AI Governance Demands Evidence, Not Just Policy

The AI Governance Gap Isn’t a Policy Problem. It’s an Evidence Problem

Ask a CISO or a chief compliance officer what keeps them up at night about AI agents, and the honest answer is rarely “the agents.” It is the question a regulator, an auditor, or opposing counsel will eventually ask. Which agent touched this record, under what authorization, and where is the proof.

That question now has an industry-wide answer, and it is not reassuring. The OneTrust 2026 AI-Ready Governance Survey Report, fielded with Sapio Research across 1,200 senior decision-makers in eight markets, found that 87 percent of organizations encourage employees and business units to use AI agents. Only 47 percent pair that encouragement with clear governance, oversight, and controls. Just 5 percent say coordination and accountability are clear across the full AI lifecycle. OneTrust’s own framing for that gap is blunt. Organizations are “building the plane while it’s already in flight.”

That 40-point spread between adoption and governance is the headline. The finding underneath it matters more to anyone who owns compliance risk. Among the eight governance activities OneTrust measured, the single least common one is governance evidence and audit trails, performed by only 28 percent of organizations, the lowest of any category tested. Confidence in individual governance tasks runs high, 76 percent to 78 percent depending on the activity. Confidence in producing evidence that ties an outcome to an authorized, logged decision does not. That distinction, between doing governance and being able to prove it, is where the AI governance conversation needs to move next.

Kiteworks’ own research points at the same fault line from the data layer up. The Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report found a Data Security and Compliance Readiness Index (DSCRI) of just 16.2 out of 100 across 459 organizations, and that 79 percent of organizations have no automated mechanism to terminate a misbehaving AI agent. The two data sets, one measuring governance process and coordination, the other measuring the underlying data controls, describe the same organization from two directions. Neither looks ready for the question a regulator asks.

Key Takeaways

  1. AI agent adoption has outrun agent governance by 40 points. OneTrust’s 2026 survey found 87 percent of organizations encourage AI agent use, but only 47 percent have matching governance, oversight, and controls in place.
  2. Coordination and accountability across the AI lifecycle is nearly absent. Only 5 percent of organizations report clear ownership and handoffs from use-case approval through post-deployment monitoring, despite performing an average of four governance activities.
  3. Evidence is the weakest governance activity measured, not the strongest. Governance documentation, audit trails, and evidence generation rank last among eight activities tested, performed by just 28 percent of organizations, which is the actual accountability gap hiding behind confident survey answers.
  4. Unapproved agent actions are already an operating incident, not a hypothetical. Forty-eight percent of organizations report at least one incident involving unapproved AI agent or AI system actions in the past 12 months, and 28 percent report two or more.
  5. The fix is a data control problem, not another policy document. Kiteworks’ own research puts the average organization’s combined data security and AI governance readiness at 16.2 out of 100, which means the evidence gap and the agent gap are the same underlying problem, an absence of any reliable record of what data an agent touched and under what authorization.

Adoption Is Winning the Race. Governance Isn’t Even Entered

The OneTrust survey’s central number bears repeating in full, because the framing matters as much as the figure. Eighty-seven percent of organizations encourage AI agent use, with or without governance in place. Only 47 percent have clear governance, oversight, and controls to go with that encouragement. Forty percent are actively encouraging agent use while acknowledging that governance and controls are “still developing.” Ten percent say agents operate in parts of the business without consistent oversight at all. Only 1 percent currently disallow AI agent use outright.

Encouragement is not evenly distributed by role, either. CISOs report the highest rate of encouraging agent use at 91 percent, ahead of CDOs at 90 percent, CPOs at 85 percent, and CMOs at 83 percent. That ordering is worth sitting with. The function most responsible for security risk management is also the function most likely to be waving agents through the door. That is not necessarily a contradiction. It may simply mean CISOs understand that blocking agent adoption outright is not a realistic policy in 2026, and that the real work is building the controls to govern what is already happening.

OneTrust’s report describes an AI Governance Maturity Model with five stages, and the distribution across it is instructive. Only 17 percent of organizations describe their governance as fully embedded by design and actively enabling innovation, the highest maturity state measured. Nearly half, 47 percent, describe governance as either reactive and fragmented, or defined on paper but slow and manual in practice. An organization can have a governance framework, a risk committee, and a documented policy, and still be in the 47 percent if none of it operates fast enough to keep pace with how agents are being deployed.

This is where the “building the plane while it’s in flight” line earns its place as the report’s defining image. It is not describing organizations that have no plan. It is describing organizations executing a plan for AI adoption while writing the governance plan in the same quarter, sometimes in the same meeting.

What Data Compliance Standards Matter?

Read Now

The Real Gap Is Coordination, and Coordination Requires Evidence

The most striking number in the entire OneTrust dataset is not the 87/47 split. It is the 5 percent. Only 5 percent of organizations report clear coordination and accountability across the full AI lifecycle, from use-case approval through post-deployment monitoring, incident response, and vendor oversight. That figure sits next to two others that seem, at first read, to contradict it. Organizations perform an average of four governance activities, and 76 percent to 78 percent of respondents report feeling confident in their ability to perform each individual governance capability tested.

Read together, those three numbers describe a very specific failure mode. Individual teams are doing individual governance tasks competently. A privacy team runs impact assessments. A security team logs incidents. A procurement team reviews vendor contracts. Confidence in each task, taken alone, is genuinely high. What is missing is the connective tissue, an owner who can say with certainty which team is accountable at each stage of an agent’s life, and a shared, evidence-quality record that survives the handoff between them.

OneTrust’s own coordination breakdown by lifecycle stage confirms there is no single dominant pain point to fix. Measuring performance, value, or business impact is the hardest coordination challenge, cited by 28 percent. Managing third-party or vendor AI risk follows at 24 percent. Monitoring AI systems after deployment and classifying AI risk before deployment are tied at 23 percent each. Maintaining technical controls sits at 22 percent. The spread across eight-plus categories, none dominant, is itself the finding. This is not a single broken step in the process, it is a process that was never connected end to end in the first place.

That is precisely why governance evidence and audit trails rank dead last among the eight governance activities OneTrust measured, performed by only 28 percent of organizations. Evidence generation is the activity that requires connective tissue by definition. You cannot produce a single, coherent record of an AI agent’s data access across its full lifecycle if the five teams that touched that lifecycle each kept their own logs, in their own format, in their own system, with no shared chain of custody. The chain of custody breaks exactly where the org chart breaks.

Regulators Regulate Data, Not Org Charts. And Not Models.

Here is the frame that a compliance leader brings to this data that a governance-process framing alone tends to miss. None of this changes what a regulator asks about. HIPAA does not have a carve-out for whether a human clinician or an AI agent accessed a patient record. GDPR’s accountability principle does not care whether a data controller’s processing decision was made by a person or by an autonomous workflow. The obligation to produce a defensible record of who accessed what, when, and under what authorization is not new, and it was never conditional on the identity of the accessor being human.

What agents change is the volume and velocity of access events that need to be logged, authorized, and made producible on demand, not the underlying legal requirement. An AI agent that queries a customer database, drafts a document from regulated records, or moves a file between systems is performing a data access event. Regulatory compliance obligations attach to that event the same way they would if a person had done it. The gap OneTrust documents, 47 percent with clear agent governance against 87 percent who have turned agents loose, is a gap in the infrastructure that would let an organization answer a regulator’s question about any one of those events.

The incident numbers in this survey should worry a compliance officer more than a security architect. Forty-eight percent of organizations report at least one incident in the past 12 months involving unapproved actions by AI systems or agents. Twenty-eight percent report two or more. An “unapproved action” is not primarily a technical failure. It is a governance failure with a specific compliance consequence. An access event occurred that no one authorized, and in a meaningful share of these organizations, no one can fully reconstruct after the fact. That is the exact scenario audit trail requirements across HIPAA, GDPR, SOX, and sector-specific frameworks like DORA exist to prevent.

Ninety-Six Percent Are Already Paying the Governance Tax, Without the Evidence to Show For It

Ninety-six percent of organizations say at least one AI initiative was slowed, paused, or complicated by governance, risk, or review requirements in the past year. That statistic could read as a case against governance rigor. It should read the opposite way. The top delay factor, cited by 52 percent of respondents, is concern about data quality, access, privacy, or security, exactly the category a mature evidence layer resolves before it becomes a delay. The second most common delay factor, at 39 percent, is limited visibility into third-party AI components, vendors, or data sources, a third-party risk management gap that shows up again later in the survey as one of the hardest lifecycle stages to coordinate.

In other words, most of the friction organizations are already absorbing is friction that a working evidence layer would eliminate, not friction the evidence layer would create. Review boards stall projects because they cannot get a fast, trustworthy answer to “what data will this agent touch, and how do we know.” That is a data-layer question. It does not get answered by another governance committee meeting. It gets answered by access controls and logging that produce the answer automatically, on demand, rather than through a manual assembly process that takes days.

Investment intent reflects growing recognition of this. Eighty percent of respondents say their function now spends more time managing AI-related risk than 12 months ago, an average net increase of 26 percent. Ninety-eight percent plan to increase their AI-governance technology budget in the coming year, by an average of 25 percent. That is a lot of new spending chasing a problem that, per the survey’s own data, is not primarily a spending problem. That same Kiteworks annual survey research found the same pattern independently. Organizations allocating 25 percent or more of their IT budget to cybersecurity scored, on average, less than one point higher on a 100-point security maturity index than the full sample. Spending more does not automatically buy readiness. Directing that spending at specific, testable data controls does.

What Kiteworks’ Own Data Says About the Layer Underneath the Governance Layer

OneTrust’s report is a governance-process and coordination study, surveying CPOs, CDOs, CISOs, and CMOs about how their organizations structure AI oversight. It is a useful, independently sourced companion to what Kiteworks measured from the data layer itself in its own 2026 annual survey research, a survey of 459 security and compliance professionals. The two studies are asking different questions and landing on the same conclusion from opposite directions.

Kiteworks’ report introduces a Data Security and Compliance Readiness Index, or DSCRI, calculated as a security maturity score multiplied by the proportion of AI data governance capabilities an organization has deployed. The survey mean DSCRI is 16.2 out of 100. The report’s authors are explicit that this is deliberately multiplicative. An organization cannot offset a large AI governance gap with incremental general security spending, because the two dimensions must advance together. That is the quantitative version of what OneTrust’s respondents are describing qualitatively when they say individual capabilities feel solid but lifecycle coordination does not.

The specific control gaps behind that 16.2 score map directly onto the OneTrust findings. Seventy-nine percent of organizations have no automated mechanism to terminate a misbehaving AI agent, what the report calls a kill switch. Among organizations that have deployed one, 23 percent have never tested it, meaning even the 21 percent with a kill switch in place cannot all say with confidence that it would work under pressure. Seventy-four percent lack purpose binding controls that would technically restrict an AI agent to its authorized tasks and data scope, meaning policy exists in most organizations without technical enforcement behind it. Fifty percent cannot produce a complete AI data access audit record within one business day, and 83 percent cannot produce one within one hour. Sixty-seven percent lack tamper-evident audit trails, the specific evidence type an auditor or investigator examines to confirm records were not altered after the fact.

Every one of those figures describes an evidence problem, not a policy problem. An organization can have a well-written AI governance policy and still be unable to answer, on the day a regulator asks, which agent accessed a specific record, whether that access was authorized, and whether the log proving it has not been tampered with. That is the exact scenario OneTrust’s respondents are describing when they say coordination and accountability across the lifecycle are unclear. The policy layer and the evidence layer are not the same layer, and a gap in the second one cannot be closed by writing more of the first.

The BBVA Model: Governance Built Into the Lifecycle, Not Bolted On at the End

OneTrust’s report includes a brief case study from BBVA, a global bank operating in 25 countries with more than 81 million customers, that is worth pulling out because it describes what closing this gap looks like operationally. Marta Sanz, BBVA’s Head of AI Governance, describes embedding governance into the AI lifecycle from the start rather than treating it as a single approval gate before launch. That means assessing intended use case, data sensitivity, model, system, autonomy level, and access impact up front, so governance scales proportionately to risk instead of applying the same heavyweight review to every project regardless of stakes.

The detail that matters most for a compliance audience is what Sanz says happens after deployment. BBVA treats post-deployment monitoring, traceability, and escalation paths as equally important as the initial assessment, because usage patterns, risks, and performance all continue to evolve after an agent goes live. That is a direct answer to the coordination gap OneTrust measured. Twenty-three percent of organizations cite monitoring AI systems after deployment as one of their hardest coordination challenges. BBVA’s model treats monitoring not as a separate, lower-priority phase but as a continuous extension of the same governance discipline applied at launch, with the same expectation of producible evidence at every stage.

Five Capabilities, One Underlying Requirement: Proof

OneTrust closes its report with a five-capability framework for what it calls the next phase of AI governance: continuous visibility into approved, unapproved, third-party, and agentic AI use; scalable governance that keeps pace with adoption; enforced guardrails that translate policy into working controls; connected accountability with clear owners and handoffs; and ongoing evidence, meaning documentation, monitoring history, approvals, and incident records that hold up to external scrutiny.

Read that list from a compliance seat, and a pattern jumps out. Every one of the first four capabilities depends on the fifth to be verifiable at all. Visibility that cannot be evidenced is a claim. Governance that cannot be evidenced is a policy. Guardrails that cannot be evidenced are intentions. Accountability that cannot be evidenced is an org chart with no way to prove who did what. Evidence is not the fifth item on a list of five equal priorities. It is the substrate the other four sit on.

Tim Mullen, CISO at OneTrust, makes the same argument independently in a companion piece for The Hacker News, published the same week as the survey report. Mullen argues that AI governance frameworks like ISO 42001 and the NIST AI Risk Management Framework should be layered onto an organization’s existing ISO 27001 foundation through continuous control monitoring, rather than built as a parallel program assessed only at a point in time. His prescription is direct. “A more practical approach is to set a solid baseline, build repeatable processes, align controls, automate where things are stable.” Mullen also cites the survey’s own incident finding, that 86 percent of organizations had at least one AI-related incident in the past year, and argues that tracking dependencies across data access, identities, third-party models, and business-process impact matters more than chasing a perfect, static compliance posture while the business keeps moving.

Both pieces converge on the same operating principle. Continuous, not point-in-time. Automated, not attested. A control that can be checked on demand, not a policy that is reviewed once a year and assumed to still be true.

What an Evidence-Grade Data Layer Actually Requires

Translating the OneTrust and Kiteworks findings into an operating checklist produces a shorter list than the scale of the problem might suggest, because most of the gap comes down to a handful of specific, testable capabilities rather than a broad cultural shift.

The starting point is knowing what data agents can reach in the first place. Data classification that enforces downstream controls, rather than applying a label that has no behavioral effect, is the foundation everything else in this list depends on. From there, access needs to be technically restricted, not policy-restricted. Attribute-based access control that scopes what an agent identity can reach, tied to the same authorization model applied to human users, closes the purpose-binding gap that 74 percent of organizations in the Kiteworks survey have not closed.

Every access event, by a human or an agent, needs to generate a log entry that flows into a CISO dashboard and a centralized audit system, not a siloed application log that never leaves the team that built the integration. That log needs to be tamper-evident, because an audit trail that could have been edited after the fact is not evidence, it is a claim. And the organization needs a tested, working mechanism to cut off an agent’s access immediately when something goes wrong, exercised on a schedule rather than assumed to work the first time it is needed.

Kiteworks secure data exchange is built around this exact requirement. A single governance layer, the Kiteworks Control Plane, applies the same access authorization, encryption, and audit logging to every party touching sensitive data, whether that party is a person, a machine, or an autonomous agent. Kiteworks Compliant AI enforces policy at the point where data would otherwise flow into an AI system unchecked, and every access event, human or agent, lands in the same audit record rather than a separate log an incident responder must go find. Agents do not get governed as a special case bolted on after the fact. They join the same identity and access framework that already governs human data access, which is the same model BBVA describes, and the same capability missing at 79 percent of the organizations in Kiteworks’ own survey.

None of this requires waiting for a perfect governance framework to be finished. It requires the same sequencing Mullen describes. Establish the baseline, make the controls repeatable and testable, and automate the ones that have proven stable. An evidence-grade record of agent data access is not the last step after governance maturity is achieved. It is the first control that makes every later governance claim verifiable.

To learn more about closing the evidence gap behind AI agent governance, schedule a custom demo today.

Frequently Asked Questions

It is primarily an evidence and enforcement problem, not a policy-drafting problem. OneTrust’s data shows organizations already perform an average of four governance activities and feel 76 percent to 78 percent confident in each individual capability. What is missing is a connected, audit-ready record that ties those activities together across the full AI lifecycle, which is why governance evidence and audit trails rank as the least-performed activity in the survey at just 28 percent.

No. Frameworks like HIPAA, GDPR, and SOX regulate the data and the access event, not the identity of whoever or whatever performed the access. An organization still needs to show that the access was authorized, logged, and traceable regardless of whether a person or an agent initiated it. Regulatory compliance obligations do not carve out an exception for autonomous systems.

No, and the data argues the opposite. Ninety-six percent of organizations report at least one AI initiative already slowed or complicated by governance and review requirements, which means the operational cost of missing controls is already being paid whether or not the controls exist. Building data classification, access enforcement, and audit logging now reduces that friction going forward instead of adding to it.

A kill switch is a documented, technical capability to immediately terminate an AI agent’s access or operations. Kiteworks’ 2026 Annual Survey Report found that 79 percent of organizations have not deployed one, and among organizations that have, 23 percent have never tested it. An untested kill switch is an assumption about what would happen in an incident, not a verified incident response control, so testing on a defined schedule is what turns the capability into evidence a regulator or auditor would accept.

OneTrust’s data suggests this is genuinely unsettled across organizations, and that ambiguity is itself part of the problem. Only 5 percent report clear coordination and accountability across the full lifecycle. The practical answer, illustrated by BBVA’s approach, is shared ownership with clearly defined handoffs, dedicated AI data governance ownership rather than treating it as an add-on to an existing security or compliance role, paired with a shared evidence layer every function can pull from rather than separate logs each team maintains independently.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks