Governance is the least-ready capability in every survey that measures it, and the cause is misdirected effort rather than laziness: firms are writing policy where they need enforcement. A control builders can decline is not a control, and the vendor selling the governance tooling names that failure mode before anyone else does.
Why this matters
Take the readiness numbers in the order of their quality. Of four factors rated in a survey of 603 technology decision-makers, risk and governance controls came last: 12% fully ready, behind infrastructure at 20%, data and cybersecurity at 15% each. A separate survey of 623 found 11% very prepared on governance structures for agents and 55% somewhat prepared, implying about a third not prepared at all. And in the largest of the three, about one in five companies report a mature model for governing autonomous agents: 21%, against three-quarters planning agentic deployment inside two years. (Deloitte’s own outputs disagree on whether the denominator is all respondents or those planning deployment; use “about one in five companies surveyed.“)
The pattern behind those numbers is that firms are broadening access while moving in the opposite direction on enforcement. Almost everyone has a policy and fewer people have to ask anyone anything. In a US tracking survey of 801 enterprise decision-makers, explicit approval processes for gen-AI usage fell from 52% to 46%, a statistically significant drop, while 70% now allow all employees access and only 5% report no formal policy at all.
This wiki’s position is that the trend is mostly correct and the conclusion drawn from it is wrong. Per-use approval fails to scale and manufactures shadow agents; dropping it is right. What should replace it is a gate at promotion rather than a broader policy document: the moment an agent moves from personal to shared to production, where the population is small, the decision is discrete, and the reviewer can actually judge something.
The strongest citation available for that stance comes from a platform vendor arguing against its own product’s sufficiency. Microsoft’s published maturity model names “guidance-only, non-enforceable controls” as a universal governance anti-pattern, alongside no inventory and no owner, missing environment separation, and one-size-fits-all controls regardless of risk tier, which it says drives shadow AI when it over-restricts. It names governance theater as the characteristic Level-200 failure: formal process that adds overhead without improving security or operational outcomes, caused by a checkbox mentality. When the company selling governance tooling leads with that, a CTO who suspects this whole field is theater is in good company and should still act.
Do not build a parallel structure. The Three Lines Model the auditors already know came out of European risk-management practice around 2010, was adopted by the internal-audit profession in 2013, was rewritten in 2020 around six principles, and has since been superseded by a newer statement of position, so check the current one before citing a version. A 2022 mainstream framework already placed citizen developers in the first line, before anyone said “agent.” Extending an existing risk committee costs a paragraph in a charter; standing up an AI ethics board costs a year and produces a body that cannot stop a build. For a 20-to-500-person fund the honest shape is second line = compliance plus whoever owns the platform, third line = the existing audit arrangement.
Three findings that change how a firm reads its own numbers:
- A low incident count is evidence about detection rather than safety. In a survey of 1,993 organizations, AI high performers reported more negative consequences, concentrated in IP infringement and regulatory compliance, because they run more use cases, more mission-critical deployments, and more monitoring.
- Explainability is the second-most-experienced AI risk and is absent from the most-mitigated list. That is precisely the question an examiner asks: why did it do that, and who decided.
- Guardrails have to be wide enough for a car, not a bicycle. The practitioner is the head of citizen development at a finance-and-insurance firm in a 24-company study, the closest sector analogue in these sources. The failure he names is governance so narrow the sanctioned path stops being usable.
On accountability, the cleanest formulation available is that at least one human entity should be accountable for every uncompensated direct harm an agentic system causes. That is the whole argument for owner-of-record, and it comes from a model vendor’s own governance paper, written before tool-using agents were widely deployed.
Regulators pursuing rule clarity, market integrity and innovation can have at most two: the innovation trilemma, argued about fintech in 2019 and not softened by agents. That is the structural reason this stays hard. Waiting for clarity means waiting for someone to give up one of the other two.
Where you stand
| Level | Looks like | Cheapest next move |
|---|---|---|
| Crawl | No inventory, no named owner, and either no policy or one nobody can apply to a specific build. | One page: what requires approval, who grants it, and what the tiers are. Then start the registry — policy without inventory governs nothing. |
| Walk | A policy exists and applies uniformly. Approval happens by ad-hoc escalation. Evidence is assembled on request. | Tier, and make the bottom tier genuinely light on purpose. Uniform controls are the documented cause of shadow building. |
| Run | Tiers bound to named control sets; gates sit at zone transitions; the existing risk committee owns it; audit evidence is a by-product of the platform rather than a project. | Answer one examiner question end to end — why did this agent do that, on whose authority — and time yourself. |
| Fly | Policy expressed as enforceable configuration, governance metrics reported alongside adoption, and tier changes triggered by observed behaviour rather than by review. | Measure governance value, not governance activity: gate throughput, time-to-approval, and how many builds the gate actually changed. |
Concerns this dimension covers
- Shadow agents — what over-restriction and under-visibility produce.
- Agent sprawl — governance debt compounding with population.
- Recordkeeping and compliance gaps — the obligations that already apply, with no grace period for agents.
- Oversight decay — governance that erodes under volume.
- Regulatory exposure — the compliance-program rule that is chargeable on its own, before any incident.
- Agent disclosure and AI-washing — accuracy of what the firm told clients and regulators about the agents.
- Unreliable output acting on your systems — the failure that needs no attacker and no policy violation.
Controls that answer them
- Agent inventory and registry — the precondition for governing anything.
- Human approval gates — designed boundaries, placed where judgment is possible.
- Logging and audit — what the examiner will actually ask for.
- Cost controls — governance cannot prioritize what it cannot price.
- Grounded in: risk tiers and trust zones and why agents break application governance.
- Built as three-zone architecture: what makes a gate a border rather than a meeting.
Who sells it
- AI governance platforms — a category with no credible leader, which is a finding rather than a gap to fill.
- Comms archiving and surveillance — the regulated-firm mainstay, and what it still fails to capture about agents.
Sequencing and where this is checked
- Day 3 sequencing — visibility, then tiering, then gates.
- Promotion gates and risk-tier assignment — the recurring decisions.
- Compliance as an approver and when to involve legal and compliance — who signs, and when they get called.
- Exam readiness and supervisory review — what a regulator asks for, and the programme that produces the evidence.
- Registry review cadence and offboarding — the lifecycle end most programs skip.
- Staffed by the reviewer pool; frameworks mapped in frameworks.
Open questions
- No mainstream framework treats citizen developers as a distinct actor class. A 2022 toolkit places them in the first line and stops there; nothing addresses a builder with no engineering norms and production reach.
- Will allocators ask? “Your LPs will require auditable AI governance” is asserted in the practitioner literature with no evidence behind it. A single institutional operational-diligence questionnaire containing AI-governance questions would settle it, and for this audience it would matter more than any regulatory forecast.