers converge, the gap is the job.