The Innovation SpeakerMario A. Brückner Request a date
Article · AI governance & compliance

The governance gap.

policies are nearly everywhere. effect is a good deal rarer.

By Mario A. Brückner ·

In September 2026, Ernst & Young published in New York the results of a survey among 202 US executives with direct responsibility for their organisation's AI systems, their governance or their audit. 98 per cent said their company had formal policies for the use of artificial intelligence. In the same questionnaire, 47 per cent admitted their organisation had at some point not followed that process for urgent deployments.

You can read that as a contradiction. I read it as a measurement.

Both figures come from the same survey and describe the same people. They do not contradict each other — they describe two different objects: the policy, and its force. One is a document, the other a practice. Whether the two are connected is not a rhetorical question. It can be investigated, and it has been.

Two methods, two numbers

If you want to know how widespread AI governance really is, there are two routes. The first: ask executives. The second: read what companies publish themselves, where they carry legal responsibility for the statement.

Glass Lewis took the second route and analysed the proxy statements of the S&P 100 for the 2025 reporting year — the documents US listed companies use to inform shareholders ahead of the annual meeting. The result: 54 per cent disclosed board-level oversight of AI, 45 per cent maintained an AI policy. Both together appeared in 28 per cent.

ISS STOXX asked the same question across a wider field and, in January 2026, reviewed the disclosures of 3,048 companies from the Russell 3000 and the S&P 500. There, 245 companies — 8 per cent — disclosed board-level oversight, and 275 — 9 per cent — an AI policy. The authors' conclusion: for most of the market, AI adoption is currently taking place in a “policy vacuum”.

The 98 per cent and the 45 per cent cannot be set directly against each other, and I am not doing so. The populations differ, and more importantly so does the object: disclosure is not the same as existence. A company may hold an excellent AI policy and not mention it in its proxy statement, because no law requires it to. The distance is no proof of dishonesty.

It shows something else, and that is the more interesting part: what executives say about their organisation and what their organisation considers worth reporting are two independent quantities. Where an AI policy does not even appear in the document in which a board describes its own oversight, it is at any rate not an object of that oversight.

A third measurement sits between the two. In May 2026 the professional association ISACA surveyed more than 3,400 practitioners in IT audit, governance and information security: 90 per cent believe AI is being used in their organisation; 38 per cent report a formal, comprehensive policy, and 25 per cent none at all. A year earlier, 28 per cent had a policy. The gap is closing, then — more slowly than adoption is growing. And because ISACA surveys its own members, an audience unusually attentive to governance, the real distance is likely to be wider rather than narrower.

A term from 1977

The pattern has had a name for almost fifty years. In 1977, John Meyer and Brian Rowan described how organisations adopt formal structures not only because they work, but because their environment expects them. Such structures confer legitimacy. And because taking them seriously would disturb day-to-day operations, they are decoupled from those operations. The structure stays in place; the work carries on beside it.

Patricia Bromley and Walter Powell sharpened the term in 2012 and split it in two. The first variant is the familiar one: a policy is adopted and not implemented — policy-practice decoupling. The second is the more uncomfortable one: the policy is implemented, but the implementation has lost its connection to the purpose — means-ends decoupling. Things are documented, reviewed, approved and reported, and none of it makes the outcome better.

For AI governance the second variant is the more dangerous. You recognise the first because nothing happens. You recognise the second by nothing at all — it produces activity, artefacts and reports. It looks like work.

A policy placed on top of an organisation without touching its decision paths behaves like a graft whose cut surfaces do not meet. It stays green for a while, because there is still sap in it. It never knits.

What practitioners report

Ravit Dotan, Tomer Gershoni, Irit Hadar and Gil Luria were the first to apply this theory systematically to AI. Their work appeared in April 2026 in Empirical Software Engineering: 32 semi-structured interviews conducted between June and November 2024 with people in technical roles, leadership roles, non-technical roles and dedicated AI ethics roles, in companies ranging from four to more than a hundred thousand employees.

Twelve of the 32 interviews are classified as negative decoupling — more declaration than practice. Among them a profile the authors call Policy Focus: policies are produced, and work on implementation does not follow. A second is Standstill — elaborate frameworks without practical application.

The more notable finding is the other one. Eight of the 32 interviews show positive decoupling — organisations doing more than they declare. Five of those sit in the Operations Focus profile: practice in place without formal structure. Decoupling runs in both directions, then. The presence of a policy says little about practice. Its absence says just as little.

For context: 32 interviews are not a representative sample, and around two thirds of participants work in the United States. The study explains the mechanics of the problem; it says nothing about how widespread it is.

Where the gap is widening

Back to the EY survey, this time with the necessary caveats. 202 respondents give a margin of error of ±7 percentage points; only listed US companies with at least one billion dollars in annual revenue were surveyed; the field ran from 28 May to 15 June 2026; the commissioning party is EY's assurance practice, which sells the obvious remedy. Nothing about mid-sized European companies follows from this. As an indication of direction for large, AI-heavy corporations it is usable.

91 per cent of respondents say their organisation uses agentic AI — as a pilot or in full deployment. Of that subgroup, 49 per cent say the existing governance framework has not yet been updated for it. And 26 per cent of that subgroup answer that their organisation cannot detect unauthorised AI agents operating internally.

That last figure deserves a moment. Anyone unable to detect unauthorised systems does not, by definition, know how many there are. The 26 per cent are the self-assessment of those aware of the gap. Nothing is thereby said about the other 74 per cent.

Independently of surveys, the number of documented incidents is rising. The Stanford AI Index Report records 362 incidents in the AI Incident Database for 2025, against 233 in 2024; until 2022 the annual figure stayed below one hundred. The report names the limits of that series itself: entries are editorially reviewed, and coverage is skewed towards English-language media and highly visible cases. What is measured is reporting, not reality. The slope remains remarkable nonetheless.

The duty without a fine

Article 4 of the AI Act has applied since 2 February 2025. It obliges providers and deployers of AI systems — that is, every organisation that merely buys and uses them — to take measures so that their staff have a sufficient level of AI literacy. Amending Regulation (EU) 2026/1744, in force since 27 July 2026, softened the wording: ensuring became supporting, and nobody has to guarantee a particular level of competence for a particular person. The duty was not removed.

Now the detail missing from most summaries: Article 4 is not in the penalty catalogue. Article 99(3) to (5) lists which infringements attract which amounts — Article 5, Articles 16, 22 to 24 and 26, the provisions for notified bodies, Article 50. Article 4 does not appear there.

It does not follow that the article is without consequence. Article 99(1) requires Member States to lay down penalties and other enforcement measures for any infringement of the regulation, expressly including non-monetary ones. In Germany, the AI market surveillance and innovation act has been in force since 29 July 2026; the Bundesnetzagentur is the national market surveillance authority, point of contact and complaints body. Legal commentary points to two further routes: an omission may be treated in liability proceedings as a breach of the duty of care, and employees may derive claims to training from it.

A duty without a fixed penalty range is therefore not the harmless one, but the one that is harder to plan for. A fine can be quantified, entered in a risk register and weighed against the effort. A duty of care shows itself only once something has happened — and then in hindsight.

The role without authority

That leaves the question of how to tell in advance which side of the gap an organisation is on. A workable indicator is not whether a policy exists, but what authority the people responsible for it hold.

Victor Frimpong and Ortopah Kojo Botchey published a mapping on this in April 2026: 351 organisations worldwide, surveying people with senior AI responsibility. In 6.3 per cent of the 351 organisations the AI governance role sits within the executive. Ranked by authority — again across all 351 — it is advisory in 32.2 per cent — influential, but without decision rights — and in only 16.5 per cent can it approve or veto an AI system.

One of their four patterns the authors call Symbolic Governance: roles that formally exist, without resources and without reach. The caveat applies here too — snowball sampling, self-report, a single study in a publisher of mixed reputation. But the order of magnitude matches the disclosure analyses, and it matches what Bromley and Powell call means-ends decoupling. Someone is in post. They are simply not allowed to do anything.

What this means for leadership

First: do not check whether a policy exists, but when it last changed a decision. The useful question is not “do we have an AI policy?” but: which initiative was stopped, reworked or rejected on its basis in the past twelve months? If the answer is “none”, there are two possibilities — either everything was in order, or the policy is decoupled. From the outside the two look identical.

Second: give the role authority before you fill it. A governance function without the right to approve is a reporting function. That can be sensible — but then it should be called one, and not mistaken for oversight.

Third: separate competence from training records. Article 4 requires measures, not certificates. A mandatory one-hour video produces an attendance list. Whether anyone afterwards recognises when a model sounds plausible and is wrong is another matter — and that is the capability at issue.

Fourth: keep an inventory before you write a policy. You can only supervise what you know. As long as nobody can say which AI systems are running in the building, on whose behalf and with which access rights, the finest policy governs an unknown object. How fast that object is growing is a matter of official statistics: the share of EU companies with ten or more employees using AI rose from 13.5 per cent in 2024 to 20.0 per cent in 2025. In Germany it stands at 26 per cent, and at 57 per cent for companies with 250 or more employees.

Fifth: do not treat the postponed high-risk deadlines as a reprieve. The Digital Omnibus moved Annex III to 2 December 2027 and Annex I to 2 August 2028. Article 4 has applied since February 2025, the transparency obligations of Article 50 since August 2026. What was postponed is the part that takes the most work — not the part that already applies. What has applied since August is set out in more detail in the article on the EU AI Act.

Sixth: allow for being better than your paperwork. Eight of 32 interviews showed positive decoupling. If sensible practice exists in your organisation that is written down nowhere, that is not a defect another document will fix. It is substance — and it leaves on the day the person who carries it in their head does.

The gap in question does not run between technology and regulation. It runs between what an organisation writes about itself and what it decides. That gap is older than artificial intelligence. What is new is that it is now being filled by systems that do not wait for the next meeting.

Note on AI use: research and drafting of this article were AI-assisted. Every figure was checked against the original publication; sample sizes, field periods and commissioning parties are given in the text or in the source list. Surveys from vendors and consultancies are marked as such. The selection, the interpretation and the conclusions are mine.

Sources

  • Ernst & Young LLP (EY US): AI Risk and Governance Survey. Online survey of 202 US executives at listed companies with at least USD 1bn revenue, fielded 28 May to 15 June 2026, margin of error ±7 percentage points. Press release of 15 September 2026. Commissioned by EY's assurance practice. ey.com
  • Wenger, S. (Glass Lewis): US AI Oversight Through Three Lenses: Investor Expectations, the S&P 100 and Company-Specific Analysis. Harvard Law School Forum on Corporate Governance, 11 March 2026. Analysis of S&P 100 proxy statements for 2025. corpgov.law.harvard.edu
  • Zeru, H. / Schultz, A. (ISS STOXX): Mind the Governance Gap: The State of Board Oversight and AI Policy in U.S. Companies, 3 March 2026. Disclosure analysis of 3,048 Russell 3000 and S&P 500 companies, data as of January 2026. iss-stoxx.com
  • Dotan, R. / Gershoni, T. / Hadar, I. / Luria, G.: Decoupling in AI ethics: Learning how to walk the talk. Empirical Software Engineering 31, article 131, online 30 April 2026, DOI 10.1007/s10664-026-10861-z. 32 semi-structured interviews, June to November 2024. doi.org
  • Frimpong, V. / Botchey, O. K.: Where Are the AI Governance Roles? Businesses 6(2), article 18, April 2026, DOI 10.3390/businesses6020018. Online survey of 351 organisations; snowball sampling, self-report. doi.org
  • Meyer, J. W. / Rowan, B.: Institutionalized Organizations: Formal Structure as Myth and Ceremony. American Journal of Sociology 83(2), 1977, pp. 340–363, DOI 10.1086/226550. doi.org
  • Bromley, P. / Powell, W. W.: From Smoke and Mirrors to Walking the Talk: Decoupling in the Contemporary World. Academy of Management Annals 6(1), 2012, DOI 10.5465/19416520.2012.684462. doi.org
  • Stanford Institute for Human-Centered AI: The 2026 AI Index Report, chapter 3 “Responsible AI”, 2026. Incident figures from the AI Incident Database; the limits of the series are stated there. hai.stanford.edu
  • Eurostat: 20% of EU enterprises use AI technologies, 11 December 2025. Official EU ICT enterprise survey, reference year 2025, enterprises with ten or more employees. ec.europa.eu
  • Federal Statistical Office of Germany: Enterprises using artificial intelligence technologies by employee size class, as of 24 November 2025, reference year 2025. destatis.de
  • Regulation (EU) 2024/1689 (AI Act), Art. 4 and Art. 99; Art. 4 and Art. 113 as amended by Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026. eur-lex.europa.eu
  • ISACA: AI Use Accelerates While Governance and ROI Lag, 5 May 2026 — survey of more than 3,400 professionals in IT audit, governance and information security; a self-selecting membership survey. 90 per cent believe staff are using AI, 38 per cent report a comprehensive policy, against 28 per cent a year earlier. isaca.org
  • German Federal Ministry for Digital Affairs: Neues KI-Gesetz tritt in Kraft, 29 July 2026 — the AI market surveillance and innovation act, with the Bundesnetzagentur as national market surveillance authority and point of contact. bmds.bund.de
  • Schulz, A. / Bohne, J. P. P.: Art. 4 KI-VO — KI-Kompetenz, revised September 2026, on the absence of Art. 4 from the penalty catalogue and on indirect consequences. itmr-legal.de

This article offers a professional assessment and does not replace legal advice on an individual case.

Mario A. Brückner

Mario A. Brückner

Keynote speaker and founder of CALADE GmbH. Works with organisations in business and public administration on transformation, strategy and the practical adoption of AI. Creator of the Living Transformation® method.

This topic as a keynote.

“the governance gap: from policy to effective oversight” — as a keynote for boards, supervisory bodies and compliance functions.