AI Governance · September 30, 2026 · 4 min de lecture
Almost Every Large Company Has an AI Policy. Nearly Half Skipped It the Moment They Were in a Hurry.
An EY survey found 98% of large companies have an AI policy, and 47% bypassed it for an urgent deployment. The problem is not discipline, it is that the policy has no fast lane.
Your AI policy exists. It was approved, circulated, maybe even pinned in a shared channel. The real question: what happens the week a client deadline collides with it?
What is actually happening
On September 18, 2026, Corporate Compliance Insights reported on an EY survey of 202 senior AI decision makers at US companies with more than $1 billion in revenue. The numbers are telling:
- 98% have a formal AI policy.
- 47% say their organization bypassed those policies for an urgent deployment.
- Among companies using agentic AI, 49% had not updated their governance framework, and 39% had no defined accountability for monitoring agents after deployment.
- Annual reviews do find real problems: data quality (57%), model drift (48%), shadow AI (39%). And they lead to action: 25% of respondents fully stopped some AI after review, 64% significantly modified it.
An honest note: these are large US enterprises and self reported answers. A European SME does not live exactly this. But the mechanism is universal, and it’s coming soon to Europe.
The usual reflex, and what actually matters
The standard reading: teams ignore the rules, so add control, tighten the policy, run a refresher training.
I read it differently. A bypass is a design signal. When the only approved path is slow, urgent work takes the other path. Your policy was written for the calm case, while the risky decisions get made in the rushed one. That is not a discipline problem, it is a usability problem with the rule itself.
And the technology moves faster than the document: agents act without a human approving every step, so the question "who answers for what the agent did?" needs a name, not a team.
What this means for an SME or leadership team
- Design the fast lane before you need it. One page, three questions (which data, what is the risk if it is wrong, who reviews), one named decision maker, an answer within 24 hours. Without it, you get silent workarounds.
- One AI use, one owner. A person, not a department. This matters even more for agents: who watches what they do once they are running?
- Review more often than once a year. Model drift and data quality move in weeks. A 30 minute monthly check beats an annual audit.
- Log exceptions without punishing them. Every bypass tells you where the rule does not fit real work. It is your best governance data. In the MAKIA framework, this is where Actors meets Alignment: the rule has to match how people actually work.
Something to sit with
If your AI policy vanished tomorrow, what would actually change in your teams' daily work? If the answer is "not much", the issue is not compliance, it is design.
Try this week
Take 25 minutes with one person on your team. List the last three times someone used AI "outside the lines" or asked "can I just...?". For each, write down what the person needed and what your policy required. Then draft the three questions of your fast lane and name who answers within 24 hours.
Sources
- Corporate Compliance Insights, News Roundup, September 18, 2026 (reporting the EY survey)