Businesses are taking AI governance seriously, but their plans lag behind the technology they’re using, according to an EY survey.
Dive Brief:
- Businesses are developing AI strategies, but those plans don’t accurately reflect their use of agentic AI, leaving serious cybersecurity gaps, according toan EY report released on Tuesday.
- Many respondents to EY’s survey said they weren’t sure they could detect an unauthorized AI agent in their enterprise.
- The consulting firm also noted that having plans didn’t mean organizations were ready to confront security challenges: “Formal governance and operational effectiveness are not the same thing.”
Dive Insight:
The EY report contains a smattering of encouraging findings about how seriously businesses are takingAI governance. Nearly three-quarters of firms require humans in the loop for important decisions, for example, and 71% require all employees to take AI risk management training. Roughly two-thirds require their vendors to report on their use of AI models, 58% use external AI risk-managementframeworks from organizations such as the National Institute of Standards and Technologyand 58% inventory all the models they use, including those embedded in third-party tools.
But those promising statistics conceal deeper challenges
“The question for audit committees is: What evidence demonstrates the controls are working?” the consulting firm said. “A registry that is incomplete, a policy that is bypassed under pressure, or a control that cannot detect unauthorized use in real time can all create the same practical result: governance exists, but confidence in its operational effectiveness remains limited.”
Agentic AIposes a particular challenge, the report found. Nearly six in 10 respondents at organizations using agentic AI reported a perception that no single group oversaw those agents after deployment, and nearly four in 10 said accountability foroverseeing agentsin their organizations was “undefined.”
Roughly half of organizations said their AI governance frameworks have not been updated to incorporaterisks specific to agentic AI, four in 10 said they lacked visibility into all the AI tools on their networks and roughly one-quarter of respondents said their organization “cannot detect unauthorized AI agents operating internally.”
EY said its findings “leave important questions about whether [organizations’] controls provide complete coverage.”
“Governance designed for AI outputs may not be sufficient for AI actions,” analysts wrote, “particularly when systems can operate across business processes, interact with data, call tools or execute tasks without real-time human involvement.”
The report suggested organizations rethinktheir governance mechanismsentirely. “As agentic AI moves deeper into critical workflows, assurance will need to focus less on whether a control has been designed and more on whether it can identify and interrupt autonomous activity before it becomes a material failure, and explain and evidence it afterwards.”
AI-related risks have long since moved from theoretical to practical. EY found that nearly nine in 10 organizations have experiencedproblems related to AIover the past year. More than one-third of survey respondents have “experienced an AI incident or failure that caused a materially negative impact, including data loss, financial damage, operational disruption and brand damage,” the consulting firm said.
AI visibility gapsincrease the likelihood that a simple breach will cascade into something worse, according to the report. “A high-profile AI failure can quickly become a reputational event, especially when the organization cannot explain how a decision was made, which control failed or who was accountable.”
EY surveyed 202 senior AI decision-makers at publicly traded U.S. companies with at least $1 billion in annual revenue between May 28 and June 15.
Filed Under:Strategy,Threats,Leadership & Careers
