Almost Half of Companies Say AI Governance Problems Are Holding Their AI Back
A new survey puts a number on what many bosses already sense: unclear rules for how staff can use AI tools is quietly breaking AI projects from the inside.

Key points
- 46% of organisations told Grant Thornton's 2026 AI Impact Survey that governance and compliance failures are the main reason their AI projects underperform.
- More than 1,100 AI-related bills were introduced by US state legislatures in a single year; 130 passed into law, leaving companies juggling conflicting rules across jurisdictions.
- Using a general-purpose AI chatbot for sensitive legal questions strips away attorney-client privilege, meaning those conversations could be read out in court.
- Waiting for a single clear set of AI regulations isn't a strategy: the rules will keep shifting as the technology does.
- Boards and CEOs, not just IT teams, now need to own AI risk the same way they own financial or safety risk.
When nearly half of all organisations say their AI tools are failing partly because of governance problems, that's not a compliance footnote. That's a business problem sitting on the CEO's desk.
The figure comes from Grant Thornton's 2026 AI Impact Survey, which found that 46% of respondents pointed to AI governance and compliance issues as a key reason their AI underperforms. Governance here means the policies and checks a company puts in place for how AI can be used, by whom, and with what data.
Why is messy AI governance actually dangerous?
Three pressures are colliding at once, and none of them are slowing down.
First, staff are already using AI tools in day-to-day decisions faster than most organisations can write policies to cover them. Second, the regulatory picture is a patchwork: US states are writing their own laws, federal rules are moving slowly, and the European Union is taking yet another approach entirely. Third, state-sponsored hackers are now using AI to generate deepfakes and disinformation at scale, meaning reputational attacks are cheaper and faster than before.
The legal risk alone is worth pausing on. If an employee types sensitive legal questions into a general-purpose AI assistant rather than calling a lawyer, that conversation isn't protected by legal privilege, the rule that normally keeps communications between a client and their lawyer private. In a court case, the other side could demand to see every word. A shortcut that felt harmless at 2pm on a Tuesday could become evidence by the following month.
We've been tracking how companies handle exactly this kind of exposure. Our story on why the fastest way to get AI into your company is through the security team found that three-quarters of employees are already using AI at work, often well ahead of any policy covering them.
Should business leaders wait for clearer rules before acting?
No. Clarity isn't coming soon, and waiting is its own risk.
Over 1,100 AI bills were introduced by US state legislatures last year alone. One hundred and thirty became law. Those laws often pull in different directions, and regulations written today are likely to be overtaken by new AI capabilities within a few years anyway. The goal can't be to comply with a fixed rulebook. It has to be building an organisation that can adapt as the rules change.
As SecurityWeek noted in its coverage, what leadership ownership of AI governance looks like in practice comes down to four things.
| Capability | What it means in plain language |
|---|---|
| Risk visibility | Know which data your AI tools touch, and what goes wrong if that data leaks |
| Flexible governance framework | Use AI-assisted monitoring tools to catch new rules and threats before they become surprises |
| Incident rehearsal | Run practice drills for scenarios like a cyberattack or a disinformation campaign |
| Executive ownership | Make AI risk a board-level item, not just an IT ticket |
A healthcare company holding patient records faces very different AI risks than a delivery firm optimising routes. Governance has to fit the actual exposure, not a generic checklist. That gap between exposure and readiness is something we reported on in July: most security teams are still reaching for tools built for a completely different kind of threat.
For ordinary employees, the practical point is simple: before you put any sensitive information into an AI tool at work, check whether your company has a policy covering it. If it doesn't, ask why not.
Common questions
Does this affect small businesses, or just big corporations?
Small businesses are often more exposed, not less. They're just as likely to have staff using consumer AI tools for work tasks, and less likely to have a legal or compliance team watching for problems.
What should I do if my company has no AI usage policy?
Raise it with management. Until a policy exists, treat any AI tool the same way you would a public forum: assume anything you type could be read by someone outside the company.



