Most US companies lack mature AI governance frameworks

US companies are investing in AI governance infrastructure but lack the maturity to manage risk as agentic systems proliferate, according to Schellman's latest report. The gap matters: organisations are spending capital on frameworks yet deploying autonomous AI without corresponding oversight structures. Budget allocation and actual governance readiness are diverging – a common pattern when boards react to hype rather than build systems methodically.
The problem sits at board level. Most companies have appointed AI oversight roles and allocated compliance budgets, but those governance layers haven't translated into enforceable policies, documented decision-making processes, or clear accountability chains. Agentic AI – systems that operate with minimal human intervention – demands a different governance posture than today's supervised large language models. Organisations cannot retrofit controls after deployment; they need them embedded in procurement, testing, and deployment gates.
This matters for ESG reporting too. Governance frameworks, including AI oversight, now feature in ESG assessment methodologies. Investors and regulators increasingly flag weak AI governance as a governance failure alongside board independence or executive pay misalignment. The Schellman finding exposes a compliance theatre problem: companies tick boxes on governance spending without building the muscle to manage what they're actually running.
The real question isn't whether companies will mature their AI governance – competitive pressure and regulation will force that. It's whether they'll do it reactively after incidents, or proactively before deploying autonomous systems into production.