An unflinching look at the gap between AI deployment and AI governance. The numbers are sober. The sources are public.
of organisations deploy AI without comprehensive governance[2026]
Adoption races ahead. Governance crawls behind. The gap between them is the exposure.
Organisations using AI in at least one business function
Near-universal adoption, yet the governance infrastructure lags a decade behind.[2026]
With comprehensive AI governance
Only 8% of organisations maintain a framework that covers policy, process, and technical controls.[2026]
Of production agents run unmonitored
Mean monitoring coverage for deployed AI agents is just 52% — nearly half operate without oversight.[2026]
Employees using shadow AI
Four in five workers use AI tools their employer has not sanctioned, creating an invisible governance surface.[2026]
Recorded AI incidents in 2025
Up 55% year-over-year from 233. Each incident is a data point in the cost of the governance gap.[2025]
Of breached orgs lacked access controls
Among organisations that experienced an AI-related security breach, almost all had no proper access controls at the time.[2026]
The shift from AI tools to autonomous agents compounds every governance deficit. Agents act, decide, transact — and almost nobody is watching.
AI agent market size (2025)
Projected to reach $52–295B by the early 2030s, depending on scope.[2025]
Plan agentic AI within 2 years
Nearly three-quarters of organisations intend to deploy autonomous agents — but only 21% have governance for them.[2026]
Cannot terminate a misbehaving agent
Most organisations lack the technical capability to enforce purpose limits or shut down a rogue agent.[2026]
Have mature agent governance
Fewer than one in four have the frameworks, tools, and accountability to oversee autonomous systems.[2026]
Where do organisations actually stand? The gap between policy and practice is vast.
The drop from 89% to 8% is the governance gap in one chart.
Regulation is accelerating. The question is whether governance can catch up before enforcement arrives.
Fines up to €35 million or 7% of global turnover for prohibited AI practices. High-risk system obligations now enforceable.[2026]
U.S. state AI legislation more than doubled from 49 in 2023 to 131, with federal agencies issuing 59 AI regulations.[2025]
The OECD AI Policy Observatory monitors over 900 AI policies across 80+ jurisdictions — and growing.[2025]
The AI economy is not ungoverned because nobody cares. It is ungoverned because governance infrastructure has not kept pace with deployment velocity. Policies exist on paper; enforcement exists in law; but the operational layer — the tooling, the monitoring, the kill-switch that actually works — is missing from the majority of deployments.
The result is an exposure gap measured in billions of dollars and hundreds of incidents per year, widening with every autonomous agent that ships without an audit trail, a purpose limitation, or a revocation mechanism.
Governance is not a cost centre. Organisations with strong AI governance are three times more likely to report meaningful financial returns.[2026]
The Sovereign Intelligence Hub publishes weekly intelligence on AI governance, digital sovereignty, and the agent economy. No hype. Sourced. Free to start.