Everyone in your organisation has already adopted AI. Copilot, ChatGPT, Claude, and (stay with me) Voicemod, the app that can make your colleague sound like Barry White mid-Teams call. Funny until you remember it’s also the tech behind a growing wave of voice-cloning fraud.

And it’s never just one tool. It’s a handful, adopted independently by different teams, with nobody quite tracking which. So here’s the real question: has anyone actually written down what “governed” means for any of it? Who’s accountable when something goes wrong? Is there a framework behind it? Does it have legal sign-off, compliance ownership or an actual policy? Or just goodwill and crossed fingers?

That’s the gap this piece is about. Even in businesses where AI use is widespread, most are running it without anything that could honestly be called a governance framework. The scale of that gap is stark: 88% of organisations are using AI. Only 8% have a comprehensive framework governing it.

Not Just a Policy Document

So, when we’re talking about AI, what does governance really mean, and what does it change?

Some people think they’ve already covered this with an AI policy document. That’s not the same thing as a governance framework. Most organisations have one of those already: an acceptable use policy, a set of principles, a slide that says, “use AI responsibly.” That’s a statement of intent. Governance is the operating discipline that makes the intent real: who decides what AI is allowed to touch, what has to be reviewed before it goes live, who’s accountable when something goes wrong, and how anyone would prove any of that happened.

Put simply, governance answers three questions a policy document doesn’t:

  • Decision rights: who has the authority to approve, block, or roll back an AI deployment, and at what point in its life?
  • Accountability: if an AI system makes a bad call, whose name is on that decision?
  • Evidence: could you show a regulator, a customer, or your own board exactly how a given AI use was reviewed and approved?

Why the Gap Exists

AI adoption happens fast, and it happens bottom-up: a team or user finds a tool that solves their problem this week and starts using it, often without asking anyone.

Governance, by contrast, is inherently slower and top-down: it needs a decision-maker, a framework, buy-in across functions. That makes it an afterthought by default, something you build once AI is already in use, not before. And by the time a framework is actually in place, the tools it was meant to govern have usually already moved on: new versions, new integrations, new ways teams have found to use them that nobody scoped for in the first place.

That mismatch has a measurable cost. Organisations with a formal AI strategy get double the success rate of those without one when it comes to moving a use case from pilot into production, yet only a minority of AI initiatives ever make that leap at all. Structure isn’t just slower to arrive than adoption; its absence is a large part of why so many AI projects stall before they’re ever finished.

What Happens When Nobody’s Watching

Three failure modes turn up again and again once you start looking for them.

  1. The app nobody reviewed. Someone in ops or finance builds a working tool with Claude or Copilot over a weekend, genuinely useful, genuinely unsanctioned. It touches customer data, or writes back to a live system, and nobody in security or IT knows it exists until it breaks something or shows up in an audit. Not malicious. Just never in scope for review.
  2. The agent with more reach than intended. An agent gets connected to a system to do one narrow task, pull a report, draft a reply, and inherits broader permissions than that task needed. It works fine for months. Then it takes an action nobody would have signed off on, and the postmortem finds the access was never the problem people thought to check.
  3. The model that quietly stopped being right. A pipeline that was accurate at launch degrades as the data it sees shifts, nothing crashes, nothing alerts, the outputs just get gradually less trustworthy. It keeps running, keeps producing plausible-looking answers, and the first sign anything’s wrong is a customer or a downstream team noticing the numbers don’t add up.

What “good” looks like

So, the pressing question: what does “good” actually look like?

A functioning governance framework isn’t a document; it’s a working system with three visible parts.

  1. A staged approval process, so an AI project moves through defined checkpoints on its way to production rather than going from idea to live deployment in one jump.
  2. A risk register, so the specific things that could go wrong with a given AI use are named and tracked, not assumed away.
  3. And a forum with genuine authority, a group that can actually say no to a deployment, not just advise on it.

The gap between having that and not having it is wider than most people assume. Fewer than a quarter of organisations have a mature governance model for AI agents specifically, and forecasts suggest well over 40% of agentic AI projects will be cancelled outright because the risk controls around them weren’t adequate.

Most AI governance writing is advisory, a view on what organisations should probably do. We’ve closed that gap ourselves, with the operations to show what governance actually looks like when someone builds it rather than advises on it. Independently assessed, we scored 3.8 out of 5 against an industry average of 1.9, and we’re happy to share that journey with customers.

Finding Out Where You Stand

The obvious next question is where your own organisation sits on that scale, and the honest answer is that most people don’t really know, because nobody’s measured it.

That’s what a proper AI governance assessment does: it benchmarks your current AI use against the same standards this piece has been citing- Deloitte, Gartner, NIST- and gives you an actual score, not a gut feeling. It’s the same methodology Acora used to score itself before turning it into something clients could use. Our team would be happy to talk through what that would look like for you.