A new report from the Infosys Knowledge Institute (IKI), the research arm of global digital services and consulting firm Infosys has uncovered a stark disparity between the perceived importance of responsible AI (RAI) and its actual implementation across enterprises.
The study, Responsible Enterprise AI in the Agentic Era, highlights the growing risks posed by AI – particularly with the rise of agentic AI – while revealing that only 2% of companies have adequate safeguards in place.
The report, based on a survey of over 1,500 business executives and interviews with 40 senior decision-makers across Australia, France, Germany, the UK, the US, and New Zealand, came to some fairly eyebrow-raising conclusions when it comes to AI-related incidents.
Perhaps most strikingly, the report found that 95% of C-suite and director-level executives reported AI-related incidents in the past two years, with 39% describing the resulting damage as “severe” or “extremely severe.” The financial and reputational consequences are significant: 77% of organisations experienced financial losses due to AI risks, while 53% suffered reputational harm.
With the advent of agentic AI – systems capable of autonomous decision-making – 86% of executives familiar with the technology believe it will introduce new risks and compliance challenges.
RAI Implementation Lags Behind Ambition
Despite 78% of senior leaders viewing RAI as a driver of revenue growth, most companies lack the necessary controls. The report introduced the “RAISE BAR” benchmark to assess RAI maturity, revealing that only 2% of firms (“RAI leaders”) met the full benchmark criteria, while just 15% (“RAI followers”) met three-quarters of the standards.
Notably, RAI leaders experienced 39% lower financial losses and 18% lower severity from AI incidents compared to their peers. These organisations excel in areas such as AI explainability, proactive bias evaluation and mitigation, rigorous AI testing and validation, and clear incident response plans.
While 83% of executives believe future AI regulations will encourage—not hinder—AI initiatives, companies estimate they are underinvesting in RAI by 30% on average. The report warns that treating RAI as a reactive compliance measure, rather than a strategic advantage, leaves businesses vulnerable as AI adoption accelerates.
Recommended reading
- Identity-based Cyber-attacks Are Surging
- Report: Hackers Are Targeting AI Agents and ‘Weaponising’ GenAI
- UN Report Highlights Progress in Global Cybersecurity
To bridge this gap, Infosys recommends learning from RAI leaders who have developed robust governance frameworks, balancing agility with governance by combining decentralised innovation with centralised RAI oversight, embedding RAI guardrails into secure AI platforms to ensure agents operate within approved data and systems, and establishing a proactive RAI office to monitor risks, set policies, and scale governance using tools like Infosys’ AI3S (Scan, Shield, Steer).
Jeff Kavanaugh, Head of Infosys Knowledge Institute, Infosys, said: “Today, enterprises are navigating a complex landscape where AI’s promise of growth is accompanied by significant operational and ethical risks. Our research clearly shows that while many are recognizing the importance of Responsible AI, there’s a substantial gap in practical implementation.
“Companies that prioritise robust, embedded RAI safeguards will not only mitigate risks and potentially reduce financial losses but also unlock new revenue streams and thrive as we transition into the transformative agentic AI era.”





