Thought Leadership Report
August 2026
Where does your organization actually grade on AI governance?
88% of organizations use AI in at least one business function. Only 8% can prove, with evidence, that they govern it. The DSALTA AI Governance Maturity Model is a five-stage benchmark, from Unmanaged through Audit-Ready, for locating exactly where your organization sits before an auditor, insurer, or regulator does it for you.
88%
of organizations use AI in at least one business function
8%
maintain a comprehensive AI governance framework
18%
maintain a current, complete AI system inventory
66%
of boards have limited-to-no working knowledge of AI
The Adoption-Governance Gap
Every enterprise AI survey published in the past eighteen months tells some version of the same story: adoption has outrun oversight. What most of them don't say outright is why the gap persists despite record spending and sophisticated existing risk functions.
What the numbers actually show:
18% of enterprises maintain a current, complete inventory of their AI systems, across a global sample of 2,000 senior executives spanning 33 geographies and 19 industries.
70% of executives say business teams are deploying AI faster than IT can track it. That's the operational definition of shadow AI.
Enterprises are projected to run an average of 1,600 AI agents by the end of 2026, yet just 12% have a centralized platform to manage that sprawl.
Only half of U.S. business leaders surveyed by PwC had even attempted to inventory their AI use cases. That's the most basic prerequisite for governance, not an advanced one.
Not a resource problem
The organizations behind these numbers aren't small companies without compliance budget. They include Fortune 500s, federal agencies, and enterprises with mature SOC 2, HIPAA, and GDPR programs already running. The gap persists despite resources, which points to structure, not funding: a clear, singular owner per AI system, with the standing and mandate to act on what an inventory reveals.
A sequencing problem, too
An inventory built once, for one audit cycle, decays within weeks in an environment averaging 1,600 AI agents per enterprise and adding more continuously. That's why "Inventoried" is a distinct, unstable stage in the maturity model below, not a finish line.
The DSALTA AI Governance Maturity Model
DSALTA's model reconciles inventory, accountability, and board-oversight data from the surveys above into one curve, mapped against the control requirements auditors apply under SOC 2, ISO/IEC 42001, and the EU AI Act. Click a step to see what defines it.
Shadow AI; no visibility into what's deployed.
N/A: nothing to govern because nothing is tracked.
Visibility without ownership or control.
A living registry of models/agents, not a point-in-time spreadsheet.
Liability assigned (CIO/CTO) without matching authority or budget.
Named owner per system, with budget and enforcement authority.
Governance exists but stays operational; board treats it as an IT issue.
AI on the standing board risk agenda, tied to the existing risk calendar.
Minimal: the exception state.
Conformity documentation, audit trails, and named accountability survive an unannounced review.
Key Finding
None of the four frameworks is optional for a company selling into regulated markets or handling EU users' data through an AI system. For teams already running SOC 2 or ISO 27001, most of the underlying muscle, including control mapping, evidence collection, named ownership, and audit trails, already exists. The gap is rarely a from-scratch build; it's an extension of infrastructure already paid for once.
The Accountability Paradox
Two-thirds of CIOs and CTOs are now held accountable for AI systems they do not fully control. They carry the liability without the authority to unilaterally fix what they're liable for. Authority and visibility move in opposite directions as you go up the org chart.
The closed loop:
A COO discovers a governance gap in day-to-day operations. A CFO never funds it, because the business case never reaches them. A CIO, nominally accountable, has no structural reason to escalate a problem that was never within their control to begin with. The result: 56% of executives say first-line technology teams are the ones actually leading responsible-AI efforts, meaning governance is being driven bottom-up rather than set top-down.
Thirty percent of public-sector Chief Data Officers have simply absorbed the Chief AI Officer role into their existing job rather than see it created and staffed separately. It's a pragmatic response to resource constraints, but also a signal that dedicated AI governance leadership remains the exception, not the rule.
66%
of CIOs/CTOs accountable for AI they don't fully control.
56%
say first-line tech teams lead responsible-AI efforts.
66%
of boards have limited-to-no working knowledge of AI.
31%
of organizations don't put AI on the board agenda at all.
The right answer, per the data
A named individual with both visibility into deployed systems and budget authority to act on findings, not split between a CIO who's accountable but lacks control and a board that has authority but lacks visibility. Policy documents don't close that gap, because policy was never the missing piece. Structural authority is.
The Regulatory Horizon
EU AI Act
Which risk tier does each system fall into, and where is the conformity documentation?
Risk classification + conformity assessment; phased enforcement is already underway.
NIST AI RMF
Can you show govern / map / measure / manage controls for this system?
Voluntary, but increasingly the reference model auditors cite.
ISO/IEC 42001
Is there a certifiable AI management system in place?
The first international AI management-system standard.
SOC 2
Does the AI system fall inside your existing control boundary?
Auditors now probing AI as an adjacent control domain during renewals.
35.7%
of managers describe themselves as adequately prepared for EU AI Act compliance.
19.4%
describe themselves as poorly prepared.
63%
of AI-breached organizations had no governance policy in place at the time.
Key Finding
None of the four frameworks is optional for a company selling into regulated markets or handling EU users' data through an AI system. For teams already running SOC 2 or ISO 27001, most of the underlying muscle, including control mapping, evidence collection, named ownership, and audit trails, already exists. The gap is rarely a from-scratch build; it's an extension of infrastructure already paid for once.
Four Predictions for 2027
Each prediction shares a mechanism: external pressure from regulators, insurers, and auditors forces the structural change internal governance advocates couldn't force on their own.
Board-level AI oversight committees become standard by mid-2027.
Driven by EU AI Act conformity deadlines, not voluntary governance maturity. It's the same pattern SOC 2 adoption followed a decade earlier. Today, 31% of organizations don't put AI on the board agenda at all.
The "AI inventory" becomes a discrete, auditable deliverable.
Closer to a SOC 2 asset inventory than an internal spreadsheet, once auditors start asking for it as evidence rather than a courtesy. Only 18% of enterprises maintain one today.
Insurers begin pricing premiums against AI governance maturity.
This mirrors how ransomware underwriting evolved after 2021, when insurers priced risk on MFA and backup adoption long before regulators mandated either. Named ownership and audit trails are a similarly legible signal.
2027's first EU AI Act enforcement wave exposes "governance theater".
Organizations with a policy PDF and no enforcement behind it get penalized faster than organizations with no policy at all. A written policy with no mechanism arguably shows the risk was identified and not acted on.
Getting Audit-Ready
Regulators, auditors, and insurers are converging on the same six-item evidence base. Check off what your organization can produce on short notice. This runs entirely in your browser, and nothing is sent or stored.
A living AI system inventory
Every model, agent, and third-party AI tool in production, updated continuously rather than compiled once for an audit.
A named owner per system
With the budget and enforcement authority to act on findings, not just the liability if something goes wrong.
Risk-tier classification
For each system, mapped explicitly to the EU AI Act's risk categories where applicable.
Conformity & control documentation
Showing the system meets the safety, transparency, and human-oversight standards claimed for its risk tier.
Audit trails
Covering who approved, who monitors, and who can explain each system's decisions on request.
A standing board reporting cadence
For AI risk, tied to the existing risk calendar rather than run as a one-off briefing.
66%
of CIOs/CTOs accountable for AI they don't fully control.
56%
say first-line tech teams lead responsible-AI efforts.
66%
of boards have limited-to-no working knowledge of AI.
31%
of organizations don't put AI on the board agenda at all.
The right answer, per the data
A named individual with both visibility into deployed systems and budget authority to act on findings, not split between a CIO who's accountable but lacks control and a board that has authority but lacks visibility. Policy documents don't close that gap, because policy was never the missing piece. Structural authority is.
FAQs
AI governance readiness, explained.
Working definitions for the terms, frameworks, and roles referenced throughout this report.
What is an AI governance maturity model?
Who should own AI governance in an organization?
What does "audit-ready" means for AI systems specifically?
Does SOC 2 cover AI systems?
What's the difference between an AI inventory and AI governance?
What is shadow AI, and why does it matter for governance?
How many AI agents does the average enterprise run?
What is the NIST AI Management Framework?
What is ISO/IEC 42001?
How is the EU AI Act enforced, and who does it apply to?
What percentage of companies have a mature AI governance framework?
Get the full report.
18 pages: the complete maturity model, the accountability paradox, the regulatory horizon, four predictions for 2027, and the six-item audit-ready evidence base, with full source citations.