Artificial Intelligence
Written by: Tathagata Sen
Updated 11:20 AM EDT, September 15, 2026

Photo credit: Unsplash.com
The OneTrust’s 2026 AI-Ready Governance Report, released September 14, found that 74% of organizations have moved beyond AI pilots into departmental or scaled adoption. OneTrust said the wider use of AI and AI agents is increasing the need for oversight, controls, and accountability, because they can take actions within business workflows, according to a Help Net Security report.
OneTrust and Sapio Research surveyed 1,200 senior business decision-makers across the United States, Canada, the United Kingdom, France, Germany, Spain, Australia, and Singapore.
Organizations are using risk assessments, employee usage controls, policies, monitoring, and other measures to govern AI. But only 5% said coordination and accountability are clearly defined across the AI lifecycle.
While 87% of respondents said their organizations encourage the use of AI agents, only 47% said those agents have clear governance, oversight, and controls. Another 40% said they are encouraging agent use while governance measures are still being developed.
The report also found that 48% of respondents had seen at least one incident in the past year in which an AI system or agent took an unapproved action. Data exposure, misuse of sensitive information, and unapproved employee use of AI tools were among the leading incident types cited.
For chief data officers (CDOs), the findings highlight a problem that goes beyond AI policy. Organizations need visibility into which AI systems and agents are being used, what data they can access, and who is responsible for them.
The survey found that 33% of organizations had employees use unapproved AI tools because approved tools or processes were not available quickly enough. In Singapore, 57% of respondents cited “data quality, access, privacy, or security concerns” as reasons AI deployment was delayed.
The report points to a need for governance to remain connected to AI systems after deployment. That includes tracking AI use, maintaining data controls, and monitoring how systems and agents operate as they change.
For CDOs, this makes AI governance closely tied to data governance. As AI gains access to more enterprise data and workflows, organizations need to know where that data is being used and whether the controls around it remain effective.