Fewer than one in three organizations have reached operational maturity in AI governance, even as nearly half already run autonomous AI agents in production, according to Schellman’s 2026 State of AI Governance report, “Bridging the Gap Between AI Governance Confidence and AI Governance Maturity.”
Operational maturity versus confidence: the readiness gap
Schellman’s research paints a study in contrast. While 57 percent of respondents maintain a formal AI governance policy, operational readiness lags: fewer than one in three organizations have achieved maturity. Documentation and procedures are inconsistent — only 44 percent have documented AI-specific incident response procedures, and 28 percent of organizations that maintain a formal acceptable‑use policy still handle violations informally on a case‑by‑case basis. The report argues these gaps turn governance into a paper exercise rather than a repeatable capability that produces demonstrable controls and evidence.
Autonomous AI agents in production and the missing controls
Adoption of autonomous agents is widespread: 46 percent of surveyed organizations already have AI agents in production and 86 percent have tested or piloted them. Yet the governance around agents is inconsistent. Only 52 percent of organizations with agents in testing or production have defined human oversight and escalation requirements, and 54 percent have assigned clear roles and accountability for agent decisions. Schellman emphasizes that when AI moves from generating answers to taking actions, governance must resolve new questions: what an agent may do independently, which actions need approval, how people can intervene or reverse actions, and whether the organization can demonstrate what happened after the fact.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAccountability concentrated at the top, but expertise not routed up
Responsibility for AI is often concentrated in IT. Forty‑two percent of respondents say the CIO or head of IT is primarily responsible for AI purchasing decisions, and 37 percent say the CIO is ultimately accountable when AI creates risk. At the same time, only 54 percent regularly report AI governance to their boards or equivalent executive leadership. Schellman warns that concentrating responsibility without cross‑functional input risks creating a single point of failure: legal, compliance, procurement, security, data teams, and business units all intersect with AI risk, and mature governance should route that expertise up to a single accountable executive through controls and governance functions.
Third‑party AI, standards, and the policy environment
Nearly every enterprise relies on software and services that contain embedded AI, yet boards are not consistently discussing that exposure: only 36 percent of boards regularly discuss third‑party or vendor AI risk. Confidence in governing embedded third‑party AI is far from universal — 69 percent of respondents say they are confident in their ability to govern AI embedded in third‑party tools. Schellman’s report highlights emerging frameworks and standards that organizations can use while policy debates continue: NIST’s AI risk management work, ISO/IEC 42001 as a certifiable standard for AI management systems, and AIUC‑1 as a certification aimed specifically at governing AI agents. The report also cites a policy moment in January when White House Office of Science and Technology Director Michael Kratsios urged Congress to work toward a federal AI standard while pushing back against global AI governance. Schellman’s authors caution organizations not to outsource governance in the hope that external clarity will arrive first; internal, adaptable controls are necessary as regulatory expectations evolve.
What this means for technologists, procurement leaders, and boards
- Technologists and security teams: Expect to be asked to make governance operational. Only 44 percent of organizations have documented AI incident response procedures, and firms with mature governance are demonstrably more likely to deploy agents (78 percent versus 22 percent for those with developing governance), suggesting that robust, testable controls correlate with safer scaling.
- Procurement leaders and vendor managers: Third‑party risk requires greater attention. Just 69 percent of respondents feel confident governing embedded vendor AI, yet nearly every enterprise relies on products with embedded AI; only 36 percent of boards regularly discuss vendor AI risk.
- Boards and executive leadership: Visibility is uneven. Only 54 percent of organizations regularly report AI governance to boards or equivalent leadership, even as governance certifications and independent assessments become more important in customer due diligence and vendor evaluation.
The takeaway is concrete: governance matters not just for compliance but as a business capability that enables responsible use. Schellman’s report finds that organizations with mature governance are more than three times as likely to have agents in production, and many respondents link effective governance to improved internal efficiency (57 percent), easier scaling and innovation (43 percent), and better readiness for new regulations (49 percent). Closing the readiness gap will require turning policies into demonstrable controls, formalizing incident response, assigning clear oversight for autonomous actions, and bringing third‑party AI under the same scrutiny as in‑house systems.
The report’s co‑author, Joe Sigman, is a Manager with Schellman based in Denver, Colorado, who has led and supported AI Assessments and related work that informs these findings. For organizations that still treat governance as a checklist, Schellman offers a blunt choice: maintain confidence on paper, or build the operational systems that will prove governance works as AI becomes more autonomous and regulations continue to evolve.




