While AI capabilities continue to race ahead, businesses are still catching up on governance. New data suggests most organisations have moved into a middle state, where a policy exists on paper but is never actually applied in practice. At the same time, new EU rules requiring businesses to disclose when people are dealing with AI came into force this month.
Here is an overview of the current situation around AI governance and the 10 foundations to protect your organisation.
IBM's 2026 Cost of a Data Breach Report, released on 29th July, surveyed organisations that had suffered a data breach and found that 68% of them had no AI governance policy in place to manage AI use or catch unapproved use. That is up from 63% the year before.
Broken down:
35% had no policy at all.
33% had one still in development.
Only 32% had a policy actually in place and working, down from 37% the year before
Source: IBM Cost of a Data Breach Report, 2026
The report tracked six types of AI governance control across both years, and five of them are now used less than before. Approval processes for new AI deployments, the most common control, dropped from 45% of organisations to 38%. Regular audits to catch unapproved AI use fell from 34% to 29%. A sixth control, coordination between governance and security teams, was measured for the first time this year, and only 19% of organisations said it was happening.
A policy that only exists on a slide is not governance, and the data shows more organisations drifting into that state, not fewer.
The timing sharpens the point. New EU rules under Article 50 of the AI Act now require any business whose AI system talks to people directly, a chatbot, a voice agent, an AI-generated video, to tell them they are dealing with AI. Those rules took effect on 2nd August 2026. If your business deals with EU customers, you should check your chatbot is compliant now.
The organisations without governance are not just exposed in principle. They are paying for it. Security incidents involving shadow AI, meaning staff using AI tools the business never approved, climbed to 43% of breached organisations this year, up from 20%. Breaches involving shadow AI averaged £4.3 million this year, up from £3.7 million the year before. Within those incidents, close to half caused data loss, over four in ten disrupted operations, and roughly one in five resulted in a regulatory fine. Each of those three outcomes traces back to a specific gap in the ten foundations listed later in this article.
That pattern matches what we see in practice when businesses assess new AI tools. Most default to saying no to a new tool and revisiting it in six months. In practice, that six-month wait is what pushes people to use the tool anyway, quietly, on their own devices, where nobody can see what data goes in.
The safer default is a quick assessment that checks how the tool handles data, whether it puts IP or data ownership at risk, how reliable the provider is, and how it fits with the rest of the stack. That way, a decision comes back in days rather than months, and people are not left waiting long enough to go around it.
The businesses losing the most to shadow AI are not the ones saying yes too often. They are the ones taking too long to say anything at all.
The governance gap is not just a staff problem. A survey of over 100 US public company directors, published by the Diligent Institute in June, found that 82% had used generative AI in their own board work in the past six months, up from 66% the previous September. Yet 54% said their company had no guidance for how directors should use AI, and only 6% reported a formal board level policy.
Close to a third of directors had used AI to summarise board papers, among the most sensitive documents any company produces. Nearly half knew of a fellow director using a consumer AI tool for board work rather than one the company had vetted.
The people setting AI policy are often the ones operating without one. A governance framework that is ignored by the people in charge will most likely be ignored by the people using AI day to day too. It is the clearest evidence yet that the ten foundations below need a named owner in leadership and not just a document that sits underneath one.
Every failure described above traces back to one of these ten elements being missed. Where a genuine AI policy exists, it tends to cover the same ground regardless of sector or size.
In our own work with leadership teams, we find that these 10 elements are the most important:
Which systems are in scope, including the AI features already built into everyday tools like the CRM or the accounting platform, not just standalone chatbots, this is where most shadow AI hides in plain sight
When and how AI use needs to be disclosed, both internally and to customers, so nobody finds out after the fact that AI made the decision
A named human responsible for every AI-driven output or decision, so accountability never defaults to "the AI did it", this is the difference between a regulator seeing a controlled incident and one of the one-in-five breaches that ends in a fine
Clear rules on what data can and cannot go into a tool, with training data treated as an absolute no, since data that goes in cannot be pulled back out
A structured, fast process for assessing new tools, rather than an indefinite hold, waiting six months to approve a tool is what pushes people toward it anyway, which is the direct mechanism behind the jump from 20% to 43% shadow AI adoption
A genuinely safe route for reporting when something goes wrong, so problems surface early rather than a regulator finding them first, punishing people for reporting is what drives incidents underground, and close to half of shadow AI incidents end in data loss precisely because nobody flagged the problem early enough to contain it
Sign-off on what is and is not appropriate use, even down to things like an AI avatar sitting in for someone on a call, so nobody has to guess where the line sits
Treating the policy as a living document that gets revisited monthly, not an annual exercise, because the tools change faster than a yearly review can track
Deliberately communicating every update, because a policy nobody knows changed might as well not have changed
Structured feedback from the people using the tools day to day, so the policy stays usable rather than becoming a document nobody reads
This can read like an enterprise-scale governance function, something only a business with a compliance team could run. It could not be further from the truth. The same 10 elements should be adopted within a 50-person business. Every business needs this, no matter their scale.
Just remember that none of this requires a perfect first draft. The businesses that get ahead are the ones that get something basic written down now and refine it, rather than waiting for a version they consider finished.
The organisations bringing this under control share a pattern. Governance sits with a named owner, not a shared inbox. Approval decisions come back in days. Updates get communicated loudly rather than buried in a document nobody reads. And the policy is treated as infrastructure for confident AI adoption.
That last point matters most, since the goal was never to slow AI use down to protect the business from itself. An organisation that throttles adoption to stay safe has simply chosen to fall behind instead of getting caught out. The goal is deep, confident use of AI at a level of risk the business has actually chosen, not one it backed into by accident.
If your business needs a clear picture of what AI tools are already in use, where the risks sit, and a policy that actually works, our AI Governance and Compliance Advisory service is built for exactly that.