SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Schellman finds AI governance gap amid regulatory pressure

Schellman finds AI governance gap amid regulatory pressure

Fri, 31st Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Schellman has published research showing that 74% of enterprises believe they are ready for an AI audit, while only 27% describe their AI governance programs as fully mature. The findings are based on a survey of 525 US-based professionals involved in AI governance.

The report points to a gap between confidence and operational readiness as companies expand their use of AI systems and face growing regulatory scrutiny. While 90% of organizations have allocated funding for AI governance, fewer have put in place the policies and procedures associated with mature oversight.

Among those surveyed, 57% said their organization has a formal AI governance policy, 44% have AI-specific incident response procedures, and 64% reported a formal AI acceptable use policy that is actively communicated to employees. The figures suggest many companies have begun building governance structures but have not yet turned them into a consistent operating model.

One area highlighted in the research is the shift of AI agents from testing into live use. Schellman found that 86% of organizations have tested or piloted AI agents, while 46% already have them in production.

Organisations with mature AI governance are far more likely to have AI agents in production: 78% have agents live, compared with 22% of those with developing governance programs.

That finding links governance progress with commercial deployment at a time when businesses are weighing both the opportunities and risks of more autonomous systems. Approaches to human oversight vary widely, indicating that many companies are still working out how decisions and actions taken by AI agents should be reviewed.

Executive control

The survey found that responsibility for AI decisions remains concentrated among senior technology leaders. Some 42% of respondents said the chief information officer or head of IT is primarily responsible for AI purchasing decisions, while 37% said the same executive is ultimately accountable when AI-related risks emerge.

Board engagement appears less consistent. Only 54% of respondents said AI governance is regularly reported to boards or executive leadership teams.

Third-party AI risk also emerged as a weaker area of oversight. Just 36% of boards regularly discuss the risks linked to AI embedded in vendor platforms and enterprise software, despite companies' growing reliance on external tools and suppliers.

Regulatory preparation is another uneven area. Nearly all respondents operate in regions where AI-related regulation is developing or already in force, but organizations reported very different levels of action depending on the jurisdiction.

According to the survey, 89% have taken action to prepare for US regulations, while 29% have taken action related to the EU AI Act and 12% have acted on AI requirements across Asia-Pacific markets. The pattern suggests domestic requirements are receiving more immediate attention than overseas rules, even for organizations that may face cross-border obligations.

Danny Manimbo, managing principal and ISO & AI practice leader at Schellman, said the issue is less about awareness than implementation. "Organisations are not struggling because they lack awareness of AI governance. Most already have policies, funding, and oversight mechanisms in place," Manimbo said. "The challenge is turning those individual activities into a mature, operationalized program that can withstand regulatory scrutiny and keep pace with rapidly evolving AI systems. As organizations deploy more autonomous AI capabilities, governance can no longer be treated as a one-time exercise. It has to become a continuous process of oversight, accountability, and validation."

Business effects

The research also examined whether governance investment is producing measurable results inside organizations. Respondents linked AI governance work to improved internal efficiency, stronger readiness for regulation, easier scaling of AI initiatives, and greater customer trust.

More specifically, 57% said governance efforts improved internal efficiency, 49% cited stronger readiness for emerging regulations, 43% pointed to easier AI scaling and innovation, and 39% said governance had increased customer trust. Those responses suggest some companies see governance not only as a compliance exercise but also as part of day-to-day business operations.

The findings come as businesses face pressure from customers, regulators, and boards to show that AI oversight is functioning in practice rather than existing only on paper. The report suggests formal structures alone are no longer enough if they are not backed by reporting lines, incident response procedures, and accountability for third-party systems.

Avani Desai, chief executive officer of Schellman, said expectations around proof of oversight are shifting. "The conversation around AI governance has fundamentally changed," Desai said. "Customers, regulators, boards, and business partners are no longer asking whether organizations are thinking about governance; they want proof that governance is working. The organizations that build trust through mature, demonstrable governance programs will be better positioned to scale AI, navigate regulatory change, and create long-term business value. Governance is increasingly becoming a competitive differentiator, not just a compliance requirement."