The gap is operational
Responsible AI is often described as a principles exercise: publish a policy, name values, and require teams to act carefully. Recent corporate data suggests that approach is not keeping pace with deployment.
In a September 17 analysis, the World Business Council for Sustainable Development reported that 43.7% of companies in a large global dataset communicate an AI strategy publicly. Of that group, only 27% report a governance framework. Board oversight appears at 40% of companies, while just 3.8% disclose a dedicated AI ethics committee.
The Thomson Reuters Foundation’s underlying AI Company Data Initiative covers 2,972 companies across 11 sectors and six regions. It reports that nearly 90% do not name an AI governance framework, only 13% disclose a policy for human oversight, and 2.3% have a dedicated AI complaints mechanism.
The takeaway is not that organizations lack interest. It is that adoption can spread through business units faster than oversight becomes an everyday operating capability.
Governance has to live in the workflow
A useful governance model connects five practical areas: ownership, approved uses, adoption controls, risk management, and data stewardship. Each one should appear inside the lifecycle of an AI system rather than in a separate policy document.
That means defining who can approve a use case, what data can enter the system, how outputs are checked, which decisions require human review, and how problems are reported. It also means keeping a current inventory of deployed models, external AI services, automations, and the business processes that depend on them.
When these controls are built into procurement, development, access management, monitoring, and incident response, responsible AI becomes repeatable. Teams spend less time debating principles after a problem and more time making clear decisions before deployment.
Agentic AI raises the stakes
The governance gap becomes more important as AI shifts from generating content to initiating actions. An agent that can update a customer record, issue a refund, modify infrastructure, or trigger another system creates a different risk profile from a chatbot that only proposes text.
Human oversight should therefore be matched to consequence. Low-risk actions may be monitored through sampling and automated controls. High-impact actions need explicit approval, defined limits, tamper-resistant logging, and a fast way to suspend the agent. The goal is not to place a person inside every routine step, but to keep people meaningfully in control of objectives, boundaries, and exceptions.
A practical four-part starting point
- Maintain an inventory of AI systems, owners, data, vendors, and affected processes.
- Classify uses by potential impact and apply stronger review to higher-risk decisions.
- Record approvals, model changes, significant outputs, overrides, and incidents.
- Give employees and affected users a clear route to question or escalate an AI-driven outcome.
Responsible AI becomes commercially valuable when it makes adoption safer, faster, and easier to explain. The organizations that operationalize governance now will be better prepared to scale automation without losing accountability.
