CIOs Face Widening AI Governance Gaps
- •Dataiku found 84% of 685 enterprise CIOs say employees deploy AI agents and apps faster than IT can govern them
- •Only 47% report clear controls, while 21% of CIOs have full visibility into AI costs
- •Two-thirds lack confidence in producing regulators an end-to-end audit trail of an AI agent decision
Enterprise CIOs face widening AI governance gaps as employees deploy agents and applications faster than IT teams can oversee them, according to surveys cited by InformationWeek on October 9, 2026. Dataiku surveyed 685 enterprise CIOs, and 84% said employees were creating AI agents and applications faster than IT could govern them. In a separate OneTrust survey of 1,200 business decision makers, 47% of organizations reported having clear governance controls. Dataiku also found that 76% of CIOs think their role will be at risk if their company fails to show measurable AI gains by the end of next year.
Financial oversight is one weak point: just 21% of CIOs said they have full visibility into AI agent and workload costs across use cases and business units. Pegasystems CIO David Vidoni said leaders need to know who is spending and on what, and to set limits. Netskope executive Mike Anderson said employees repeatedly recreate the same skills, adding redundant work and expense when companies lack a central place to track tools and skills.
Data quality presents another challenge as companies inventory approved data sources while new data and AI-generated material continue to appear. Vidoni warned that poorly curated data can lead AI tools to use outdated or incorrect information and increase the likelihood of hallucinations. In the OneTrust survey, 52% of business leaders cited data quality, access, privacy or security concerns as the main factors delaying AI launches and expansion. Houston Methodist Hospital executive Roberta Schwartz said organizations must know where AI is used, what data it accesses and whether it stores that data; existing third-party risk policies can be adapted to vendors' AI systems.
Shadow AI adds difficulty when employees create agents or use tools without controls. Vidoni warned that an unmanaged MCP server could expose an application to agents, creating performance and stability problems or leaking data when access controls are incomplete. Anderson said staff need education to choose suitable models and tools, and people must remain involved to check that systems produce accurate, unbiased outcomes. As agents gain autonomy, he said governance should detect authority drift and behavior changes.
Two-thirds of CIOs surveyed by Dataiku lack confidence that they could provide regulators with an end-to-end audit trail of an agent's decision. Anderson also warned that human reviewers may become fatigued and rubber-stamp machine-speed outputs. Executives cited leadership collaboration, governance committees, clear policies and simple reporting channels as ways to address gaps. Schwartz said employees need an easy path to report incorrect or unexpected AI behavior. More tools for financial, data quality, privacy, security and operational governance are expected to become available over time, but Anderson said long-term over-reliance on AI remains a concern.