AI adoption is moving quickly. Organizations are putting AI into production, embedding it into existing tools, and experimenting with new use cases across the business. But is governance keeping pace?
Our 2026 AI Governance, Risk & Operational Resilience Benchmark Study provides a snapshot of how organizations are approaching AI governance today.
The benchmark examined 21 governance practices across five areas: security, resilience, privacy, incident response, and continuous review. The goal was to move beyond assumptions and get a clearer picture of how organizations are actually approaching AI governance today.
Watch the webinar recording and access the presentation slides below, then explore the key findings from the benchmark.
The benchmark provides a snapshot of where organizations are today across five key areas of AI governance:
Security was the most mature area measured, while continuous review ranked lowest.
That difference is significant. Organizations may establish governance controls when an AI system is introduced, but those controls need to remain effective as systems, data, threats, and use cases change.
The benchmark suggests that the next gains in maturity will come from recurring review, clear accountability, and tested incident response—not simply from adding more policies or frameworks.
The benchmark brought together perspectives from organizations across 11 industries, with particularly strong participation from financial services and consulting.
Financial services represented 23% of respondents, followed by consulting at 21%, healthcare at 10%, technology vendors at 10%, and outsourcing and service providers at 8% each.
The survey also included a range of organizational roles. Directors, CXOs, and VPs represented 56% of completed participants, providing perspectives from both leadership and practitioners working directly with AI and governance programs.
Geographically, 74% of respondents were from the United States, followed by the United Kingdom (8%) and Canada (5%), with additional participation from France, Switzerland, Germany, Japan, and the United Arab Emirates.
AI is already becoming part of day-to-day operations.
In the benchmark, 36% of respondents reported having AI in production, 24% reported employee-led use, 24% were piloting AI, and 13% described AI as broadly embedded across the organization.
This rapid adoption creates a governance challenge. AI systems are being introduced across enterprise applications, third-party platforms, browsers, and other tools—sometimes without a centralized view of where those systems exist or how they are being used.
The benchmark findings suggest that governance needs to keep pace with adoption. Organizations need to know what AI systems they have, who is accountable for them, what risks they introduce, and how those risks are monitored over time.
One of the strongest themes from the benchmark was the difference between having governance intent and operationalizing that intent.
Organizations are establishing policies, committees, and controls. But participants also described fragmented ownership, uncertain monitoring, and limited validation.
This raises an important question: Where does AI governance actually happen?
Rather than creating an entirely separate governance structure, organizations can extend the disciplines they already have.
Existing ITSM practices can provide a foundation for AI governance:
The objective is not to create governance in isolation. It is to embed governance into the processes where work is already being performed.
AI does not eliminate process problems. In some cases, it can make them more significant.
The benchmark discussion highlighted a growing concern around process debt—the accumulated gap between how work is actually performed and the processes needed to operate and govern it effectively.
When processes are outdated, fragmented, poorly documented, or lack clear ownership, organizations may end up automating those weaknesses at scale.
As David Mainville, Navvia CEO and co-founder, explained during the webinar, AI governance cannot be stronger than the processes it depends upon.
Before automating or augmenting a process with AI, organizations need to understand how that process actually works, who owns it, what controls are required, and where informal workarounds or gaps exist.
AI can accelerate a process—but it cannot compensate for a process that was never properly defined or governed.
The lowest-scoring benchmark domain was continuous review, at 37%.
The individual practices within this area showed particularly low maturity around:
These findings point to a broader issue: governance cannot be a one-time exercise.
AI systems change. Models change. Data changes. Threats change. And the way employees use AI can change just as quickly.
That means organizations need an ongoing assurance cycle that includes recurring reviews, measurable outcomes, tested controls, monitoring, and lessons learned.
Putting governance in place is only the beginning. The real challenge is making sure it continues to work.
The benchmark shows that organizations recognize the need for AI governance. The next step is turning that intent into something that is owned, repeatable, measurable, and sustained.
Based on the findings, organizations should consider:
Establishing clear ownership. Know who is accountable for AI systems, risks, controls, and governance activities.
Maintaining an authoritative AI inventory. You cannot effectively govern AI systems you don't know exist.
Embedding governance into existing processes. Extend established ITSM, security, risk, supplier, and continuity practices rather than creating disconnected governance activities.
Monitoring AI after deployment. Governance needs to continue beyond implementation through ongoing monitoring and review.
Testing and validating controls. Organizations need evidence that their governance and resilience controls actually work.
Addressing process debt. Before automating processes with AI, make sure the underlying processes are understood, documented, owned, and capable of supporting the desired outcomes.
AI governance is ultimately an operational challenge. The organizations that can connect governance requirements to the processes, people, controls, and accountability already embedded in their operations will be better positioned to manage AI as its use continues to expand.
Understanding where your organization stands is the first step toward strengthening AI governance.
Navvia can help organizations assess current capabilities, identify gaps, design and document processes, and operationalize the practices needed to support AI governance and resilience.
Explore Navvia's AI Governance, Risk & Resilience Assessment →