Businesses sidestep AI governance policies as concerns mount

AI governance is lagging. Senior leaders at major organisations are circumventing existing frameworks because those frameworks don't address AI's specific risks – according to EY research cited in this report. The gap isn't theoretical: it means organisations are deploying AI systems without adequate oversight, shifting risk onto stakeholders and regulators.
This is a governance failure dressed up as innovation pressure. When a company says it's "moving fast", what it often means is: we're moving faster than our controls allow. EY found that senior AI leaders recognise the problem; they simply aren't waiting for policy to catch up. That's not agility. That's negligence with plausible deniability.
The mechanics are familiar: existing compliance frameworks – data protection, risk management, audit – were built for different technologies. They don't map onto algorithmic bias, hallucination, model drift, or supply-chain dependencies in training data. Organisations that acknowledge this mismatch and then deploy anyway aren't innovating responsibly. They're gambling with their reputational and legal exposure.
What's missing from most boardrooms is the simple admission that AI systems carry material risks that require material governance change. Not tweaks to existing policy. Not adding "AI" to a compliance checklist. Genuine architectural change to how decisions get made, who signs off, what gets audited, and who owns failure.
The question isn't whether regulation will tighten – it will. The question is whether your organisation will have a credible governance narrative ready when regulators ask why you deployed systems you admit your frameworks couldn't properly oversee.