Most enterprises have deployed AI into daily operations, but the governance structures needed to manage the risks have not kept pace. The ISACA 2026 AI Pulse Poll, released September 7, finds that while 84% of organisations now use AI across their business, only a third maintain a formal policy directing how employees should use it. That gap is pushing AI governance from an IT concern to a board-level business priority.
Chris Dimitriadis, Chief Global Strategy Officer at ISACA, said organisations need to move beyond "minimal compliance" and towards demonstrable governance and accountability. The shift matters because the financial and operational stakes are rising. The International Monetary Fund has flagged AI-driven cyber threats as a potential systemic risk to global financial stability.
The governance gap in numbers
The ISACA data reveals multiple pressure points. Thirty-six percent of security leaders say they are worried about AI-driven threats, and 37% of organisations report a lack of secure practices across their AI initiatives. When incidents happen, response capability is uncertain: 35% of security leaders cannot confirm whether their organisation has already been hit by an AI-driven cyberattack, and 59% said they would not know how quickly they could shut down an AI system if a breach occurred.
Reporting channels remain weak. Only 42% of organisations have processes that let employees flag AI incidents, and 41% are unsure they have the right procedures. Just 33% conduct thorough AI risk assessments before deployment. Leadership accountability is thin too - 38% have appointed a specific executive or board-level owner for AI risk. A third of organisations do not require employees to report their use of automated tools, creating unmonitored "shadow AI" that reduces enterprise visibility.
Skills shortages compound the risk
Workforce readiness is another pressure point. Seventy-nine percent of professionals believe they will need expanded skills within the next year, but the pipeline for those skills remains narrow. ISACA is responding with three new professional credentials aimed at teams responsible for securing and auditing machine learning frameworks.
The qualifications target distinct roles. AAIA (AI Audit) validates expertise in evaluating governance models, internal controls, and compliance requirements. AAIR (AI Risk) equips risk officers to deliver rapid, board-ready assessments of AI technologies. AAISM (AI Security Management) focuses on mitigating AI-driven cyber threats for security leaders. For executives building internal capability, these programmes offer a path to close the expertise gap without relying entirely on external hires.
ISACA will also place greater emphasis on governance at its Europe Conference in Munich from 7 to 9 October 2026, with sessions on digital trust, audit, and resilience.
Why this matters for executives and strategy
Corporate strategy is being forced to shift from rapid AI deployment to unified oversight that spans audit, security, risk, compliance, and legal functions. The ISACA findings show that most organisations have not yet made that shift. Boards that treat AI governance as a compliance checkbox rather than a strategic capability are carrying risk they cannot see - and in many cases, cannot measure. For senior leaders, the immediate task is building the internal frameworks and AI governance for executives expertise that turns accountability from a principle into an operational reality.
Your membership also unlocks: