Enterprise adoption of artificial intelligence is increasing the workload associated with AI risk and governance, with a OneTrust survey finding that four in five senior business decision-makers, including Chief Information Officers, Chief Information Security Officers and Chief Data Officers, are spending more of their working day managing AI risk. Their working hours have increased by an average of 26% because of AI-related governance demands. The findings come as organisations expand AI use across business functions, while autonomous and agentic systems introduce additional governance challenges.
The survey also found that 33% of respondents had seen employees use unapproved AI tools because approved solutions or processes were not available quickly enough. Meanwhile, 86% reported AI-related incidents, and more than one-quarter had experienced two or more incidents involving AI systems taking unauthorised actions. The rapid growth of employee-led AI development is adding another layer of complexity, as non-IT teams increasingly build applications and agents themselves.
The challenge is shifting governance from simply approving AI tools to establishing continuous oversight, data lineage, model versioning, escalation mechanisms and audit trails. As AI agents gain greater autonomy and access to sensitive information and enterprise systems, organisations are also being urged to strengthen identity controls, continuous monitoring and human oversight. The development highlights a widening gap between AI governance awareness and actual organisational readiness, particularly where controls are being introduced reactively after incidents occur.
Want to deepen your expertise beyond today’s news?
Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.
Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.
#Riskmanagementnews