There is a real distance between how far along companies feel on AI governance and how far along the evidence says they are. A new survey from Schellman, published July 29, 2026, put a number on the distance between confidence and capability, and it is the single most useful read for any leader trying to figure out whether their AI program is real or just busy.
Here is the finding. Schellman asked 525 U.S. professionals who evaluate, deploy, secure, or govern AI at large companies whether they could pass an AI compliance audit today. Seventy-four percent said yes. When the same survey asked whether their AI governance program was fully mature, only 27 percent said yes. Three in four feel ready. Barely one in four have operationalized the thing that would make them ready.
Because Schellman is a compliance and attestation firm (the release describes it as the first ANAB-accredited ISO 42001 certification body and the first authorized AIUC-1 auditor), read these numbers as a vendor's survey of its own market. The methodology is transparent, which helps: respondents came from large companies with 500 or more employees, fielded by Researchscape between April 13 and May 11, 2026, results unweighted. The pattern it describes lines up with what a lot of leaders already feel in their gut.
Spending money is not the same as building capability
Ninety percent of the organizations in the survey have already allocated funding for AI governance. That one is worth your attention. The money is committed. The intent is there. And yet the maturity number sits at 27 percent, which tells you the budget is going out the door faster than the operational discipline is coming together.
You can see the same split in the specific controls:
- 57 percent maintain a formal AI governance policy
- 64 percent have a formal AI acceptable use policy that is actively communicated to employees
- 44 percent maintain AI-specific incident response procedures
So a little more than half have written the policy down, and fewer than half have a plan for what happens when an AI system does something it should not. Meanwhile, 86 percent have tested or piloted AI agents and 46 percent already have agents running in production. The tools are moving into daily operations faster than the guardrails are being built around them.
This is the trap the study names most clearly: confusing motion for maturity. Buying a tool, funding an initiative, and running a pilot all feel like progress. They are activity, not capability. Danny Manimbo, who leads Schellman's ISO and AI practice, put it this way: "Organizations are not struggling because they lack awareness of AI governance. The challenge is turning those individual activities into a mature, operationalized program."
The number that should change how you sequence your bets
Here is the finding that recasts governance from a cost center into a growth lever. Among organizations with mature governance, 78 percent are running AI agents in production. Among organizations still developing their programs, only 22 percent are.
Read that again, because it inverts the usual assumption. The instinct is to treat governance as the brake and deployment as the accelerator, as if the responsible thing and the fast thing pull against each other. The data points the other way. The companies that did the unglamorous work (the policy, the incident response plan, the acceptable use standard communicated to actual employees) are the same companies actually shipping AI into their operations. Governance is what lets them move without flinching.
That correlation does not prove causation, and a survey cannot. But the practical read for a leader placing bets is straightforward. If you want AI agents doing real work in your business, the governance program is closer to the foundation you build first so the deployment holds.
Where accountability lives, and where it goes quiet
Two more findings are worth knowing before your next board conversation.
First, accountability concentrates almost entirely in IT. Forty-two percent of respondents say the CIO or Head of IT is mainly responsible for AI purchasing decisions, and 37 percent say that same person is ultimately accountable for AI-related risk. That can work, but it is worth asking whether one function should own both the buying and the risk, especially as AI spreads into marketing, sales, HR, and finance where the CIO has limited line of sight.
Second, the board conversation is uneven. Fifty-four percent report AI governance to boards or executive leadership on a regular basis, which is a healthy number. But only 36 percent of boards regularly discuss third-party AI risk. Given that most AI in most companies arrives through a vendor rather than a homegrown model, that is a quiet blind spot. The risk is coming in through the supply chain, and roughly two-thirds of boards are not looking at it on a regular cadence.
Regulatory readiness is lopsided
The survey also shows how uneven preparation is across jurisdictions. Eighty-nine percent of organizations say they have prepared for U.S. AI regulations. Only 29 percent have prepared for the EU AI Act, and just 12 percent for Asia-Pacific requirements. For a company with any international exposure, that is a real exposure to size. The home-market rules feel close and get attention; the rules that apply the moment you serve a customer abroad have barely been touched.
What this means if you feel behind
If you are a leader who suspects your organization is behind on AI, the honest takeaway from this study is oddly reassuring: most of your peers only feel ready. The confidence is widespread. The operationalized capability is rare. That means the durable advantage is being one of the few who can actually prove the program works.
This is exactly why measurement beats confidence. In The 7 Levels of AI Proficiency, the difference between an early level and a high one is demonstrated, repeatable capability that holds up when someone independent looks at it. A company can allocate budget, run pilots, and still sit at a low level of real proficiency, because none of those activities prove the organization can do the work reliably. Self-assessment overstates readiness by a wide margin, which is the whole story of the 74-versus-27 split.
Customers, regulators, boards, and business partners are no longer asking whether organizations are thinking about governance, they want proof that governance is working.
Avani Desai, Schellman's CEO, named the change that is coming for every leader: "Customers, regulators, boards, and business partners are no longer asking whether organizations are thinking about governance, they want proof that governance is working."
Proof is the operative word. Feeling ready is common. Being able to show it is the thing that separates the companies putting AI to work from the ones still talking about it.
Next step
Before your next AI budget decision or board update, ask one question and answer it honestly: could we prove our AI program works if someone independent looked at it this week? Not "have we funded it" and not "are we piloting things," but could we show the policy, the incident response plan, and the record of who is accountable. If the answer is anything short of a clear yes, that is where the next dollar and the next month of attention belong.
Related reading: Level 6: The Admiral (Systems Integrator).
Sources
- New Schellman Research: 74% of Enterprises Say They Are Audit-Ready for AI, Only 27% Actually Are (GlobeNewswire)
- New Schellman AI Research Report (Schellman news blog)
- Why Organizations Aren't Audit-Ready for AI (Schellman AI governance blog)
Frequently Asked Questions
What did the Schellman study actually measure?
Schellman surveyed 525 U.S. professionals involved in evaluating, deploying, securing, or governing AI at large companies with 500 or more employees. The survey ran from April 13 to May 11, 2026, and results are unweighted. Because Schellman sells compliance and attestation services, treat the findings as a vendor's research of its own market, with a transparent methodology.
Why is the 74 percent versus 27 percent number worth your attention?
It quantifies the distance between how ready companies feel and how ready they are. Seventy-four percent believe they could pass an AI compliance audit today, while only 27 percent describe their governance program as fully mature. The lesson is that confidence and self-assessment routinely overstate genuine capability.
Is governance really tied to actually using AI?
The survey found that 78 percent of organizations with mature governance run AI agents in production, versus 22 percent of those still developing their programs. Correlation, not proof of cause, but it suggests the companies doing the governance work are also the ones shipping AI into real operations.
Find your AI Proficiency level
The free 7 Levels assessment places you across seven stages of AI capability. Under ten minutes. Research-backed scoring.