65% of organizations have had an AI incident in the last two years. Only 44% have a documented procedure.
Schellman published its 2026 State of AI Governance report on July 29. The first ANAB-accredited ISO 42001 certification body surveyed 525 U.S. professionals involved in AI governance at companies above 500 employees and $100 million in revenue. Fielded April to May 2026. Results unweighted.
What it says
Two thirds of organizations report an AI-related incident or near miss. Less than half have documented incident response procedures.
Funding is not the constraint. 90% have allocated budget specifically for AI governance. Policy alone is not the answer either: among organizations with a formal acceptable use policy, 28% still handle violations case by case.
From the same respondents, 74% say their organization could pass an AI compliance audit today. 27% describe their governance as fully mature.
Why it matters
Agents are already in production at 46% of surveyed organizations. Among those running agents, control coverage sits between 52% and 57% across every measure, including defined human oversight and escalation. Only 22% have set thresholds that trigger human review.
Third-party AI is the harder gap. 69% are confident in governing AI embedded in vendor tools. 36% of boards discuss third-party AI risk. Liability for vendor AI transfers. Inspection rights do not.
The report frames the shift plainly: the question is moving from whether an organization has an AI governance program to whether it can prove one.
Key takeaways
- Incident response documentation is the first artifact an enterprise buyer asks for, and it trails incident frequency by 21 points.
- Agent oversight without defined thresholds defaults to reviewing everything or reviewing nothing. Neither survives diligence.
- Vendor AI is inherited exposure. Contract review is the only available control, and it happens before signature.
The fix is structural: classify agent actions by consequence, then set review requirements per tier. Autonomous execution with an audit trail at the low end, preapproval and a documented approval workflow for anything touching financial systems, customer data, or access management.
Source:
· Schellman — 2026 State of AI Governance — schellman.com, July 2026
What is the first piece of evidence your enterprise customers ask for when AI enters the security review?