Almost Half of Companies Say AI Governance Problems Are Holding Their AI Back
A new survey puts a number on what many bosses already sense: unclear rules for how staff can use AI tools is quietly breaking AI projects from the inside.

Key points
- 46% of organisations told Grant Thornton's 2026 AI Impact Survey that governance and compliance failures are the main reason their AI projects underperform.
- More than 1,100 AI-related bills were introduced by US state legislatures in a single year; 130 passed into law, leaving companies juggling a patchwork of conflicting rules.
- Using a general-purpose AI chatbot for sensitive legal questions strips away attorney-client privilege, meaning those conversations could be read out in court.
- Waiting for a single clear set of AI regulations is not a strategy: experts say the rules will keep shifting as the technology does.
- Boards and CEOs, not just IT teams, now need to own AI risk the same way they own financial or safety risk.
When nearly half of all organisations say their AI tools are failing partly because of governance problems, that is not a compliance footnote. That is a business problem sitting on the CEO's desk.
The figure comes from Grant Thornton's 2026 AI Impact Survey, which found that 46% of respondents pointed to AI governance and compliance issues as a key reason their AI underperforms. Governance here just means the policies, rules, and checks a company puts in place for how AI can be used, by whom, and with what data.
Why is messy AI governance actually dangerous?
Three pressures are colliding at once, and none of them are slowing down.
First, staff are already using AI tools in day-to-day decisions faster than most organisations can write policies to cover them. Second, the regulatory picture is a patchwork: US states are writing their own laws, federal rules are moving slowly, and the European Union is taking yet another approach entirely. Third, state-sponsored hackers are now using AI to generate deepfakes and disinformation at scale, meaning reputational attacks are cheaper and faster than ever before.
The legal risk alone is worth pausing on. If an employee types sensitive legal questions into a general-purpose AI assistant rather than calling a lawyer, that conversation is not protected by legal privilege, the rule that normally keeps communications between a client and their lawyer private. In a court case, the other side could demand to see every word. A shortcut that felt harmless at 2pm on a Tuesday could become evidence by the following month.
Should business leaders wait for clearer rules before acting?
No. Clarity is not coming soon, and waiting is its own risk.
Over 1,100 AI bills were introduced by US state legislatures last year alone. One hundred and thirty became law. Those laws often pull in different directions, and regulations written today are likely to be overtaken by new AI capabilities within a few years anyway. The goal cannot be to comply with a fixed rulebook. It has to be building an organisation that can adapt as the rules change.
As SecurityWeek noted in its coverage of this topic, what leadership ownership of AI governance actually looks like in practice comes down to four things.
| Capability | What it means in plain language |
|---|---|
| Risk visibility | Know which data your AI tools touch, and what goes wrong if that data leaks |
| Flexible governance framework | Use AI-assisted monitoring tools to catch new rules and threats before they become surprises |
| Incident rehearsal | Run practice drills for scenarios like a cyberattack or a disinformation campaign |
| Executive ownership | Make AI risk a board-level item, not just an IT ticket |
A healthcare company holding patient records faces very different AI risks than a delivery firm optimising routes. Governance has to fit the actual exposure, not a generic checklist.
For ordinary employees, the practical take is simple: before you put any sensitive information into an AI tool at work, ask whether your company has a policy covering that. If it does not, ask why not.
Common questions
Does this affect small businesses, or just big corporations?
Small businesses are often more exposed, not less. They are just as likely to have staff using consumer AI tools for work tasks, and less likely to have a legal or compliance team watching for problems.
What should I do if my company has no AI usage policy?
Raise it with management. Until a policy exists, treat any AI tool the same way you would a public forum: assume anything you type could be read by someone outside the company.



