92% of Firms Use AI Daily, But Only 42% Have Formal Policies
ISACA research exposes a widening gap between enterprise AI deployment and the governance structures needed to manage risk and accountability.
Deployment outpaces oversight
Artificial intelligence has moved from pilot projects to production at breakneck speed, but the management frameworks meant to govern it have not kept pace. According to the ISACA 2026 AI Pulse Poll, 92% of surveyed organizations now use AI in daily operations, yet only 42% have established a comprehensive, formal policy to guide employee use of these systems.
The gap extends beyond policy. Thirty-five percent of respondents cannot confirm whether their organization has been targeted by an AI-driven cyberattack, and 59% of security leaders admit they do not know how quickly they could shut down an AI system in the event of a breach. These findings, first reported by Cyber Magazine, underscore a troubling reality: enterprises are embedding AI deeply into workflows without the visibility or control mechanisms required to manage the associated risks.
Why it matters
As AI systems take on more critical business functions—from customer interactions to financial forecasting—the absence of governance creates both operational and reputational exposure. The International Monetary Fund has flagged AI-driven cyber threats as a potential systemic risk to global financial stability, signaling that software vulnerabilities now carry enterprise-wide consequences. For boards and executives, AI is no longer an IT issue—it is a strategic business imperative that demands accountability, resilience, and trust.
Leadership and skills gaps persist
Only 38% of organizations have appointed a specific executive or board member to oversee AI risk, according to the ISACA poll. Meanwhile, a third of companies do not require employees to report their use of AI tools, enabling "shadow AI" practices that erode enterprise visibility and increase exposure.
Workforce readiness is equally concerning. While 79% of professionals believe they will need to upskill in AI within the next year, 21% of organizations offer no formal training. Chris Dimitriadis, Chief Global Strategy Officer at ISACA, emphasized that organizations must move beyond "minimal compliance" and toward demonstrable governance and accountability.
To address the skills deficit, ISACA is launching three advanced professional certifications designed for leaders responsible for securing and auditing AI systems:
- AAIA (AI Audit): Validates expertise in evaluating governance models, internal controls, and regulatory compliance.
- AAIR (AI Risk): Equips risk officers to identify, analyze, and mitigate exposure across AI lifecycles.
- AAISM (AI Security Management): Focuses on protecting against AI-enabled threats while enabling secure adoption.
These credentials aim to translate governance principles into practical capability, helping organizations strengthen resilience without stifling innovation.
Building governance that scales
The ISACA findings make clear that sustainable AI adoption requires more than technical deployment. It demands unified oversight spanning audit, cybersecurity, risk, compliance, and legal functions. As regulatory expectations rise—particularly in the UK and EU—global organizations face mounting pressure to demonstrate corporate accountability and operational resilience.
ISACA will explore these themes further at its Europe Conference in Munich, Germany, from October 7 to 9, 2026, bringing together international speakers for sessions on AI governance, assurance, cyber resilience, and digital trust.
Details were first reported by Cyber Magazine based on the ISACA 2026 AI Pulse Poll.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
