Employees Are Using Unapproved AI Tools Across the Enterprise
What Happened — A 2026 OneTrust AI‑Ready Governance survey found that 74 % of respondents have departmental or organization‑wide AI adoption, yet many lack formal oversight. Only 17 % report governance “by design,” while 47 % encourage AI agents without fully defined controls.
Why It Matters for Trust & Control Assurance
- Unapproved AI tools bypass established risk‑classification and impact‑assessment processes, creating gaps in the control‑assurance evidence needed for audits.
- Inconsistent usage policies hinder continuous monitoring and defensible documentation of AI‑related decisions across the organization.
- The situation directly tests the control objective of AI lifecycle governance and usage controls, a single objective that maps to multiple frameworks (e.g., NIST AI RMF, ISO/IEC 42001).
Who Is Affected – Enterprises across technology, finance, healthcare, and other sectors that have enabled AI agents or generative‑AI services for employees.
Recommended Actions
- Conduct an inventory of all AI tools and agents in use, tagging each with ownership and risk level.
- Formalize AI usage policies that require pre‑approval, classification, and documented impact assessments before deployment.
- Deploy continuous monitoring to capture AI tool activity and collect evidence for audit readiness.
Technical Notes – The survey highlights that governance gaps stem from rapid AI adoption outpacing policy creation, leading to fragmented controls and limited real‑time oversight. Source: https://www.helpnetsecurity.com/2026/09/15/onetrust-enterprise-ai-governance-trends-report/