Large enterprises have spent the past two years building AI policies, committees and approval processes. A new EY survey suggests that the next governance problem is more operational: whether organisations can see, control and audit AI systems once they begin acting on their own.
EY commissioned an online survey of 202 US senior AI decision-makers at publicly traded companies with at least $1 billion in annual revenue. Ninety-eight per cent of respondents said their organisation has formal AI governance policies. Yet 47% said their organisation had previously bypassed its AI governance process for urgent deployments, while 36% reported an AI incident or failure that caused a materially negative impact.
The agentic AI findings are more revealing. Among respondents whose organisations use agentic AI, 49% said existing governance had not yet been specifically updated for agentic risks and 26% said their organisation could not detect unauthorised AI agents operating internally. The survey has a reported margin of error of plus or minus seven percentage points, so these figures should be read as evidence from this sample rather than as a census of enterprise AI.

Traditional AI governance has often focused on model selection, data use, bias, privacy and human review. Agentic systems add a different class of questions because software can call tools, retrieve data, trigger workflows and take actions across enterprise systems. That makes inventory, identity, permissions and observability part of governance rather than purely technical concerns.
The practical challenge is straightforward to state and difficult to implement. An organisation needs to know which agents exist, who owns them, which systems and data they can access, what actions they are allowed to take, how those permissions can be revoked and what evidence is retained after an action occurs. Governance committees can approve a use case, but they cannot govern an agent they cannot see.
The EY findings therefore point toward a second generation of enterprise AI governance. The first generation was policy-led: define acceptable use and establish oversight. The next is likely to be enforcement-led: connect those policies to identity, access controls, runtime monitoring, audit evidence and incident response.
For financial institutions and other highly regulated organisations, that transition matters because the cost of an autonomous error can be higher than the cost of a poor answer from a chatbot. As agents move closer to operational systems, governance will increasingly be judged by whether controls actually operated, not by whether a policy document existed.
