Most Companies Can't Prove Their AI Governance Works, a New Report Finds

Regulated companies are racing to write AI rulebooks. Far fewer can prove the rules are being followed — and a new report warns that gap is about to collide with a wave of audits, investigations and regulatory deadlines.

Arctera, the compliance-software business spun out of Veritas Technologies, published its "State of AI Governance 2026" report this week, and its central finding lands like a warning shot. More than three-quarters of organizations using AI tools — 78% — expect their communications risk to rise over the next 12 to 24 months. Yet fewer than one in five, just 19%, say they have the controls needed to prove what actually happened when AI helped produce a message or a decision.

The report, based on a survey of 500 full-time compliance decision-makers and influencers across the Americas and EMEA, was conducted online in May by Hanover Research. Respondents came from finance, healthcare, and energy and utilities — sectors where records, decision-making and communications are already subject to intense regulatory scrutiny. The picture it paints is one of confidence outrunning capability.

On paper, many companies look ready. A little more than half, 55%, said they have core AI policies, training and human-review steps in place. And 71% of AI-using organizations described themselves as very or extremely prepared to produce a defensible audit trail. But that self-assessment rests on controls most of them have not built. The evidence layer — logging of prompts and outputs, automated retention, policy detection and automated risk scoring — is the part that lets an organization reconstruct after the fact who prompted a model, what it produced, who reviewed the output, where it went and whether the record was kept. Only 19% have it.

"Policies, training and human review remain essential, but they are no longer enough on their own," said Soniya Bopache, Senior Vice President and General Manager at Arctera. "As AI becomes an integral part of day-to-day work, organizations operating in regulated industries must be able to reconstruct the evidence behind AI-assisted communications and decisions."

The stakes are rising because AI is no longer a fringe experiment inside these firms. Nearly half of respondents, 45%, said AI is core to or extensively used in their regulated workflows. At the same time, 60% said their compliance function is now primarily accountable for AI governance — pushing responsibility onto compliance leaders, legal teams, chief information officers and risk executives who often lack the tooling to trace AI activity across channels.

Where those teams want to invest is telling. About 31% named AI oversight logging as a priority, and another 31% pointed to faster cross-channel search and reconstruction — a sign that firms increasingly want to trace what happened after an event, not just set policy before one. Legacy systems are being pressed into that role: 70% of respondents said their archives are a major or critical asset for AI-driven innovation, recasting old records platforms as source material for reviews, internal investigations and regulatory responses.

Bopache framed the fix as a shift in mindset rather than a bolt-on. "Moving from policy to proof means organizations must treat evidence as part of the AI workflow itself, not something to be recreated after the fact," she said. "This is the foundation of defensible AI governance."

Why It Matters

Arctera has an obvious commercial interest here — it sells the logging, retention and detection tooling the report says companies lack, with a platform it says draws from more than 130 content sources and ships with more than 280 AI policies. But the underlying gap is corroborated by the broader market mood: adoption of AI, and increasingly of autonomous agents, is sprinting ahead while the machinery to govern it lags well behind.

That mismatch is becoming a legal exposure, not just an operational one. Regulators are moving from principles to enforcement, and enforcement demands evidence. A company that cannot show how an AI-assisted decision was made — what data it drew on, whether a human reviewed it, how the record was preserved — is a company that cannot defend itself in an audit, a lawsuit or a regulatory inquiry. In finance, healthcare and energy, where "we think it was handled correctly" has never been an acceptable answer, the inability to reconstruct AI-assisted work is fast becoming its own category of risk. The report's core tension — 71% feeling prepared, 19% actually equipped — is precisely the kind of gap that surfaces only when someone official comes asking.

What to Watch

The pressure test is close. On Aug. 2, the European Union's enforcement toolkit for general-purpose AI models and its Article 50 transparency duties become active, handing regulators information-request and model-access powers. In the United States, a thickening patchwork of state laws — Illinois joined California and New York this month — is layering fresh documentation and audit expectations onto AI developers and deployers.

The question the Arctera data raises is whether "defensible AI governance" becomes the year's dominant compliance buzzword or its year's dominant enforcement story. Watch for the first regulatory action or audit in which a firm's inability to produce an AI evidence trail — not the AI output itself — is what gets it in trouble. On the survey's math, most organizations would struggle to pass that test today.

"Moving from policy to proof means organizations must treat evidence as part of the AI workflow itself, not something to be recreated after the fact. This is the foundation of defensible AI governance."
— Soniya Bopache, Senior Vice President and General Manager, Arctera
78%
Expect comms risk to rise
19%
Can prove what their AI did
55%
Have core AI policies
500
Compliance leaders surveyed