CEOs Urged to Own AI Governance as Gaps Widen

Many C-suite executives delay AI governance despite Grant Thornton’s 2026 AI Impact Survey finding 46% of organizations link AI underperformance to governance and compliance issues.

C-suite leaders are postponing formal AI governance even as Grant Thornton’s 2026 AI Impact Survey reports that 46% of organizations say governance and compliance issues cause AI to underperform. The survey calls on boards and chief executives to take responsibility rather than wait for uniform laws.

The report finds companies are deploying AI tools faster than they create rules for their use. More than 1,100 AI-related bills were introduced in U.S. state legislatures last year and about 130 became law. Federal action has been slower and European regulators are pursuing different standards, creating a fragmented regulatory picture. The report also notes a growing threat environment, including state-sponsored deepfakes and AI-generated disinformation aimed at reputations and operations.

Grant Thornton documents common operational gaps. Organizations often allow general-purpose AI assistants into daily workflows without clear limits. Information entered into those tools can be discoverable in litigation and may not be covered by legal privilege, the report says. That can expose sensitive legal conversations and erase protections companies may assume they have.

The report outlines three areas of focus for executive leadership. First, visibility into exposure: firms should map the data they hold, identify which datasets feed AI systems, and determine which state, federal and sector rules apply. Leaders should also assess potential consequences of a breach or misuse, including direct financial loss, regulatory fines, reputational damage and litigation risk.

Second, the report recommends flexible governance rather than static checklists. It advises adopting policy frameworks that can be updated quickly and using AI-assisted monitoring tools to track regulatory and threat developments across jurisdictions. Those tools can flag new requirements or emerging risks so internal processes and data policies can be adjusted.

Third, the report calls for rehearsed incident response for scenarios such as cyberattacks, data exposure or coordinated disinformation campaigns. Simulated crises give teams an opportunity to practice communication, containment and recovery steps and to coordinate action during the first hours of an event.

The report states that AI governance is no longer solely a legal or IT matter and that executive-level oversight can align technical capability with commercial risk and regulatory obligations. It presents building visibility, adaptive policies and incident rehearsals as components of an enterprise-level approach to AI use and risk management.

Articles by this author