65% of organizations have had an AI incident in the last two years. Only 44% have a documented procedure.

Schellman published its 2026 State of AI Governance report on July 29. The first ANAB-accredited ISO 42001 certification body surveyed 525 U.S. professionals involved in AI governance at companies above 500 employees and $100 million in revenue. Fielded April to May 2026. Results unweighted.

What it says

Two thirds of organizations report an AI-related incident or near miss. Less than half have documented incident response procedures.

Funding is not the constraint. 90% have allocated budget specifically for AI governance. Policy alone is not the answer either: among organizations with a formal acceptable use policy, 28% still handle violations case by case.

From the same respondents, 74% say their organization could pass an AI compliance audit today. 27% describe their governance as fully mature.

Why it matters

Agents are already in production at 46% of surveyed organizations. Among those running agents, control coverage sits between 52% and 57% across every measure, including defined human oversight and escalation. Only 22% have set thresholds that trigger human review.

Third-party AI is the harder gap. 69% are confident in governing AI embedded in vendor tools. 36% of boards discuss third-party AI risk. Liability for vendor AI transfers. Inspection rights do not.

The report frames the shift plainly: the question is moving from whether an organization has an AI governance program to whether it can prove one.

Key takeaways

  • Incident response documentation is the first artifact an enterprise buyer asks for, and it trails incident frequency by 21 points.
  • Agent oversight without defined thresholds defaults to reviewing everything or reviewing nothing. Neither survives diligence.
  • Vendor AI is inherited exposure. Contract review is the only available control, and it happens before signature.

The fix is structural: classify agent actions by consequence, then set review requirements per tier. Autonomous execution with an audit trail at the low end, preapproval and a documented approval workflow for anything touching financial systems, customer data, or access management.

Source:
· Schellman — 2026 State of AI Governance — schellman.com, July 2026

What is the first piece of evidence your enterprise customers ask for when AI enters the security review?

Mathieu Flamant
Founder · Tech Leader · mathieuflamant.com