The 81% Problem: Why Most AI Deployments Are Flying Blind
Return to Part 0: Table of ContentsPrevious Article: Part 4
Flying blind.
A chief information security officer at a financial services firm told me late last year that her team had discovered, almost by accident, that the marketing department had been feeding customer segmentation data into ChatGPT for six months. Not maliciously. Not even carelessly. They were trying to write better campaign copy. Nobody had told them not to. When she pulled the logs, three other teams were doing the same thing with different tools. The firm had an AI policy. It had been approved by the board, formatted beautifully, and published on the intranet. Nobody had read it.
Her story is not unusual. It is the norm.
The World Economic Forum's 2025 Responsible AI Playbook found that 81 per cent of companies remain stuck in the earliest stages of AI governance maturity. Fewer than one per cent have reached full maturity. [1] At the same time, 88 per cent of organisations now report using AI in at least one business function. [2] Nearly nine in ten organisations have deployed AI. Fewer than one in a hundred govern it properly. The gap between those two numbers is not a rounding error. It is the single largest unpriced risk on most enterprise balance sheets in 2026.
The previous chapter showed what digital assembly lines can do when they work: legal review costs dropping from several dollars per page to under a dollar, cycle times compressing by 30 to 40 per cent, knowledge work being decomposed into sequenced agent chains. Those are real gains. But they carry a question that most organisations have not yet answered: who is watching the machines?
This chapter examines three dimensions of the governance gap: opacity in AI decision-making, the explosion of shadow AI, and the systemic fragility that results when adoption runs years ahead of oversight. The evidence is drawn from global surveys, recent incidents, and the regulatory frameworks now being enforced. The conclusion is uncomfortable but actionable: governance is not the brake on AI value. It is the precondition.
The Governance Gap: What It Means and Why It Persists
Governance, in the context of enterprise AI, means the policies, processes, and oversight structures that ensure AI systems behave as intended, comply with applicable law, and remain accountable to human decision-makers. It is not a compliance checklist. It is an operating system for trust. And in 2026, most organisations do not have one.
McKinsey's November 2025 State of AI survey found that only 28 per cent of organisations have their CEO directly responsible for AI governance. Board-level oversight sits at just 17 per cent. [2] Deloitte's 2026 enterprise survey is blunter: only one in five companies has a mature governance model for autonomous AI agents. [3]
The persistence of this gap is not a mystery. Three forces sustain it.
First, speed. Enterprise AI adoption has moved faster than any technology wave McKinsey has tracked in eight years of surveying. Usage went from early experimentation to 88 per cent adoption in roughly three years. Governance structures, which require cross-functional coordination, legal review, technical tooling, and cultural change, cannot be built at that pace. The technology shipped before the guardrails were designed.
Second, fragmentation. AI is not a single system that a single team can govern. It is embedded across functions: marketing, finance, HR, engineering, customer service. Each function adopts different tools, from different vendors, at different speeds. Zscaler's January 2026 AI Security Report found that the number of applications driving enterprise AI transactions quadrupled year-on-year to more than 3,400. [4] No governance team was built to monitor 3,400 applications.
Third, the illusion of policy. Many organisations believe they have governance because they have published a policy document. IBM's 2025 Cost of a Data Breach study tested that assumption. Among organisations that experienced an AI-related breach, 63 per cent had no AI governance policy at all. Of those that did, only 34 per cent performed regular audits for unsanctioned AI use. [5] A policy that nobody enforces is not governance. It is theatre.
Shadow AI: The Risk You Cannot See
Shadow AI, the use of AI tools by employees without formal IT approval, is now the single fastest-growing category of enterprise risk. IBM's 2025 report quantified the cost for the first time: one in five data breaches involved shadow AI, and those breaches cost organisations an average of US$670,000 more than standard incidents. [5] Among breached organisations that had experienced an AI-related security incident, 97 per cent lacked proper access controls.
The employee behaviour data tells a consistent story across every major survey conducted in 2025 and early 2026. Microsoft and LinkedIn's Work Trend Index found 78 per cent of AI users bring their own tools to work. [2] BlackFog's January 2026 study of 2,000 UK and US employees found 86 per cent use AI weekly, with roughly half using tools their employer has not sanctioned. [6] The pattern holds regardless of sample, geography, or methodology. Shadow AI is not an edge case. It is the default.
There are early signs of improvement. Netskope's January 2026 data shows the share of employees using personal AI accounts has dropped from 78 per cent to 47 per cent, and company-approved accounts have risen from 25 per cent to 62 per cent. But the average company still experiences 223 data policy violations per month. The trajectory is encouraging; the gap remains large.
The data volumes are staggering. Zscaler measured 18,033 terabytes of enterprise data flowing to AI and ML applications in 2025, a 93 per cent increase year-on-year. That is roughly equivalent to 3.6 billion photographs. ChatGPT alone triggered 410 million data loss prevention policy violations, including attempts to share social security numbers, source code, and medical records. [4]
This is not employees being reckless. It is employees being rational. When approved enterprise tools are slow to deploy, limited in capability, or buried behind weeks of procurement process, workers reach for the tools that help them do their jobs. More than 60 per cent of employees surveyed by BlackFog believe using AI without IT oversight is acceptable when no company-approved alternative exists. [6] The demand signal is clear. Governance that blocks without providing alternatives does not stop shadow AI. It merely drives it underground.
Governance Failures in the Wild
The consequences of the governance gap are no longer theoretical. 2025 produced a series of governance failures that illustrate the breadth of the problem, from consulting firms to courtrooms to national security agencies.
In October 2025, Deloitte submitted a government report to Australia's Department of Employment and Workplace Relations containing fabricated citations and misquoted legal references generated by AI. A University of Sydney researcher discovered the fabrications because he personally knew the cited authors and knew they had never written the attributed works. The report was subsequently revised with a disclosure acknowledging that AI had been used to address documentation gaps. Forrester's analysis was direct: the incident reflected broader challenges as enterprises scale AI without mature governance. [7] The irony that one of the world's largest governance advisory firms was caught by the very gap it advises clients on was not lost on the industry.
In July 2025, the acting director of the US Cybersecurity and Infrastructure Security Agency uploaded documents marked for official use only into the public version of ChatGPT, despite the tool being blocked for most CISA employees. The incident triggered automatic security alerts and a Department of Homeland Security internal audit. [8] When the person responsible for defending national cybersecurity infrastructure cannot resist the convenience of a public AI tool, the governance gap is not just an enterprise problem. It is a systemic condition.
The AI Incident Database's late 2025 roundup documented governance failures across every domain. An Argentine court annulled a conviction after a judge used ChatGPT without disclosure. A Canadian federal tax chatbot gave incorrect guidance at scale. An Italian court dismissed a case entirely and imposed financial penalties after an AI-drafted legal submission contained fabricated citations. A Belgian university rector used fabricated AI-generated quotes in a public speech. [8] Each incident follows the same pattern: a capable tool used without verification, oversight, or accountability structures.
Stanford's HAI AI Index found that publicly reported AI-related security and privacy incidents rose 56.4 per cent from 2023 to 2024. [9] The incidents are accelerating. The governance response is not.
Gutenberg's Governance Problem
The printing press created the same structural dilemma. Johannes Gutenberg's technology democratised access to information, but it also democratised the capacity for harm. Within decades of the press spreading across Europe, governments faced an explosion of unauthorised pamphlets, forged documents, and heretical texts that no existing governance framework was designed to handle.
The response was predictable and instructive. Some authorities tried prohibition: banning unlicensed printing, burning books, punishing printers. It did not work. The technology was too useful and too distributed. The authorities that succeeded were those that built governance around the technology rather than against it: licensing systems, quality standards, institutional review. They did not try to stop the press. They built the structures to govern what came off it.
The parallel to 2026 is precise. Organisations that attempt to ban AI tools will fail. The employees have already adopted them. The organisations that will govern AI successfully are those building oversight into the workflow itself: approved tool catalogues, data classification, automated monitoring, and human review at decision points. Governance as infrastructure, not governance as prohibition.
What Governance That Works Actually Looks Like
The gap between the 81 per cent and the fewer-than-one-per-cent is not bridged by policy documents. It is bridged by operational controls. Here is what the evidence says works.
Know what you have. You cannot govern AI you cannot see. Zscaler's 2026 report found that most organisations still lack a basic inventory of AI models and embedded AI features operating inside their enterprise. [4] The first governance action is discovery: mapping every AI tool, every embedded AI feature in your SaaS stack, every data flow to external AI services.
Provide what employees actually need. Shadow AI thrives where approved alternatives are absent or inadequate. Deloitte's enterprise survey found that the AI skills gap is the biggest barrier to integration. [3] Organisations that deploy enterprise-grade AI tools with proper data governance, and make them easy to access, reduce shadow AI by giving employees a path that is both productive and safe.
Monitor continuously, not quarterly. IBM found that AI-related security incidents take 26 per cent longer to identify than standard breaches. [5] Quarterly policy reviews cannot detect a data leak that happens in minutes. Governance for AI must operate at the same speed as AI itself: continuous monitoring of data flows, automated alerting on policy violations, real-time logging of AI interactions.
Put humans at decision points, not at every step. McKinsey's research identified that high-performing organisations are distinguished by having defined processes for when model outputs need human validation. [2] The goal is not to review every AI output. It is to ensure that consequential decisions, those affecting people's money, health, rights, or employment, have human review before they become final.
In New Zealand, structured AI governance guidance exists at the central government level, but no equivalent of the IBM or Zscaler studies measures actual adoption across the enterprise landscape. The Government Chief Digital Officer's Responsible AI Guidance for the Public Service, published in February 2025, provides a structured lifecycle for AI governance: risk assessment, human oversight, transparency, and accountability. [10] The Privacy Commissioner's guidance on AI and the Information Privacy Principles sets out requirements including privacy impact assessments before deployment, human review prior to acting on AI outputs, and transparency about how AI tools process personal information. [11] The gap is that no study has yet measured actual AI use, shadow AI prevalence, or governance maturity across New Zealand's enterprises and agencies.
What data does exist tells a mixed story. Kordia's 2025 Business Cyber Security Report, surveying 295 large New Zealand organisations, found that 28 per cent of business leaders cite AI-generated attacks as a top concern, yet only six per cent reported an actual AI-related breach. [13] Sixteen per cent cited improper employee AI use as a key security challenge. The Institute of Directors' 2025 Director Sentiment Survey sharpened the picture further: 60.6 per cent of boards are working with management to understand AI's productivity potential, but only 16 per cent have adopted even basic policies to govern shadow AI. Meanwhile, the share of boards regularly discussing cyber risk actually fell, from 62.2 per cent to 57.2 per cent. [14] Boards are accelerating AI adoption while loosening the governance conversation. That is the 81 per cent problem in local terms.
The 2025 cross-agency AI survey reported 55 use cases in the operate stage, with barriers shifting from technology to skills, funding, and security. [12] But it measured declared use. No survey has yet measured undeclared use. In a country where the Ockham Book Awards disqualified two titles over AI-generated covers in late 2025, prompting a public backlash and policy reversal, the cultural tension around AI governance is already visible. The question is whether governance frameworks can scale from principle to practice before the global enforcement wave raises the stakes for every organisation operating across borders.
The Deadline Is August
The EU AI Act's high-risk system requirements become fully enforceable on 2 August 2026, with penalties reaching EUR 35 million or seven per cent of global turnover, pending legislative developments that could extend the timeline. [13] Colorado's AI Act takes effect in June. Texas's Responsible AI Governance Act is already in force. FINRA's 2026 Regulatory Oversight Report positions AI governance as a core compliance obligation for financial services. The SEC's 2026 examination priorities displaced cryptocurrency with AI and cybersecurity as the dominant risk concern.
The regulatory cliff has arrived. Organisations that have spent 2024 and 2025 experimenting with AI without building governance structures now have months, not years, to close the gap. For those operating across borders, the patchwork of state, national, and supranational regulations means that the strictest standard becomes the effective standard.
Eighty-one per cent of companies are in the earliest stages of governance maturity. The 2026 enforcement calendar does not grade on a curve. The organisations that treated governance as a future problem have just run out of future.
That CISO I mentioned at the start? She did not fire anyone. She did not ban ChatGPT. She built an approved tool catalogue in three weeks, deployed enterprise-grade AI with proper data controls, and made it easier to use than the shadow tools. Usage of unsanctioned tools dropped 70 per cent in the first quarter. The policy on the intranet did not change a thing. The infrastructure did. The question for the other 81 per cent is whether they will figure that out before the regulators do it for them.
Executive Takeaway
Run an AI inventory this quarter. Map every AI tool, embedded AI feature, and data flow to external AI services across your organisation. You cannot govern what you have not discovered.
Deploy approved AI tools that employees actually want to use. Shadow AI fills a demand gap. Enterprise-grade alternatives with proper data governance reduce unauthorised use by addressing the root cause, not the symptom.
Shift from periodic review to continuous monitoring. Implement automated data loss prevention for AI interactions, real-time alerting on policy violations, and continuous logging of AI data flows. Quarterly policy reviews cannot contain minute-speed data leaks.
Define where humans must remain in the loop. Not every AI output needs human review. Every consequential decision does. Map your high-risk decision points and build mandatory human checkpoints for outputs affecting health, money, rights, or employment.
Prepare for the August 2026 enforcement deadline. The EU AI Act's high-risk provisions take effect on 2 August 2026. If your AI systems touch EU citizens, customers, or partners, the compliance clock is running. Begin risk classification, documentation, and technical safeguards now.
Next week in Part 6: From Prompt to Intent, the shift from reactive AI tools to proactive autonomous agents, and why it changes everything about how we build, govern, and trust AI systems.
Your organisation has almost certainly deployed AI faster than it has governed it. What was the moment you first realised your governance was not keeping pace with your adoption, and what did you do about it?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape.
References
1. World Economic Forum. (2025). Advancing Responsible AI Innovation: A Playbook. WEF Reports. https://www.weforum.org/publications/advancing-responsible-ai-innovation-a-playbook/
2. McKinsey & Company. (2025, November). The State of AI 2025: Agents, Innovation, and Transformation. McKinsey Global Survey. https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
3. Deloitte. (2026). The State of AI in the Enterprise. Deloitte US. https://www.deloitte.com/us/en/what-we-do/capabilities/applied-artificial-intelligence/content/state-of-ai-in-the-enterprise.html
4. Zscaler. (2026, January 27). ThreatLabz 2026 AI Security Report. Zscaler. https://www.zscaler.com/campaign/threatlabz-ai-security-report
5. IBM. (2025, July). Cost of a Data Breach Report 2025. IBM Security / Ponemon Institute. https://www.ibm.com/reports/data-breach
6. BlackFog. (2026, January). Shadow AI Threat Research. BlackFog. https://www.blackfog.com/blackfog-research-shadow-ai-threat-grows/
7. Computerworld. (2025, October 8). "Deloitte's AI governance failure exposes critical gap in enterprise quality controls." Computerworld Australia. https://www.computerworld.com/article/4069521/
8. AI Incident Database. (2026, February). "AI Incident Roundup, November and December 2025 and January 2026." Responsible AI Collaborative. https://incidentdatabase.ai/blog/incident-report-2025-november-december-2026-january/
9. Stanford Institute for Human-Centered Artificial Intelligence. (2025). AI Index Report 2025. Stanford HAI. https://aiindex.stanford.edu/report/
10. Government Chief Digital Officer (NZ). (2025, February). Responsible AI Guidance for the Public Service: GenAI. New Zealand Digital Government. https://www.digital.govt.nz/standards-and-guidance/technology-and-architecture/artificial-intelligence/
11. Office of the Privacy Commissioner (NZ). (2024). AI and the Information Privacy Principles. Privacy Commissioner. https://www.privacy.org.nz/publications/guidance-resources/ai-and-the-information-privacy-principles/
12. Government Chief Digital Officer (NZ). (2025). 2025 Cross-Agency Survey of Use Cases for AI. New Zealand Digital Government. https://www.digital.govt.nz/
13. European Parliament and Council. (2024). Regulation (EU) 2024/1689 (AI Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Kordia. (2025, March). New Zealand Business Cyber Security Report 2025. Kordia / Aura Information Security. https://www.kordia.co.nz/cyber-security-report-2025
14. Institute of Directors New Zealand. (2025). Director Sentiment Survey 2025. IoD NZ. https://www.iod.org.nz/

