AI Governance Depends on Clear Accountability
- •Deloitte found 84% of surveyed organizations had not adjusted jobs for AI, while only 21% had mature governance frameworks.
- •Legal AI tools hallucinated on queries 17% to 33% of the time; one case led to nearly $95,000 in sanctions.
- •GitLab found 92% faced AI code governance challenges; Faros reported review times rose 441% among high-adoption developers.
Enterprises need clearer accountability for AI risk, approvals, monitoring, and outcomes as adoption expands, according to executives and research cited in a CIO report published October 7, 2026. Deloitte’s 2026 State of AI in the Enterprise report found that 84% of surveyed organizations had not adjusted jobs for AI and only 21% had a mature AI governance framework. Beena Ammanath of the Global Deloitte AI Institute says organizations must redesign workflows and establish ownership, rather than relying only on governance tools and periodic reviews.
A 2024 Stanford RegLab study found that LexisNexis’s Lexis+ AI and Thomson Reuters’ Westlaw AI-Assisted Research and Ask Practical Law AI hallucinated on legal queries between 17% and 33% of the time. The Damien Charlotin AI Hallucination Cases Database had identified 2,041 cases of fabricated information, and one case, Couvrette v. Wisnovsky, resulted in nearly $95,000 in sanctions. The report connects such failures to unclear responsibility for checking AI output before it is used.
Executives say autonomous, multi-step agents raise additional oversight questions because errors can pass from one step to the next before a human reviews the final result. Microsoft Research’s VeriTrail project says checking only the final output is insufficient; the source of errors must be traced through intermediate outputs. Gartner analyst Lauren Kornutick says business teams cannot be accountable for agent deployments if they cannot verify performance while systems run.
Eaton has deployed multi-step workflows without a human in the loop, including an agent that authenticates supplier payment inquiries, matches purchase orders with invoices, and returns payment information. Eaton isolates the less predictable large language model components and evaluates them against expected outputs to detect model drift. Company executive Ross Schalmo says autonomous applications without a later human review take longer to develop because teams must decide where generative AI is appropriate and where deterministic tools should be used. Breakthru Beverage Group has updated AI use policies, required AI e-learning, and blocked unsanctioned AI tools.
Responsibility for governance is spread across technology, legal, security, data, and business teams at many companies. Forrester Research’s Craig Le Clair says 21% of organizations already have a chief AI officer and roughly 24% of enterprises will move AI and automation governance outside the CIO’s office over the next year. At Principal Financial Group, Rajesh Arora’s team sets standards and oversight but works with business, legal, compliance, risk, and technology leaders; the company has assessed nearly 200 use cases.
Governance platforms also have visibility gaps. Le Clair says current agent platforms lack an adequate control plane (a system for monitoring and controlling agents), while platform-specific registries may not show agents built on competing services. Schalmo says his team reviewed four or five external governance vendors, many of which could not discover AI built into other vendors’ products. He is considering a cybersecurity vendor’s discovery component, a control-tower product, and an additional governance layer built with AI.
Surveys show governance challenges alongside productivity gains. A 2026 GitLab survey found that 92% of organizations reported challenges governing AI-generated code, and 34% of organizations with an AI-related incident could not later determine whether AI-generated code caused it. Faros AI analyzed 22,000 developers and found that those with high AI adoption completed 34% more tasks and 66% more epics, while median pull-request review time increased 441%. Ammanath says governance and speed need to be designed together, and that adding governance only after broad deployment slows organizations.
Executives recommend workforce education alongside workflow redesign, role-specific training, and clear accountability for outcomes. Principal invested in workforce readiness, while Ammanath says policies and tools alone do not clarify decision rights or how daily responsibilities change. Schalmo says organizations should assess how agent projects affect workers and workflows. An Eaton automated process for complex bid requests was piloted in a country with lower labor costs than the United States, challenging the project’s economics; the affected employees handled higher-volume