Finance Accounting Marketing Human Resources Sales Corporate Governance Technology Startup Procurement Law
Select Page

What Did the 2026 Smarsh-FTI Study Find About AI Governance?

The July 2026 Smarsh-FTI Consulting Enterprise AI Trends Study found that 55% of enterprises are actively deploying AI, but only 26% say their governance frameworks are fully aligned with the pace of that deployment.

⚡ TL;DR
Q: Are boards keeping up with AI adoption inside their companies?
No. New research shows 55% of enterprises are deploying AI, but only 26% say governance is keeping pace, and just 30% can reliably detect unauthorized “shadow AI” tools in use across the business.

The gap between AI deployment and AI governance is no longer a theoretical risk. It is now a documented, quantified board-level exposure, arriving in the same month that U.S. securities regulators are actively revisiting disclosure rules that determine what companies must tell investors about exactly this kind of risk.

Why Is Shadow AI a Growing Board-Level Risk?

Shadow AI refers to AI tools employees use outside approved workflows, and only 30% of organizations in the Smarsh-FTI study report having comprehensive capability to detect and manage it, leaving most boards without visibility into a significant operational risk.

Unlike sanctioned AI deployments, shadow AI use typically has no audit trail, no data governance review, and no accountability structure if it produces an error, a data leak, or a compliance breach. For risk committees, this creates a disclosure problem: a company cannot represent that its AI risk controls are adequate if it cannot first confirm the full scope of AI tools actually in use across the organization. This is the same “last-mile” visibility gap covered in kurums.com’s reporting on HR’s declining confidence in AI as adoption peaks.

Where Is Enterprise AI Investment Actually Going?

The Smarsh-FTI study found 62% of enterprises are investing in AI and machine learning capabilities, 53% in data quality and enrichment, and 51% in modernizing recordkeeping and archives, showing spending is concentrated on capability, not controls.

2026 Enterprise AI: Investment vs. Governance Readiness AI/ML investment 62% Data quality investment 53% Recordkeeping investment 51% AI deployment overall 55% Governance aligned 26% Shadow AI detection ready 30%
Source: Smarsh × FTI Consulting, 2026 Enterprise AI Trends Study (released July 7, 2026).

The imbalance is the core finding: capability spending (62%, 53%, 51%) outpaces governance readiness (26%, 30%) by a wide margin. For audit and risk committees, this is a clear signal that the standard board question — “how much are we investing in AI?” — needs to be paired with “how much are we investing in controlling it?” to get an accurate risk picture.

How Is the SEC Responding With Disclosure Reform?

SEC Chair Paul Atkins flagged Regulation S-K reform as a priority at the July 9, 2026 Society for Corporate Governance Conference, including a possible “materiality overlay” that would let companies omit disclosure of non-material line items.

Separately, the SEC’s proposed liberalization of Form S-3 — easing automatic-effectiveness qualification for issuers with 12 or more months of reporting history — had its public comment period close on July 27, 2026. Neither proposal targets AI governance directly, but both reshape the disclosure environment boards will operate in while deciding how much AI risk detail to include in filings. A materiality overlay, in particular, raises the stakes of correctly judging whether an AI governance gap like the one Smarsh-FTI documented counts as material to investors.

💡 Pro Tip: Ask management for a shadow AI inventory before your next audit committee meeting. If the company cannot produce one, that gap is itself a governance finding worth documenting in committee minutes.

What Should Boards Do to Close the AI Governance Gap?

Boards should require a documented AI inventory, assign clear governance ownership, and set a recurring review cadence, rather than treating AI oversight as a one-time policy approval at rollout.

  1. Commission a full AI inventory: Include both sanctioned deployments and known or suspected shadow AI use across departments.
  2. Assign governance ownership: Designate a specific committee or executive accountable for AI risk, rather than leaving it split across IT, legal, and business units.
  3. Set a review cadence: Reassess AI governance quarterly, not annually, given how fast deployment is outpacing the 2026 baseline data.
  4. Align disclosure with materiality: Work with counsel to determine whether current AI governance gaps meet the threshold for investor disclosure under evolving SEC guidance.
  5. Track cross-functional risk: Coordinate with HR and risk teams, since AI-related workforce decisions and AI governance gaps are frequently linked, as seen in reversed AI-driven layoffs.

How Does This Connect to Other 2026 Regulatory Moves?

Banking regulators — the FDIC, OCC, and NCUA — issued interagency guidance on July 13, 2026 requiring supervised institutions to factor legal work-authorization status into credit risk assessments, part of a broader 2026 pattern of regulators formalizing risk data requirements faster than many institutions can operationalize them.

Taken together with the Smarsh-FTI findings and the SEC’s disclosure review, the pattern across 2026 is consistent: regulators and researchers are converging on the same conclusion from different directions — that enterprise risk data and controls infrastructure has not kept pace with either AI adoption or evolving compliance requirements. Boards that treat these as separate, siloed issues risk missing how closely connected they actually are.

Why Are AI Governance Gaps Emerging Now, in 2026, Rather Than Earlier?

AI governance gaps are surfacing now because enterprise AI adoption accelerated faster between 2024 and 2026 than internal risk, legal, and compliance functions could staff up to match, leaving controls infrastructure built for a slower rollout pace.

Most large organizations built their existing risk governance frameworks — model risk management, third-party vendor review, data privacy controls — around a much slower cadence of technology adoption, often measured in years per major system. Generative and agentic AI tools have compressed that adoption cycle to months, with individual departments frequently procuring or building tools without going through the same review cycle a core system would require. The Smarsh-FTI study’s headline numbers are, in effect, a measurement of that mismatch: 62% of enterprises investing in AI/ML capability against just 26% reporting governance that has kept pace is the direct byproduct of speed outrunning process. Boards that treat this as a temporary transition problem, rather than a structural one requiring permanent investment in faster-moving governance functions, are likely to see the gap persist into 2027 rather than close.

Frequently Asked Questions

What percentage of companies have AI governance aligned with deployment?
Only 26% of enterprises say their governance frameworks are fully aligned with the pace of AI deployment, according to the Smarsh-FTI Consulting 2026 Enterprise AI Trends Study released July 7, 2026.

What is shadow AI and why does it matter for governance?
Shadow AI is the use of AI tools outside approved company workflows. Only 30% of organizations can reliably detect and manage it, creating a visibility gap that undermines accurate risk disclosure and audit oversight.

Is the SEC changing AI-related disclosure requirements in 2026?
The SEC has not issued AI-specific disclosure rules, but Chair Paul Atkins’ July 2026 remarks on Regulation S-K reform and a possible materiality overlay directly affect how boards judge whether AI governance gaps require investor disclosure.

What is the first step a board should take to close its AI governance gap?
Commission a documented inventory of both sanctioned and shadow AI use across the organization — most boards cannot close a governance gap they have not first measured.

⚠️ Warning: Regulatory guidance on AI disclosure is evolving quickly. Confirm current SEC and banking-regulator positions with counsel before finalizing board reporting language based on this article.

How Should Audit Committees Question Management on AI Risk?

Audit committees should move beyond asking whether an AI policy exists and instead ask for evidence: inventory completeness, detection coverage for unsanctioned tools, and a named owner accountable for closing identified gaps.

A written AI policy alone does not address the finding that only 26% of enterprises have governance aligned with deployment — the gap in the Smarsh-FTI study is one of execution, not documentation. Committees should request quarterly evidence of the inventory being updated, ask how shadow AI detection coverage has changed since the last review, and confirm that governance ownership sits with a specific, named role rather than being distributed informally across departments. Questions framed this way surface real gaps instead of policy documents that look complete on paper but do not reflect operational reality.

This analysis builds on kurums.com’s coverage of audit quality scrutiny at the Big Four firms and Moody’s AI capex credit-risk warning, both of which reflect the same underlying theme: governance and controls infrastructure lagging behind the pace of AI-driven change.

✍️ Kurums.com Corporate Governance Desk · 📅 Son Güncelleme / Last Updated: July 30, 2026 · Sources: Smarsh × FTI Consulting 2026 Enterprise AI Trends Study, Harvard Law School Forum on Corporate Governance, SEC public statements, Corporate Compliance Insights.


Discover more from Kurums | Business Intelligence

Subscribe to get the latest posts sent to your email.

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Kurums | Business Intelligence

Subscribe now to keep reading and get access to the full archive.

Continue reading