Firms’ AI leaders lack confidence in governance frameworks

AI leaders inside large organisations don't trust their own governance structures. That's the core finding from an EY report highlighting three concrete problems: insufficient internal expertise to manage AI risk, risk protocols that haven't kept pace with technology deployment, and exposure to regulatory penalties they can't adequately forecast.
This matters because governance gaps around AI don't sit in isolation. They're governance gaps, full stop – they cascade into ESG risk, liability exposure, and supply chain vulnerability. A financial services firm that can't govern its AI use of third-party data faces not just regulatory action but also reputational damage when bias surfaces in lending models or pricing algorithms.
The confidence deficit reveals something starker than a skills shortage. It suggests boards and audit committees aren't yet treating AI governance as a core control function. Instead, it's often silo'd within technology teams or treated as a compliance checkbox. Until governance sits at the same table as risk and strategy, frameworks stay reactive.
Regulatory appetite is accelerating – the EU AI Act already defines high-risk applications, and sectoral regulators in finance, healthcare, and employment are hardening expectations. Firms waiting for clarity before acting will find themselves playing catch-up when enforcement begins.
The gap between technology deployment speed and governance maturity is structural. The question now is whether boards will resource it as urgent, or whether it remains a problem for next year's audit cycle.