Companies roll out AI agents faster than they can govern them

EY surveyed 202 senior AI executives at US organizations with at least $1 billion in revenue. Almost all (98 percent) say they have formal AI governance policies. Nearly half (about 47 percent) admit the organization has skipped that process for urgent deployments. Among respondents whose firms use agentic AI, 26 percent say they cannot detect unauthorized AI agents running inside the company. About 36 percent report an AI incident or failure that already caused material harm, such as data loss, financial damage, brand damage, or operational disruption. Roughly two-thirds worry they lack internal expertise to design, implement, or evolve governance controls as autonomous systems spread.
Until recently, many teams treated AI risk as a policy document problem. If a governance framework existed, leaders assumed the hard work was done and day-to-day use could stay informal: paste context, ship the draft, fix problems later. That assumption no longer holds. Autonomous agents multiply the same failure pattern professionals already feel in one-off chats: missing inventory, skipped review steps, and speed beating standards. Formal policy without consistent application means incidents arrive before anyone can name what is running, who owns the output, or when a human must stop the workflow.
Analysis
Treat this as a trap to avoid: do not wait for a perfect enterprise policy while your team quietly adds agents and reusable assistants. Write a one-page AI operating rule for your next recurring workflow that names allowed tools, required business context, a human review checkpoint, and the one case where urgency still cannot skip the check—then share it before the next rollout conversation.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Companies roll out AI agents faster than they can govern them", Collab365 Spaces. 1 source referenced.