Jul 31, 2026
Enterprise

Schellman AI governance report finds US companies lack maturity

Schellman says 27% of surveyed US companies have mature AI governance, even as most fund oversight and test AI agents.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

Schellman AI governance report finds US companies lack maturity
Photo: CIO Dive

The Schellman AI governance report released Wednesday found a wide gap between enterprise confidence and operating discipline: nearly three-quarters of surveyed governance professionals said their organizations could pass an AI compliance audit, while only 27% called their programs fully mature. The compliance services firm surveyed 525 U.S.-based professionals involved in governance, making the findings a useful check on how far enterprise AI oversight still trails deployment.

Schellman said 90% of respondents reported that their organizations have set aside money for AI governance. That spending has not translated into consistent controls across policy, oversight and accountability, according to the report, as companies put more AI systems into use.

Danny Manimbo, managing principal and ISO and AI practice leader at Schellman, said in a statement that many companies have put basic governance steps in place. The harder work, he said, is converting those separate efforts into programs that operate consistently, can hold up under regulatory review and can keep pace with changing AI systems.

How mature is AI governance at US companies?

Schellman’s numbers suggest most companies are still in the middle stage: they have budgets and some governance artifacts, but lack complete operational programs. Only 64% of organizations surveyed said they have a formal AI acceptable-use policy that is actively communicated to employees, 57% said they maintain formal policies, and 44% said they have incident response procedures specific to AI.

Agentic AI adds pressure to that gap. The report found that 86% of organizations are testing AI agents, and nearly half already have them in production. Agentic AI generally refers to systems that can take actions toward a goal with less direct human instruction than earlier AI tools, which makes governance harder to treat as a document-and-approval exercise.

Other research cited by CIO Dive points in the same direction. A June IBM Institute for Business Value study found that many organizations are rolling out AI faster than IT can track, and that two-thirds of CIOs and CTOs said they are responsible for AI systems they do not fully control. A Deloitte study earlier this year found that only 1 in 5 companies had a mature model for governing autonomous agents, a shortfall that can raise exposure to vulnerabilities.

Manimbo said organizations using more autonomous AI capabilities should treat governance as an ongoing process involving oversight, accountability and validation, rather than a one-time compliance project.

Schellman also reported that organizations with more meaningful governance programs said they saw better internal efficiency, easier scaling of AI and innovation, and higher customer trust. Those are respondent-reported outcomes, not independently verified performance measures, and the report did not disclose company-level operating metrics behind them.

Regulation is another driver. Schellman found that a majority of companies said they were preparing for U.S. rules, while nearly one-third said they were preparing to comply with the EU AI Act.

Avani Desai, Schellman’s CEO, said in a statement that AI governance has moved from optional to required as customers, regulators, boards and business partners ask for evidence that oversight works. The report’s harder message for enterprise buyers and vendors is that budget alone is not evidence of control.

This story draws on original reporting from CIO Dive.

More from Enterprise

All Enterprise →