Thought Leadership Report

August 2026

Where does your organization actually grade on AI governance?

88% of organizations use AI in at least one business function. Only 8% can prove, with evidence, that they govern it. The DSALTA AI Governance Maturity Model is a five-stage benchmark, from Unmanaged through Audit-Ready, for locating exactly where your organization sits before an auditor, insurer, or regulator does it for you.

88%

of organizations use AI in at least one business function

8%

maintain a comprehensive AI governance framework

18%

maintain a current, complete AI system inventory

66%

of boards have limited-to-no working knowledge of AI

The Adoption-Governance Gap

The eleven-to-one ratio behind every AI governance headline.

The eleven-to-one ratio behind every AI governance headline.

Every enterprise AI survey published in the past eighteen months tells some version of the same story: adoption has outrun oversight. What most of them don't say outright is why the gap persists despite record spending and sophisticated existing risk functions.

What the numbers actually show:

18% of enterprises maintain a current, complete inventory of their AI systems, across a global sample of 2,000 senior executives spanning 33 geographies and 19 industries.

70% of executives say business teams are deploying AI faster than IT can track it. That's the operational definition of shadow AI.

Enterprises are projected to run an average of 1,600 AI agents by the end of 2026, yet just 12% have a centralized platform to manage that sprawl.

Only half of U.S. business leaders surveyed by PwC had even attempted to inventory their AI use cases. That's the most basic prerequisite for governance, not an advanced one.

Not a resource problem

The organizations behind these numbers aren't small companies without compliance budget. They include Fortune 500s, federal agencies, and enterprises with mature SOC 2, HIPAA, and GDPR programs already running. The gap persists despite resources, which points to structure, not funding: a clear, singular owner per AI system, with the standing and mandate to act on what an inventory reveals.

A sequencing problem, too

An inventory built once, for one audit cycle, decays within weeks in an environment averaging 1,600 AI agents per enterprise and adding more continuously. That's why "Inventoried" is a distinct, unstable stage in the maturity model below, not a finish line.

The DSALTA AI Governance Maturity Model

Five stages, graded F through A.

Five stages, graded F through A.

DSALTA's model reconciles inventory, accountability, and board-oversight data from the surveys above into one curve, mapped against the control requirements auditors apply under SOC 2, ISO/IEC 42001, and the EU AI Act. Click a step to see what defines it.

F

1. Unmanaged

D

2. Inventoried

C

3. Accountable

B

4. Integrated

A

5. Audit-ready

A

5. Audit-Ready

Estimated share of organizations: 5-8%

Primary risk

Minimal. This is the exception state.

What "good" looks like

Conformity documentation, audit trails, and named accountability survive an unannounced review.

F

1. Unmanaged

D

2. Inventoried

C

3. Accountable

B

4. Integrated

A

5. Audit-ready

A

5. Audit-Ready

Estimated share of organizations: 5-8%

Primary risk

Minimal. This is the exception state.

What "good" looks like

Conformity documentation, audit trails, and named accountability survive an unannounced review.

Grade

Grade

Grade

Stage

Stage

Est. share

Est. share

Primary risk

Primary risk

Primary risk

What "good" looks like

What "good" looks like

What "good" looks like

F

F

1 ·
Unmanaged

~30-40%

1 ·
Unmanaged

~30-40%

Shadow AI; no visibility into what's deployed.

N/A: nothing to govern because nothing is tracked.

D

D

2 ·
Inventoried

~35-40%

2 ·
Inventoried

~35-40%

Visibility without ownership or control.

A living registry of models/agents, not a point-in-time spreadsheet.

C

C

3 ·
Accountable

~15-20%

3 ·
Accountable

~15-20%

Liability assigned (CIO/CTO) without matching authority or budget.

Named owner per system, with budget and enforcement authority.

B

B

4 ·
Integrated

~8-10%

4 ·
Integrated

~8-10%

Governance exists but stays operational; board treats it as an IT issue.

AI on the standing board risk agenda, tied to the existing risk calendar.

A

A

5 ·
Audit-Ready

~5-8%

5 ·
Audit-Ready

~5-8%

Minimal: the exception state.

Conformity documentation, audit trails, and named accountability survive an unannounced review.

Key Finding

None of the four frameworks is optional for a company selling into regulated markets or handling EU users' data through an AI system. For teams already running SOC 2 or ISO 27001, most of the underlying muscle, including control mapping, evidence collection, named ownership, and audit trails, already exists. The gap is rarely a from-scratch build; it's an extension of infrastructure already paid for once.

The Accountability Paradox

Who should actually own AI governance?

Who should actually own AI governance?

Two-thirds of CIOs and CTOs are now held accountable for AI systems they do not fully control. They carry the liability without the authority to unilaterally fix what they're liable for. Authority and visibility move in opposite directions as you go up the org chart.

The closed loop:

A COO discovers a governance gap in day-to-day operations. A CFO never funds it, because the business case never reaches them. A CIO, nominally accountable, has no structural reason to escalate a problem that was never within their control to begin with. The result: 56% of executives say first-line technology teams are the ones actually leading responsible-AI efforts, meaning governance is being driven bottom-up rather than set top-down.

Thirty percent of public-sector Chief Data Officers have simply absorbed the Chief AI Officer role into their existing job rather than see it created and staffed separately. It's a pragmatic response to resource constraints, but also a signal that dedicated AI governance leadership remains the exception, not the rule.

66%

of CIOs/CTOs accountable for AI they don't fully control.

56%

say first-line tech teams lead responsible-AI efforts.

66%

of boards have limited-to-no working knowledge of AI.

31%

of organizations don't put AI on the board agenda at all.

The right answer, per the data

A named individual with both visibility into deployed systems and budget authority to act on findings, not split between a CIO who's accountable but lacks control and a board that has authority but lacks visibility. Policy documents don't close that gap, because policy was never the missing piece. Structural authority is.

The Regulatory Horizon

EU AI Act vs. NIST AI RMF vs. ISO/IEC 42001 vs. SOC 2

EU AI Act vs. NIST AI RMF vs. ISO/IEC 42001 vs. SOC 2

The EU AI Act's phased enforcement is underway. In the U.S., state statutes in Colorado and California are setting precedent in the continued absence of a federal AI law. Four frameworks now do most of the practical work, and each opens with a different first question.

The EU AI Act's phased enforcement is underway. In the U.S., state statutes in Colorado and California are setting precedent in the continued absence of a federal AI law. Four frameworks now do most of the practical work, and each opens with a different first question.

Framework

Framework

Framework

What it actually asks first

What it actually asks first

What it actually asks first

Why it matters now

Why it matters now

Why it matters now

EU AI Act

Which risk tier does each system fall into, and where is the conformity documentation?

Risk classification + conformity assessment; phased enforcement is already underway.

NIST AI RMF

Can you show govern / map / measure / manage controls for this system?

Voluntary, but increasingly the reference model auditors cite.

ISO/IEC 42001

Is there a certifiable AI management system in place?

The first international AI management-system standard.

SOC 2

Does the AI system fall inside your existing control boundary?

Auditors now probing AI as an adjacent control domain during renewals.

35.7%

of managers describe themselves as adequately prepared for EU AI Act compliance.

19.4%

describe themselves as poorly prepared.

63%

of AI-breached organizations had no governance policy in place at the time.

Key Finding

None of the four frameworks is optional for a company selling into regulated markets or handling EU users' data through an AI system. For teams already running SOC 2 or ISO 27001, most of the underlying muscle, including control mapping, evidence collection, named ownership, and audit trails, already exists. The gap is rarely a from-scratch build; it's an extension of infrastructure already paid for once.

Four Predictions for 2027

Where the pressure pushes next?

Where the pressure pushes next?

Each prediction shares a mechanism: external pressure from regulators, insurers, and auditors forces the structural change internal governance advocates couldn't force on their own.

01

01

Board-level AI oversight committees become standard by mid-2027.

Driven by EU AI Act conformity deadlines, not voluntary governance maturity. It's the same pattern SOC 2 adoption followed a decade earlier. Today, 31% of organizations don't put AI on the board agenda at all.

02

02

The "AI inventory" becomes a discrete, auditable deliverable.

Closer to a SOC 2 asset inventory than an internal spreadsheet, once auditors start asking for it as evidence rather than a courtesy. Only 18% of enterprises maintain one today.

03

03

Insurers begin pricing premiums against AI governance maturity.

This mirrors how ransomware underwriting evolved after 2021, when insurers priced risk on MFA and backup adoption long before regulators mandated either. Named ownership and audit trails are a similarly legible signal.

04

04

2027's first EU AI Act enforcement wave exposes "governance theater".

Organizations with a policy PDF and no enforcement behind it get penalized faster than organizations with no policy at all. A written policy with no mechanism arguably shows the risk was identified and not acted on.

Getting Audit-Ready

Self-check: how audit-ready is your AI governance right now?

Self-check: how audit-ready is your AI governance right now?

Regulators, auditors, and insurers are converging on the same six-item evidence base. Check off what your organization can produce on short notice. This runs entirely in your browser, and nothing is sent or stored.

A living AI system inventory

Every model, agent, and third-party AI tool in production, updated continuously rather than compiled once for an audit.

A named owner per system

With the budget and enforcement authority to act on findings, not just the liability if something goes wrong.

Risk-tier classification

For each system, mapped explicitly to the EU AI Act's risk categories where applicable.

Conformity & control documentation

Showing the system meets the safety, transparency, and human-oversight standards claimed for its risk tier.

Audit trails

Covering who approved, who monitors, and who can explain each system's decisions on request.

A standing board reporting cadence

For AI risk, tied to the existing risk calendar rather than run as a one-off briefing.

66%

of CIOs/CTOs accountable for AI they don't fully control.

56%

say first-line tech teams lead responsible-AI efforts.

66%

of boards have limited-to-no working knowledge of AI.

31%

of organizations don't put AI on the board agenda at all.

The right answer, per the data

A named individual with both visibility into deployed systems and budget authority to act on findings, not split between a CIO who's accountable but lacks control and a board that has authority but lacks visibility. Policy documents don't close that gap, because policy was never the missing piece. Structural authority is.

FAQs

AI governance readiness, explained.

Working definitions for the terms, frameworks, and roles referenced throughout this report.

What is an AI governance maturity model?

Who should own AI governance in an organization?

What does "audit-ready" means for AI systems specifically?

Does SOC 2 cover AI systems?

What's the difference between an AI inventory and AI governance?

What is shadow AI, and why does it matter for governance?

How many AI agents does the average enterprise run?

What is the NIST AI Management Framework?

What is ISO/IEC 42001?

How is the EU AI Act enforced, and who does it apply to?

What percentage of companies have a mature AI governance framework?

Get the full report.

18 pages: the complete maturity model, the accountability paradox, the regulatory horizon, four predictions for 2027, and the six-item audit-ready evidence base, with full source citations.