Site navigation

Businesses Are Struggling to Follow Their Own AI Governance

Elizabeth Greenberg

,

ai governance
“For years, responsible AI has lived comfortably as a promise,” said Dr Iain Brown, Global Head of AI & Data Science at SAS.

Seven out of 10 UK and Irish enterprises have written an internal policy on how employees should use generative AI (GenAI), but only one in eight can demonstrate that those rules are being followed.

A new study of 100 enterprise technology decision-makers, commissioned by data and AI leader SAS and independently carried out by Coleman Parkes, reveals that writing guidelines for GenAI use has proved far easier than tracking what employees are actually doing with the technology.

Just 12% of tech leaders describe their current AI governance framework as well-established and comprehensive, suggesting a clear gap between GenAI adoption and governance as binding obligations begin landing this year.

Governance gaps come under scrutiny as legal deadlines approach

For companies operating across borders, EU AI Act transparency obligations for deployers come into force on 2 August 2026 while obligations relating to certain high-risk systems have been extended to December 2027.

Organisations running customer-facing AI systems, GenAI chatbots, or AI-assisted content at scale, may fall within the scope.

The financial penalties are significant for non-compliance. Under the EU AI Act, the most serious violations carry separate penalties of up to €35 million or 7% of worldwide annual revenue.

Despite these consequences, according to the SAS research, only 13% of tech leaders feel they will be fully prepared for current and upcoming regulation.

In SAS’ equivalent 2024 research, that figure was 8%, suggesting that two years of investment and policy-writing hasn’t translated into greater preparedness or stronger governance capabilities.

Why is enterprise GenAI governance stuck in development?

A lot of this comes down to a false sense of security. The UK has deliberately maintained a flexible, sector-led approach to AI regulation to encourage investment, giving businesses what many assumed was long-term breathing room compared to the EU’s more prescriptive framework.

The data suggests businesses used this regulatory approach to prioritise speed instead. Over the last two years, the proportion of UKI firms with a formal GenAI policy rose from 59% to 77%. Yet while organisations drafted guidelines, most failed to build the systems needed to enforce them.

The majority of tech leaders, 63%, say their governance infrastructure remains in development – up from 55% in 2024, suggesting progress has stalled.

“For years, responsible AI has lived comfortably as a promise,” said Dr Iain Brown, Global Head of AI & Data Science at SAS.

“But as legal deadlines phase into force, that comfort is rapidly eroding. Many UK firms have likely treated the absence of a standalone AI regulation as an excuse to focus elsewhere, but the rules have been changing around them. The challenge now is being able to demonstrate that those policies are operating in practice.

“Organisations must avoid a situation where underlying data pipelines cannot track, log, or audit what information is entering and leaving a model in real time. If you cannot audit your software, you do not have governance.”


Recommended reading


Exposure is highest where deployment has moved fastest

The risk is most acute where GenAI has already been deployed at scale. Nearly a quarter (23%) of UKI firms actively using GenAI have already integrated it into customer-facing or regulated decision-making workflows. These are the environments most likely to face transparency and audit requirements under emerging regulations.

Meanwhile, human oversight has not kept pace with deployment. Only 25% of active users are running GenAI systems with human-in-the-loop oversight. A further 9% are already operating AI autonomously across selected workflows, with only exception-based human intervention.

How do firms move policy to active governance?

For organisations looking to move their policy to active governance, Dr Brown says there are clear priorities:

“Most organisations don’t actually know where GenAI is running inside their business right now, which data it’s touching, which workflows it’s influencing. That’s the starting point.

“Everything else flows from the data layer: can you show what went into the model, what came out, and whether that was appropriate? That needs live telemetry.

“And the Omnibus delay on high-risk systems is not an excuse to put it to the bottom of the pile. EU regulators have been clear, use this time to build, because the bar in 2027 will be higher than the bar that’s been set this year. Governance has to become an operational capability.”

Elizabeth Greenberg

Staff Writer

Latest News

Events Technology

Socitm Conference to Explore AI, Data and Cyber

AI Cybersecurity

AI Finds Higher Risk Vulnerabilities and Leads to More Exploits

Featured Government

Scot Gov Invests £3M To Commercialise Uni Research

AI Editor's Picks Security

OpenAI Firings Highlight Wider AI Security Concerns