AI risk #79/99: The board signed the AI policy. 47% have gone round it.
Almost every large company has an AI policy. EY found nearly half have gone round it for something urgent, and a quarter cannot see the AI agents acting inside the business. The policy points at the wrong thing.
Almost every large company now has an AI policy. EY's latest survey of 202 senior AI executives at US companies with at least US$1 billion in revenue, published on 15 September, puts the figure at 98%. The same survey found that 47% of them have skipped their own governance process at least once because a deployment was urgent.
Both numbers are believable, and they sit together more comfortably than they should. A policy is written for the deployments that arrive through the front door with time to spare. Urgent ones come in through the side door, and the policy never hears about them.
Where the 47% comes from
EY's numbers describe the shape of it. Nine in ten of the companies surveyed already run AI agents, in pilots or in production. Among those, 85% say at least some of their agents act without a person watching each step, and 49% say the governance framework has not been updated to cover agents at all. One in four cannot tell whether an agent nobody sanctioned is running inside the business.
For a director, the useful word in all of that is "act". Software is now taking actions on the company's behalf, some of it under no policy and some of it under nobody's name. Which is less a technology question than a question about who is allowed to decide what.
Delegations of authority, with a new signatory
Every business of any size runs on a delegations of authority framework, whether it calls it that or not: who can approve spend to what limit, who can sign a contract, who can change a price, who can release a payment. It is one of the oldest safeguards on the register, usually owned by the CFO or the company secretary, with approval limits, sign-off rules and an audit trail behind it.
All of that assumes a person is making the decision, and that a person who exceeds their authority will turn up in the approval trail. An agent that reprices a product, approves a refund, raises a purchase order or answers a customer complaint is making decisions inside those delegations, and nobody added it to the schedule. When the plan needs something quickly and the policy is the slow route, the decision gets made anyway, and the register goes on scoring the line as though the old safeguard still holds. That is most of what the 47% is.
Richard Jackson, who leads AI assurance for EY in the Americas, said it plainly in the release: "Organizations are applying yesterday's governance rules to today's interactions with AI". The rules themselves are fine. They point at the wrong thing.
What it has already cost
This is not a forecast. 89% of EY's respondents ran into an AI-related risk in the past year, and 36% said an AI incident or failure had done material harm to their organisation: data loss, financial damage, operational disruption or damage to the brand. More than a third, at companies with a policy, a committee and an annual review already in place.
The companies that went looking found plenty. Nearly all of them run a formal AI assurance review at least once a year, and of those, 64% ended up significantly changing a quarter or more of their AI systems, 29% paused a quarter or more, and 25% stopped a quarter or more altogether. The most common findings were data quality, model drift and shadow AI. Reviews work, in other words. They also show how much was running before anyone looked at it.
Attach the policy to the decisions
The AI policy does not need rewriting. It needs connecting to the decisions it was meant to govern, and that starts with one question for the executive team: which decisions in the plan does an agent now make, and who approved that?
The answer usually comes from the people running each function rather than from the tool inventory. For each part of the plan (pricing, credit, purchasing, hiring, customer service) they can say whether any step is now taken by software without a person approving it, if they are asked plainly.
Those decisions then belong under the delegations. If an agent can approve, release, price or promise, it gets a limit, an owner and an audit trail, the same as a new manager would. The policy says who may deploy AI. The delegations say what it may decide.
The last check is the cheapest. Take the most recent thing that shipped in a hurry and walk it back through the policy as written. If it would have failed, you have found your own 47%, and you can see which step the policy needs to lose or which decision the plan needs to slow down.
The boards I talk to mostly have the first document. The second is the one I ask about now.
If you would rather see where else in the plan the same gap sits, the AI Disruption Index is free and takes about ten minutes. It works from your objectives, scores the risks AI is driving against each of them, ranks them, and drafts a safeguard for every one. It cannot tell you which of your agents is acting outside its delegation. It will show you which objectives that decision lands on.
Which of your objectives is AI hitting hardest? Free, in about ten minutes.