Most businesses rolling out AI tools know they need governance policies. Fewer than one in five can actually prove those policies are working. That gap is about to become a major liability.
Arctera, a business unit of Cloud Software Group, released its State of AI Governance 2026 report this week, based on a survey of 500 compliance decision-makers and influencers across finance, healthcare, and energy/utilities in the Americas and EMEA. The research, commissioned by Hanover Research, paints a clear picture: organizations are moving fast on AI adoption but not fast enough on the accountability infrastructure behind it.
The Governance Gap in Numbers
Three statistics from the report tell the story:
78% of organizations using AI expect their communications risk to increase over the next 12 to 24 months.
55% have the core AI policies, training procedures, and review steps in place.
19% have the logging, retention, detection, and scoring controls they would need to prove governance is actually working.
Read that sequence again. Most companies are aware of the risk. More than half have written a policy. But barely one in five has the evidence layer that would let them show an auditor, a regulator, or a board exactly what their AI produced, who reviewed it, where it went, and whether the record was retained.
The report also found that 70% of organizations see their data archives as a major or critical asset for responsible AI use. The data is there. The gap is in instrumentation — the ability to track, log, and reconstruct AI-assisted decisions when it matters.
Why This Is Happening Now
There is a predictable pattern in how organizations adopt new technology. The first wave is about deployment: get the tools in place, write a policy, do some training. The second wave is about accountability: prove that what you deployed is actually behaving as intended.
With AI, the first wave happened fast. The pressure to ship AI tools — from leadership, from competitors, from vendors — compressed the adoption timeline. The second wave, which requires sustained investment in infrastructure, is now running to catch up.
The Arctera findings land as regulators in the US and Europe are starting to ask harder questions about AI governance. The EU AI Act’s compliance deadlines are staggered across 2025 and 2026 for high-risk systems. The US has introduced sectoral guidance for financial services and healthcare. In both cases, organizations need to demonstrate controls, not just assert them.
What This Means for Business
If you are using AI tools to generate communications, support decisions, or interact with customers, the question your compliance team will eventually ask is not “do we have a policy?” but “can we reconstruct what happened on this date, with this model, producing this output?”
That reconstruction capacity requires a few things that most organizations have not fully built out yet: audit logs of AI-generated content, retention policies that account for AI as a system of record, detection controls that flag when AI outputs diverge from expected patterns, and scoring frameworks that can evaluate AI behavior over time.
None of this is exotic. It is fundamentally a data management problem. But it requires treating AI governance the same way mature organizations treat financial controls or cybersecurity: with structured processes, regular testing, and evidence that can survive scrutiny.
The 81% of organizations that cannot yet prove governance readiness are not necessarily doing the wrong things. Most have started in the right place. The work now is moving from policy to proof — from writing the rule to showing the audit trail that confirms the rule is being followed.
The Data Angle
One of the more interesting findings in the Arctera report is that 70% of organizations already view their archives as a critical asset for responsible AI. That represents a real opportunity. Organizations that have invested in data infrastructure, enterprise search, and information governance have a head start. The governance evidence layer is, at its core, a data layer.
For businesses still operating with scattered data, inconsistent logging practices, and no clear system of record for AI-generated content, the path to governance readiness runs directly through better data foundations.
This is worth paying attention to regardless of your industry or company size. Regulators may be moving slower than the technology, but they are moving. The organizations that will handle this well are the ones building the evidence infrastructure now, while there is still time to do it thoughtfully rather than reactively.
Enterprise DNA works with organizations at every stage of AI adoption, from initial upskilling to full agentic deployment. If your team is building AI capabilities and needs help thinking through the data infrastructure that makes governance possible, book a discovery call.
Source
GlobeNewswire / Arctera