
Ninety-eight per cent of large US companies now have a formal AI governance policy. Forty-seven per cent admit they have bypassed it anyway, whenever a deployment deadline mattered more than the process built to slow it down. That is not two different populations, careful firms and reckless ones. It is the same organisations, doing both, inside the same year.
The Survey Behind the Number
EY’s own research, published this month, surveyed 202 senior AI decision-makers, board members, C-suite executives and vice presidents, at US companies with revenue above one billion dollars. Alongside the 47% bypass figure, 91% of these organisations are already running agentic AI in pilots or full deployment, yet 49% have not updated their governance frameworks to address what autonomous agents actually do differently from the AI systems those frameworks were originally written for. Richard Jackson, EY Americas Assurance CTO, put the mismatch plainly to Dark Reading: organisations are applying yesterday’s governance rules to today’s interactions with AI.
The Number That Should Worry a Board More Than 47%
Thirty-nine per cent of companies using agentic AI have no defined owner for monitoring what those agents do once they are live. Eighty-five per cent admit their agentic systems take actions without real-time human oversight at all. Put those two figures together and the picture is a policy built for a slower, more supervised kind of AI, applied to a faster and more autonomous one it was never designed to cover, rather than a policy occasionally skipped through carelessness. Eighty-nine per cent encountered an AI-related risk in the past year, and 36% experienced an incident with material damage, lost data, financial cost or reputational harm.
Why the Bypass Keeps Happening
The instinct is to read a 47% bypass rate as a discipline problem and fix it with a stricter policy. EY’s John McLain, Americas Assurance Technology Risk AI Leader, frames the actual failure differently: the biggest agentic AI risk is that human oversight has not evolved at the same pace as the technology it is meant to supervise. Sixty-nine per cent of respondents say they lack the internal expertise to evolve their own governance controls, and 63% lack the capacity to implement or design them at all. A team asked to enforce a framework it does not have the expertise to update will eventually stop enforcing it, quietly, under deadline pressure, exactly as this survey found.
What a PMO Actually Owns Here
This is not a problem legal or a chief AI officer can solve by writing a better document. A policy nobody has the capacity to update, monitor or enforce at the point of decision is not governance, it is a filing exercise that happens to be 98% complete on paper. The PMO’s real job in this gap is smaller and more concrete than “AI governance”: name an owner for every agent already in production, build the bypass itself into the reporting line instead of pretending it does not happen, and treat the 39% accountability gap as a delivery risk to close this quarter, not a policy debate to revisit next year. Ninety-eight per cent of organisations already have the document. Almost half of them have already shown you it is not enough.