AI adoption inside most organizations is no longer in question — employees are using it constantly, sanctioned or not. What's missing is the governance layer that's supposed to keep pace. Three separate research efforts published in 2026 landed on the same conclusion from three different angles: adoption is running well ahead of any formal program to track, approve, or oversee it. For anyone studying toward the AAISM certification, this gap is the day-one governance failure mode that Domain 1 material is built around.
The Gap, By the Numbers
ISACA's 2026 AI Pulse Poll, which surveyed roughly 3,400 digital trust professionals across audit, governance, cybersecurity, privacy, and emerging-technology roles, found that about 90% of respondents said employees at their organizations use AI tools — but only 38% had a formal, comprehensive AI policy in place, up from 28% a year earlier. A quarter of organizations surveyed had no AI policy at all. The same poll found only 38% of practitioners felt confident their board actually understood AI risk, suggesting the gap runs from front-line usage all the way up to the oversight layer that's supposed to catch it.
Smarsh, working with FTI Consulting, published a similar finding in its 2026 Enterprise AI Trends Study: 55% of enterprises reported actively deploying AI, but just 26% said their governance frameworks were fully keeping pace with that deployment. More pointed for a governance audience, only 30% reported having real capability to detect and manage shadow AI — tools employees adopt outside any approved or visible workflow.
EY's separate pulse poll of technology-industry executives found the pattern repeating from the top down: 78% of leaders said AI adoption was outpacing their organization's governance capacity, and 52% of department-level AI initiatives were running without any formal approval process at all.
Closing the Gap: What a Real Governance Program Requires
The data points to the same structural fix across all three studies, even though none of them frame it identically: governance programs are being built around policy-writing when the actual bottleneck is visibility and approval speed.
- Discovery before policy enforcement — a policy is only as good as an organization's ability to know what's actually running against it. Network and SaaS-usage discovery, browser extension audits, and simple self-reporting channels all surface more shadow AI than a policy document alone ever will.
- Risk-scoped approval paths, not blanket bans — EY's finding that over half of department-level AI initiatives skip formal approval suggests slow, one-size-fits-all approval processes aren't being followed in practice. A fast-track path for lower-risk use cases removes the incentive to route around governance entirely.
- Escalation authority that's actually usable — per the same EY poll, only half of governance or ethics leaders can independently halt a project that fails safety checks; the rest need CEO or board sign-off, which likely means real exposure windows outlast the escalation process in practice.
Want to go deeper on how this domain is tested on the AAISM exam? The AI Security Management Prep App covers this and 300 other practice scenarios, offline.
Explore the App — $9.99Related Reading
For the full exam breakdown, see the AAISM Certification Study Guide. For a live example of a governance and containment gap playing out at a single organization, see The AI That Hacked Another Company. For the regulatory side of the same adoption-outpaces-oversight story, see EU AI Act Enforcement Is Live.
Sources
ISACA — 2026 AI Pulse Poll
Smarsh — New Smarsh Research Finds Enterprises Are Deploying AI Faster Than They Can Govern It
EY — EY survey: autonomous AI adoption surges at tech companies as oversight falls behind