AI adoption inside most organizations is no longer in question — employees are using it constantly, sanctioned or not. What's missing is the governance layer that's supposed to keep pace. Three separate research efforts published in 2026 landed on the same conclusion from three different angles: adoption is running well ahead of any formal program to track, approve, or oversee it. For anyone studying toward the AAISM certification, this gap is the day-one governance failure mode that Domain 1 material is built around.

The Gap, By the Numbers

ISACA's 2026 AI Pulse Poll, which surveyed roughly 3,400 digital trust professionals across audit, governance, cybersecurity, privacy, and emerging-technology roles, found that about 90% of respondents said employees at their organizations use AI tools — but only 38% had a formal, comprehensive AI policy in place, up from 28% a year earlier. A quarter of organizations surveyed had no AI policy at all. The same poll found only 38% of practitioners felt confident their board actually understood AI risk, suggesting the gap runs from front-line usage all the way up to the oversight layer that's supposed to catch it.

Smarsh, working with FTI Consulting, published a similar finding in its 2026 Enterprise AI Trends Study: 55% of enterprises reported actively deploying AI, but just 26% said their governance frameworks were fully keeping pace with that deployment. More pointed for a governance audience, only 30% reported having real capability to detect and manage shadow AI — tools employees adopt outside any approved or visible workflow.

EY's separate pulse poll of technology-industry executives found the pattern repeating from the top down: 78% of leaders said AI adoption was outpacing their organization's governance capacity, and 52% of department-level AI initiatives were running without any formal approval process at all.

Why this matters for AAISM: Shadow AI — unauthorized or ungoverned AI tool use — sits squarely in Domain 1's program management material, specifically the expectation that a governance program has actual visibility into what's deployed, not just policy language describing what should be. A written AI policy nobody is checking against real usage isn't a control; it's a document.

Closing the Gap: What a Real Governance Program Requires

The data points to the same structural fix across all three studies, even though none of them frame it identically: governance programs are being built around policy-writing when the actual bottleneck is visibility and approval speed.

Want to go deeper on how this domain is tested on the AAISM exam? The AI Security Management Prep App covers this and 300 other practice scenarios, offline.

Explore the App — $9.99

Related Reading

For the full exam breakdown, see the AAISM Certification Study Guide. For a live example of a governance and containment gap playing out at a single organization, see The AI That Hacked Another Company. For the regulatory side of the same adoption-outpaces-oversight story, see EU AI Act Enforcement Is Live.

Sources

ISACA — 2026 AI Pulse Poll
Smarsh — New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It
EY — EY survey: autonomous AI adoption surges at tech companies as oversight falls behind