Businesses Sidestep AI Governance Policies as Concerns Mount
CIO Dive, Wednesday, September 16th, 2026
One in four agentic AI users has no defined accountability for post-deployment monitoring, an EY report finds.
Senior AI leaders surveyed by EY say governance frameworks have not been updated for the technology's specific risks, and organizations keep bypassing the protocols they do have despite well-documented security incidents.
Among respondents using agentic AI, around one in four said accountability for maintaining or monitoring it after deployment was undefined.
The recommended approach is embedding governance into the AI development and deployment lifecycle with clear requirements for testing, approval, monitoring and escalation, plus an explicit exception process naming who can authorize an expedited deployment and what additional controls or post-deployment reviews apply.