
Agentic AI Governance: Why Companies Break the Rules They Wrote
47% of $1B-plus US companies in a new EY survey have bypassed their own AI governance process to ship faster, while 85% already let AI agents act without a person watching in real time.
Key Takeways
- EY found that 98% of large US public companies have formal AI governance policies, yet 47% have bypassed their own process to ship faster.
- When a company skips its AI governance process under deadline pressure, the deadline becomes the rule that actually governs its AI deployments.
- 85% of large US companies in the EY survey run AI agents that take actions without real-time human oversight, and 49% have not updated their governance for agentic AI.
- The slowest part of agentic AI governance is retraining the people who oversee agents, a learning debt that compounds every quarter it is deferred.
47% of America's largest companies have bypassed their own AI governance process when a deployment felt urgent. That finding comes from an EY survey of 202 senior AI decision-makers at public companies with more than $1 billion in annual revenue, published September 15. The companion number sounds reassuring on its own: 98% of those same companies have a formal AI governance policy in place.
Put the two side by side and most executives will recognize the picture. The rules exist, written down and approved. When a launch date gets close, nearly half of the organizations that wrote them find a way around them.
Behind that figure are real people: the product lead told to ship by Friday, and the risk officer asked to sign the exception anyway. Both of them know the policy, and both of them know the calendar.
The deadline is the policy that wins
I read the 47% as a verdict on the rules themselves. When a process gets skipped every time pressure rises, the organization has already told you which rule it follows. The deadline wins, so the deadline is the real policy.
I shaped a $1.1 billion innovation portfolio across nearly 20 years at Cisco, and the pattern behind that 47% is a familiar one: an exception request is data. Each one marks a place where the official process runs slower than the work it was built to govern. Most companies file those exceptions away. The better-run ones study them.
Rules written for a slower world
I call this pattern rules written for a slower world. Most corporate AI policies were drafted for chatbots and copilots, tools where a person read every output before anything happened. Agents act. They send, buy, approve, and change records on their own, at any hour.
EY's numbers show how far practice has moved past the paperwork. 91% of these companies use agentic AI, in pilots or full deployment. 85% have agents executing actions without real-time human oversight. And 49% still haven't updated their governance to account for agents specifically.
Richard Jackson, EY's Americas Assurance CTO, summed up the mismatch in one line.
"Organizations are applying yesterday's governance rules to today's interactions with AI."
The cost has already arrived. 36% of the companies surveyed reported an AI incident that caused material negative impact. The number I keep returning to is smaller: 26% cannot detect an unauthorized AI agent running inside their own organization. At 1 in 4 of these companies, an agent could be answering customers today without anyone in leadership knowing it exists. Some of those unseen agents were built by employees trying to get their work done faster, which is innovation running ahead of the rules. The people are moving at the speed of the tools, and the governance process is still catching up.
A policy that half the company can skip under pressure works like a voluntary statement, and the wider governance conversation is already moving from voluntary statements toward binding commitments. Knowing which agents exist comes first, which is why NIST's work on identity standards for autonomous agents deserves a place on every enterprise security agenda.
The learning debt sits with the overseers
John McLain, EY Americas Assurance Technology Risk AI Leader, named the harder part of the problem: "The biggest agentic AI risk is that human oversight hasn't evolved accordingly."
Rewriting a policy document takes a few meetings. Teaching the people who oversee agents how to oversee agents takes far longer, and every quarter that work gets deferred, the learning debt compounds. The agents take on more of the business while their reviewers stay trained for the last generation of tools. Policies move at the speed of meetings. Agents move at the speed of software.
That idea sits at the center of my forthcoming book, The Great Relearning: skills expire faster than ever, and oversight is a skill like any other. The 49% who haven't updated their governance for agents are carrying a debt that grows whether or not anyone records it.
If your company is in that 49%, you have plenty of company, and the first step is smaller than a full rewrite. Two questions will get you further than a new committee. When did we last skip our own AI review, and what did the exception tell us about where our process runs slow? And could we produce, by Friday, a list of every agent acting in our company's name, with the person who answers for each one?
If you work beside these agents without holding the budget, one question belongs to you. When an agent makes a mistake in your part of the business, who reviews it, and how quickly? Ask your manager. A company worth working for will have an answer, or will want one.
What these private decisions add up to
Multiply those answers across every billion-dollar company in the country and they settle something larger than compliance. They decide whether a customer can trust a decision made by software at 2 a.m., and whether the people asked to oversee that software get retrained for the job or handed the blame. I write about that choice across my AI governance work, because it is where the next decade of trust in AI gets built or lost.
The companies that come out ahead will write rules fast enough that nobody needs to route around them. Start with the last exception your team signed, and read it as data. What was it trying to tell you? Take that question into your next leadership meeting. And if you want to compare notes, I'm easy to find.
How reliable is the EY survey on AI governance?
EY surveyed 202 senior AI decision-makers at US public companies with at least $1 billion in revenue. Respondents were directors, C-suite executives, or vice presidents and above, and the survey ran from May 28 to June 15, 2026. The margin of error is plus or minus 7 points at 95% confidence, so the 47% who bypassed their own process sits somewhere between roughly 40% and 54%. Even at the low end, the pattern holds.
What AI risks are large companies running into most?
89% of the companies EY surveyed encountered an AI-related risk in the past year. Cybersecurity led at 52%, followed by human and people risk at 47% and shadow AI at 46%, which covers tools and agents employees adopt outside approved channels.
What is the difference between AI governance and agentic AI governance?
Traditional AI governance reviews what a model produces before a person acts on it. Agentic AI governance covers systems that act on their own. It has to settle harder questions up front: which agents exist, what each one may touch, how its actions get logged and reversed, and which named person answers for it.
Here is what makes Alex a credible voice on this topic: Alex shaped Cisco's $1.1 billion innovation portfolio and now advises the California State University system on AI governance, so he knows how approval processes bend under deadline pressure and how to rebuild them for AI that acts on its own.
Talk with Alex about agentic AI governance for your company →
