AI Governance Maturity Gap

Created: 2026-05-17 Updated: 2026-09-17 Source count: 35

Updated 2026-09-17 (second update this day; daily AI-governance vendor-intelligence scan) based on S-2026-09-10-harness-state-of-agent-dlc-2026an engineering-side survey quantifies the gap between asserted and evidenced agent controls, pair by pair. Harness’s State of Agent DLC 2026 (10 Sep 2026; Sapio Research, July 2026; n=700 engineering/IT/technology leaders at 1,000+-employee, $100M+ enterprises in the US, UK, France, Germany and India, all with agents at least in live PoC) reports 77% confident of a complete inventory of every agent, MCP server and LLM vs 44% running active discovery tooling; 74% confident testing would catch a production-impacting failure vs 19% with an automatic release-blocking gate; 76% believing they could disable a misbehaving agent within 15 minutes vs 33% with an instant kill switch; 75% calling agents “secure end to end” yet reporting incidents at 88% vs 87% overall; 42% pushing prompt edits through the ordinary code pipeline; 58% seeing more incidents per 100 changes since deploying agents. Its distinctive contribution is the paired design — each confidence statement sits beside the control that would evidence it — which reads directly as an assurance test plan, and the security-confidence/incident-parity finding, which suggests self-assessed security posture is uninformative. Reinforces (does not contradict) the thesis; complements the same-week OneTrust survey (decision-makers) with an engineering-leadership sample — the two cannot be combined. ⚠️ Authority medium, self-interested: commissioned by a DevSecOps vendor that sells agent inventory, evals, gating and rollback; cross-sector with no FS or country cut published; questionnaire and full report unread. Source count reconciled to the Sources list (34 entries before this addition; the frontmatter/body figures had drifted). Added as this banner, a Key Point and a Source entry. [S-2026-09-10-harness-state-of-agent-dlc-2026]

Updated 2026-09-17 (daily DG/DM vendor-intelligence scan) based on S-2026-09-14-onetrust-ai-ready-governance-report-2026a privacy/AI-governance vendor’s second annual survey adds an incident-response and shadow-AI cut to the 2026 convergence. OneTrust’s 2026 AI-Ready Governance Report (14 Sep 2026; Sapio Research, n=1,200 senior decision-makers across US, CA, UK, FR, DE, ES, AU, SG) reports 87% encouraging AI-agent use vs 47% with clear governance, oversight and controls; 28% with two-plus incidents of AI systems or agents taking unapproved actions; 86% with at least one AI-related incident (vendor-defined basket: sensitive-data/IP exposure, unapproved employee AI use, misinformation, data loss) yet only 27% paused or slowed deployment (49% added training instead); 33% saw shadow AI because approved tools or processes were too slow; 80% spend more time on AI risk (+26% hours) and 98% plan higher AI-governance technology budgets (+25% average). Its distinctive contributions are the response-to-incident datum (training, not braking) and the approval-friction-breeds-shadow-AI mechanism — a governance-design finding that cuts against treating slow sanctioning as a control. Reinforces (does not contradict) the thesis. ⚠️ Authority low: vendor-commissioned by an AI-governance platform whose runtime-enforcement product narrative the release’s framing serves (“judgment has to live in the runtime itself”); no fieldwork dates, sector split or EU/UK cut published; the 86% incident rate is not comparable to any regulatory incident definition; gated report not read. Added as this banner, a Key Point and a Source entry. [S-2026-09-14-onetrust-ai-ready-governance-report-2026] Updated 2026-09-14 (daily regulatory-intelligence scan — practitioner-research source line) based on S-2026-02-intelligine-governance-benchmarkan operating-model benchmark reframes the 2026 maturity gap as a dispersion in governance discipline wider than the dispersion in technology. Intelligine Group’s “AI in financial services: the 2026 governance benchmark” reports primary data from structured interviews with the sitting Chief AI Officer (or equivalent) at 42 banks and insurers (24 banks incl. 11 G-SIBs; 18 insurers; >$41tn AUM/in-force; interviews Sep 2025–Jan 2026). Its headline is that “the technology choices are converging; the operating models are diverging” — and it localises the divergence in three artefacts: kill criteria (only 19/42 have at least one unit-economic kill criterion continuously instrumented; those firms held portfolios within 12% of the approved cost envelope vs a 68% median overrun for the other 23), escalation paths (only 7/42 can move from a kill-criterion breach to a decision inside 72 hours without a board calendar event; 11/42 have no written escalation path at all), and audit posture (cleanest reconciliation where the runtime audit trail and the governance artefact are maintained by separate teams on separate reporting lines — a Three Lines of Defence for AI independence argument [inference]). It adds a modal three-tier scheme keying documented MRM and instrumented kill criteria to proximity to a regulated decision (feeds Model Risk Management and Agentic AI). Reinforces (does not contradict) the thesis; sharpens the operating-model / evidence cut and, in particular, the Service Line — Independent Governance Assurance demand case (escalation and audit-reconciliation are exactly the assurance-evidence gap). Authority low / date caveat: single independent consulting firm’s own primary data (n=42), self-described methodology, gated instrument, global G-SIB-weighted with no UK/EU cut; byline February 2026, outside the strict past-7-day window but net-new to the vault and directly on-point (the four regulator sources returned no net-new in-window item this run). Added as this banner, two Key Points, a Detail subsection and a Source entry. [S-2026-02-intelligine-governance-benchmark]

Updated 2026-09-11 (daily regulatory-intelligence scan — provenance only, no claim changed). The primary Deloitte “Banking on Trust” page was fetched in full and confirms every figure cited from that source on this page (63% weekly use; 13% optimized / 87% scope; 72% design→55% monitoring; 72% with <half of use cases registered; 44% agentic-lifecycle monitoring vs 61%/59%; 10-pt Index ≈ 10pp revenue as association-not-causation). ⚠️ Date correction: the primary byline is 08 Jul 2026, so the “report dated 14 Aug 2026” characterisation in the banner and Key Point below reflects the Financial Brand relay date, not the source’s own date — both preserved on S-2026-08-14-deloitte-banking-on-trust (S-tag rename to 2026-07-08 flagged as a future action). No Key Point figures changed; authority of the source upgraded from relay-only to primary-confirmed. All four official sources (EBA, FCA, BIS, EU AI Office) and the practitioner search returned no net-new in-window item this run.

Updated 2026-08-28 (second update this day; daily DG/DM vendor-intelligence scan) based on S-2026-08-21-solutionsreview-dm-roundup and S-2026-08-10-collibra-banking-readiness-gaptwo vendor-side articulations of the same gap, both added as attributed data points rather than findings. The Modern Data Company’s interim survey (n=540+ data leaders, reported week of 21 Aug 2026) reports 57.3% piloting or operating AI agents against only 8.4% saying the underlying data is “sufficiently trustworthy for production” — the widest adoption-versus-data-trust spread on this page, and one that locates the constraint in data rather than model governance, with data quality and trust, missing context and lineage, and security all ranked above skills and tooling. Separately, Collibra’s 10 Aug FS blog supplies the sharpest framing yet — that the EU AI Act high-risk deferral and the US SR 26-2 carve-out relocate accountability inside the firm rather than removing it, making every ungoverned model “AI governance debt” that “compounds quietly until it comes due”. ⚠️ Both are low-authority and self-interested: the Modern Data Company sells governed-context tooling and publishes no methodology; Collibra’s post resolves to its own “single governing semantic model” product thesis, and every regulatory fact in it is second-hand and unverified (the 2 Dec 2027 AI Act deadline and the SR 26-2 description both need primary confirmation via the regulatory scan — logged on Collibra’s Open Questions). Both reinforce, and neither contradicts, the existing thesis. Added as this banner, one Key Point and two Source entries. [S-2026-08-21-solutionsreview-dm-roundup][S-2026-08-10-collibra-banking-readiness-gap]

Updated 2026-08-28 based on S-2026-08-14-deloitte-banking-on-trust (daily regulatory-intelligence scan, practitioner-research source line) — a Big Four, banking-specific 2026 survey adds the sharpest lifecycle-and-agentic cut yet to the maturity gap. Deloitte’s “Banking on Trust: AI Governance for Growth, Resilience and Scale” (14 Aug 2026; 135 respondents — 24 AI-governance leaders at G-SIBs/D-SIBs across 14 countries + 111 senior tech/AI/data staff across 16 countries) finds weekly AI use among bank employees doubled to 63% in 2026 (from 30% in 2025) while only 13% of banks reach the highest (“optimized”) governance maturity and 87% have material scope to strengthen — the same adoption-outpaces-governance signal this page tracks, now from a Big Four’s own banking research. Its distinctive contribution is to locate the gap after go-live and in agentic AI specifically: 72% apply mandatory controls at design but only 55% at monitoring, 72% have under half their AI use cases in a central register, and only 44% have risk monitoring across the lifecycle for agentic AI vs 61% traditional / 59% generative. It also names the weakest pillars as organisational structure and people/skills (not procedures), and reports a governance–deployment link (optimized banks average 5.5 fully-implemented AI solutions vs 0.7 at ad hoc) and a governance–revenue association (10-point Governance-Index rise ≈ 10pp revenue-growth rise) that Deloitte explicitly flags as association, not causation — preserved as such, not smoothed. Reinforces (does not contradict) the thesis; pairs with the existing Deloitte AI-Controls-and-Assurance competitive-context note [S-2026-08-12-deloitte-ai-controls-assurance]. Date caveat: report dated 14 Aug 2026, just outside the strict past-7-day window but research-grade and not previously ingested — the strongest available practitioner signal this run (25–27 Aug practitioner scans returned negative); figures are from The Financial Brand’s relay of the gated report, self-reported, G-SIB/D-SIB-weighted (⚠️ see Source page and raw stub). Added as this banner, a Key Point, a Detail subsection and a Source entry. [S-2026-08-14-deloitte-banking-on-trust]

Updated 2026-08-25 based on S-2026-08-17-aca-ai-governance-examination-priority (daily AI-governance vendor-intelligence scan; FinTech Global relay, 17 Aug 2026, of an ACA Group insights post — primary ACA post not fetched) — the maturity gap acquires an examination-risk framing from a second assurance-market competitor. ACA Group (FS compliance advisory/assurance) argues regulators in the US, UK and UAE are converging on “existing frameworks already apply to AI”: the SEC’s 2026 Examination Priorities embed AI oversight across information-security, operational-resiliency and emerging-fintech categories; FINRA’s 2026 Annual Regulatory Oversight Report adds a dedicated GenAI section asking member firms for evidence of testing, supervision, governance, vendor diligence and recordkeeping — regardless of whether the firm markets AI; the FCA points firms to its principles-based model (AI Lab, AI Live Testing, Mills Review); and the DFSA issued a DIFC-wide circular on governance/accountability, risk management, operational risk and third-party arrangements. ACA’s own survey (200+ compliance/ops professionals, 62% CCOs) supplies a fresh adoption-vs-governed-scope datum: 84% use desktop AI tools at work, yet the average firm applies AI in fewer than two of 20 surveyed functions — and ACA closes by selling independent assessments to benchmark governance “before gaps become examination findings”. ⚠️ Regulator characterisations are ACA’s summaries (primaries owned by the regulatory scan); survey methodology undisclosed; the closing recommendation is self-interested positioning — ACA joins Deloitte [S-2026-08-12-deloitte-ai-controls-assurance] as a competitor attesting to, and monetising, the same gap. Reinforces (does not contradict) the thesis; sharpens the demand case for Service Line — Independent Governance Assurance [inference]. Added as this banner, a Key Point, a Detail subsection and a Source entry. [S-2026-08-17-aca-ai-governance-examination-priority]

Updated 2026-08-21 based on S-2026-08-12-deloitte-ai-controls-assurance (daily AI-governance vendor-intelligence scan; primary Deloitte press release, 12 Aug 2026, fetched in full — found late, 9 days after the announcement, not previously in the vault) — a Big Four AI-assurance practitioner data point lands alongside a service-expansion signal. Deloitte announced expanded end-to-end AI Controls and Assurance services on 12 Aug 2026, citing its own “State of AI in the Enterprise” research that 74% of companies plan to deploy agentic AI within two years, but only 21% report a mature governance model for autonomous agents — a fresh, differently-sourced restatement of the same adoption-outpaces-governance gap this page has tracked since May, this time from a Big Four assurance provider’s own market research rather than an independent survey house. The service-expansion angle matters as much as the statistic: Deloitte is building “AI governance, controls and risk management” (including model validations and standards-based readiness assessments), “AI-powered enablement” of clients’ internal audit/controls functions, and “regulatory readiness” (SOC reports, certifications) into one named offering under its Trustworthy AI™ framework — i.e. a large incumbent competing directly for the same independent-assurance-over-AI work this page frames as Paul’s market opportunity [inference]. ⚠️ No regulatory standard (EU AI Act, ISO/IEC 42001, SR 11-7, SS1/23) is named anywhere in the release text — a notable absence for an assurance provider positioning on “regulatory readiness”; no named client; the 74%/21% figure is Deloitte’s own report, not independently verified this run; the release is US-dated with no explicit UK/EU scope statement. Reinforces (does not contradict) the existing thesis and the standing Deloitte CFO Signals citation already on this page [S-2026-07-23-deloitte-cfo-signals-q2-2026]; a light-touch, dated note is also added to Big 4 Differentiation Frame flagging the competitive-context implication. Added as this banner, a Key Point, a Detail subsection and a Source entry. [S-2026-08-12-deloitte-ai-controls-assurance]

Updated 2026-08-19 based on S-2026-08-12-tech-reseller-aaa-icdr-ai-governance-gap (daily regulatory-intelligence scan, practitioner-research source line) — a mid-August trade-press relay (Technology Reseller, 12 Aug 2026) of an AAA-ICDR Institute study adds the sharpest policy-to-proof datum yet in financial services: 96% of FS respondents report formal AI governance policies, but only 53% have translated them into specific technical controls, and just 21% are “very confident” they could produce centralised, complete and auditable evidence for regulators, auditors or courts. It reinforces (does not contradict) the evidence-layer thesis — near-universal written policy, thin technical controls and audit-ready evidence — echoing Arctera’s “55% policy vs 19% proof” [S-2026-07-21-arctera-ai-governance-2026] and the confidence-vs-maturity Tension. Added as this banner, a Key Point, a Tensions datum and a Source entry. Authority low / traceability partial: trade-press relay; the primary AAA-ICDR study was not retrieved and a direct WebFetch of the article returned an empty client-rendered shell, so the 96%/53%/21% figures come from the WebSearch summary and are not independently confirmed (⚠️ see Source page and raw stub). Selected as the practitioner source because it is within the past-7-day window and genuinely new — the other 2026 FS AI-governance surveys surfaced by search (CCAF, CSA, McKinsey, Grant Thornton, ProSight, Wolters Kluwer, Deloitte, Arctera, Domino, Cloudera) are already ingested. [S-2026-08-12-tech-reseller-aaa-icdr-ai-governance-gap] Updated 2026-08-17 based on S-2026-08-14-cloudera-ai-rearchitecture-survey (daily vendor-intelligence scan) — Cloudera’s global survey of 1,500 enterprise architects, cloud infrastructure leads and data architects (released week to 14 Aug 2026) adds an architect-population cut: 72% say their data architecture needs significant change for AI, 75% have already changed storage/architecture practices because of AI, 77% actively use AI — and 95% have delayed or cancelled projects over data governance, compliance, or regulatory challenges, which Cloudera brands the “Great AI Re-Architecture”. Reinforces (does not contradict) the adoption-outpaces-governance thesis, quantifying governance/compliance as the leading project-stopper from the infrastructure side. Authority low (vendor-commissioned, relayed twice over — Cloudera → CRN Asia → Solutions Review; methodology, fieldwork dates and FS/EU-UK cut not retrieved; the 95% figure’s denominator and timeframe are unknown). Added as this banner, a Key Point, a Detail subsection and a Source entry. [S-2026-08-14-cloudera-ai-rearchitecture-survey]

Updated 2026-08-06 based on S-2026-06-24-techuk-agents-of-change (daily scan, practitioner-research source line) — techUK’s “Agents of Change: Generative and Agentic AI in Financial Services 2026” (dated 24 June 2026; member-sourced use cases + survey) adds a UK-specific, industry-body cut to the 2026 adoption-outpaces-governance convergence: 61% of surveyed firms were using or assessing generative AI and 42% agentic AI in 2025, with agentic AI “moving from experimentation to live deployment”, and the report reframing the question as “how governance, assurance, and operational resilience frameworks keep pace with increasingly capable systems.” It names the binding governance challenges as behavioural drift, human oversight at scale, AI supply-chain concentration, and cyber resilience, and prescribes three ecosystem moves — a dedicated agentic-AI governance workstream (via the Bank of England/FCA AI Consortium), expanded shared testing infrastructure (FCA Supercharged Sandbox / AI Lab), and stronger AI supply-chain resilience under the UK Critical Third-Party regime. Reinforces (does not contradict) the thesis and pairs directly with the same day’s ESA frontier-AI statement S-2026-07-31-esas-frontier-ai-statement — the same concerns from the industry side. Date caveat: 24 June 2026, outside the strict past-7-day window but not previously ingested; figures are from the public summary (full report gated ⚠️). Authority medium (credible trade body; self-selected contributors, promotional framing). Added as this banner, a Key Point and a Detail subsection. [S-2026-06-24-techuk-agents-of-change]

Updated 2026-07-28 (second update this day; AI-governance vendor-intelligence scan) based on S-2026-07-22-domino-enterprise-ai-report — Domino Data Lab’s Fifth Annual Enterprise AI Report (released 22 Jul 2026; fieldwork by BARC Research, n=639 senior enterprise AI leaders, NA/UK/continental Europe, fielded Apr 2026, sectors incl. FS & insurance) adds the first cut on this page to quantify the governance dividend on agentic AI: 41% of organisations pilot (12%) or scale (29%) agentic AI without the governance to manage it, while organisations whose governance fully keeps pace are 3.9x as likely to reach governed agentic production (67.5% vs 17.2%) and 3x as likely to report significantly improved delivery velocity (75% vs 23%). FS/banking/insurance lead every vertical on governance maturity and production velocity (“built governance infrastructure first, then scaled”) — a relative-leadership finding that echoes, and shares the caveat of, the Coastal “FS leads formal frameworks” claim; and Europe reports the lowest fully-integrated-governance rate (42.6% vs ~51% NA/UK). Also refreshes the ROI-plateau datum: 57% say ROI fails to outpace spend, unchanged since 2025, even as production capability rises (93%). Reinforces the adoption-outpaces-governance thesis and adds the governance-velocity correlation; the causal direction (“govern early → scale faster”) is the source’s reading of a correlation, preserved as such. Authority medium (vendor-commissioned, independently fielded by BARC, methodology published, gated report; ingested via Computer Weekly analysis — primary release provenance-blocked). Added as Key Points, a Detail subsection, an Open Question and a Source entry. [S-2026-07-22-domino-enterprise-ai-report]

Updated 2026-07-28 based on S-2026-07-21-arctera-ai-governance-2026 (daily vendor-intelligence scan) — Arctera’s State of AI Governance 2026 (released 21 July 2026; Hanover Research survey, n=500 compliance decision-makers/influencers, Americas + EMEA, finance/healthcare/energy-utilities, fielded May 2026) adds a compliance-function, communications-governance cut that reframes the gap as a policy-vs-proof gap: 55% have core AI policies, training and review in place but only 19% have the logging, retention, detection and scoring controls “needed to prove what happened”, while 78% expect AI communications risk to rise over 12–24 months and 60% say compliance is primarily accountable for AI governance. Its 71% “very or extremely prepared to produce a defensible audit trail” figure lands directly in the existing confidence-vs-maturity Tension (a second self-reported-confidence outlier alongside Deloitte’s 96%) and is added there, not smoothed. Reinforces the evidence-layer thesis; does not contradict any existing claim. Authority low (vendor-commissioned by an archiving/comms-compliance vendor whose product narrative the “evidence layer” framing serves; panel-recruited; gated report; cross-sector). Added as Key Points, a Detail subsection, a Tensions datum and a Source entry. [S-2026-07-21-arctera-ai-governance-2026]

Updated 2026-07-27 based on S-2026-07-23-deloitte-cfo-signals-q2-2026 (daily regulatory-intelligence scan, practitioner signal) — Deloitte’s Q2 2026 CFO Signals Survey AI-governance release (23 July 2026; n=200 North American CFOs at ≥$1bn-revenue companies, fielded 22 May–7 June 2026) adds a large-company, cross-sector, CFO-owner cut. It partly cuts against the maturity-gap headline on stated confidence96% of CFOs are “somewhat or very confident” in their AI governance framework and 93% use AI across key operations — while reinforcing it on substance: 59% name balancing deploy-fast pressure against risk as their top governance-framework barrier, 51% cite a lack of governance authority, 43% insufficient visibility into AI tools, and only 19% of CFOs own AI governance (behind CISOs/CIOs). The confidence figure is surfaced (not resolved) as a new Tensions entry — “somewhat or very confident” is a lower bar than the “highly developed” readings elsewhere, and the population is non-FS corporate finance. Authority medium (credible firm; North American, cross-sector, CFO-function — not FS/CDO/CRO-specific). Added as a Key Point, a Detail subsection, a Tensions entry and a Source entry. [S-2026-07-23-deloitte-cfo-signals-q2-2026]

Updated 2026-07-24 based on S-2026-07-21-avalara-agents-of-change (daily regulatory-intelligence scan, practitioner signal) — Avalara’s July 2026 survey of 1,500+ CFOs and senior finance leaders (US, UK, India, Australia) who have deployed/piloted/evaluated AI agents adds a mid-2026, finance-function cut to the 2026 “adoption outpaces governance” convergence: 92% feel career pressure to show AI-agent ROI (half “significant”) while half report only limited measurable ROI to date, and the report’s central framing is that “the race to deploy AI agents is outrunning financial governance” — controls and accountability lag deployment. Reinforces the existing thesis (and the Coastal / Oxford Economics ROI-and-measurement finding) from an agentic-automation-in-finance angle; does not contradict any existing claim. Authority low (vendor-commissioned — Avalara is a tax-compliance software vendor — self-reported, finance-function not specifically CDO/CRO respondents) — directional corroboration only. Added as a Key Point, a Detail subsection and a Source entry. [S-2026-07-21-avalara-agents-of-change]

Updated 2026-07-03 based on Weekly Briefing — 3 July 2026 (own-writing weekly synthesis) — records a cross-lens confirmation of the fragmented-ownership datum already on this page: three unrelated 2026 methodologies now converge on “no clear owner for AI-related risk” — EMA DSPM (security-team lens; [S-2026-06-30-ema-dspm-ai-data-security]), Coastal / Oxford Economics (AI-operations lens; ~55% of FS on informal/still-building frameworks while 25% run fully autonomous AI) and Bank Director (board lens; a third don’t understand agentic AI). The briefing reads this convergence as the Independent Governance Assurance demand case stated three ways. No existing claim changed; reinforcing only [S-2026-07-03-weekly-briefing].

Updated 2026-07-01 based on S-2026-06-30-ema-dspm-ai-data-security (daily vendor-intelligence scan, read-across) — EMA’s 30 June 2026 research “Leveraging DSPM and AI to Solve Data Security Challenges” (n=225 North American IT/security/data-governance leaders; sponsor-funded) adds a data-security-posture cut to the 2026 convergence: AI-governance accountability is fragmented across IT (30.2%), security (29.8%), CDOs (20%) and governance committees (18.7%) — “no clear ownership” — and securing AI data flows is now the #1 DSPM investment driver (64.4%, overtaking exfiltration prevention). Reinforces the adoption-outpaces-governance / ownership-gap thesis from a DSPM angle and gives the “fragmented ownership” problem an independent datum. Authority medium (credible analyst firm, but sponsor-funded, North American, gated) — directional for EU/UK. Added as a Key Point, a Detail subsection and a Source entry; no existing claim changed. Updated 2026-06-30 based on S-2026-06-26-precisely-ai-readiness-report (daily vendor-intelligence scan, read-across) — Precisely’s 2026 State of Data Integrity and AI Readiness report (with Drexel University’s LeBow College of Business) adds another 2026 research data point to the convergence: “confidence in AI is high but readiness is not”, with data integrity (governance, quality, integration, enrichment) positioned as the foundation for trustworthy AI. Reinforcing, not contradicting, the adoption-outpaces-readiness thesis. Authority low (vendor-sponsored survey; no specific figures, sample or FS cut retrieved) — directional corroboration only. Added as a Key Point and a Sources entry; no existing claim changed. Updated 2026-06-30 based on Oxford Economics — 2026 AI Operations Survey (financial services cut) (S-2026-06-24-coastal-ai-operations-fs) — daily regulatory-intelligence scan, practitioner signal: a US survey conducted with Oxford Economics (n=150 FS firms within an 800-org, AI-active sample) adds a post-deployment “AI operations” cut to the 2026 convergence. FS leads all sectors on autonomous-AI deployment (25% fully autonomous in production vs 11% across the full sample) yet ~55% remain on informal or still-building AI frameworks (~30% informal + ~25% building), with 61% reporting an ROI shortfall and 71% post-launch data accuracy/availability issues — relocating the binding constraint from deployment to running AI well after launch and to the moving autonomy-vs-human-oversight boundary. Added as Key Points, a Detail subsection and an Open Question; reinforcing, not contradicting, the existing maturity-gap thesis. Authority low (vendor survey, self-reported, gated, US/AI-active sample) — directional corroboration only. The official daily sources carried no new governance items this run: EBA latest is the 22 June ESG disclosure ITS (already ingested); BCBS latest is the d608 consolidated-guidelines consultation (closed 26 June, already ingested); EU AI Office high-risk classification draft guidelines consultation closed 23 June with no newer item; the most recent FCA item is CP26/23 (29 June, Consumer Duty scope — captured on FCA, not AI-specific). Updated 2026-06-29 based on Bank Director — 2026 Risk Survey “AI Exposes Threats, Knowledge Gaps” (S-2026-03-30-bank-director-risk-survey) — daily regulatory-intelligence scan: gave a dedicated Source page to Bank Director’s 2026 Risk Survey (Baker Tilly-sponsored, 30 Mar 2026, US bank boards/CROs), which back-fills the previously un-tagged “a third do not understand agentic AI” claim on this page. Adds a US bank-board cut to the 2026 adoption-outpaces-governance convergence: AI-fraud against customers is the top AI concern (84%), board agentic-AI literacy is the named gap, and “governance from the very beginning” is the practitioner prescription. Note the survey’s regulatory-risk-receding finding (28%, down from 55%) is the inverse of the UK/EU supervisory direction — flagged as a US-specific divergence, not a contradiction of the maturity-gap thesis. The official daily sources (EBA, FCA, BCBS, EU AI Office) carried no new items this run (most recent relevant items already captured; 27–29 Jun was a weekend). Updated 2026-06-26 based on S-2026-06-22-gartner-mq-ai-governance-platforms — daily vendor-intelligence scan: added a cross-reference to the new AI Governance Platforms topic. Gartner’s inaugural Magic Quadrant for AI Governance Platforms (June 2026) formalises the vendor-tooling category firms deploy to close this gap (AI-asset inventory, EU AI Act control mapping, runtime oversight). No existing claim changed; cross-reference only. Updated 2026-06-11 based on S-2026-06-mckinsey-ai-trust — McKinsey “State of AI trust in 2026: Shifting to the agentic era” (AI Trust Maturity Survey, ~500 organisations, fielded Dec 2025–Jan 2026) given a dedicated Source page, back-filling the previously un-tagged McKinsey citations on this page. Adds that average responsible-AI maturity rose to 2.3 (from 2.0 in 2025) but only ~one-third of firms reach maturity level 3+ in strategy, governance and agentic-AI governance, and that financial services leads on RAI maturity on the strength of its risk-management and data foundations — reinforcing, not contradicting, the data-substrate thesis. Source date unconfirmed (see Source page ingestion note). Updated 2026-06-10 based on S-2026-06-09-csa-fs-ai-governance — Cloud Security Alliance “State of Cloud and AI for Financial Services 2026” (n=340 FS professionals worldwide, released 9 June 2026, commissioned by Anjuna) added; reinforces the adoption-outpaces-governance signal from an agentic-autonomy and incident-visibility angle (62% have deployed AI agents and 93% of agent-users grant them some autonomy, yet 20% had a known AI-security incident and 21% did not know — a visibility gap; sensitive-data leakage is the top AI security concern at 61%). Added as Key Points, a Detail subsection and an Open Question on vendor-commissioned-survey reliability. Reinforcing, not contradicting, the existing convergence. Updated 2026-06-08 based on S-2026-05-27-wolters-kluwer-ai-risk-governance-index — Wolters Kluwer H1 2026 US Banking AI Risk and Governance Index (n=230 senior banking risk/compliance/AI leaders, 27 May 2026) added; corroborates the adoption-outpaces-governance signal from a US-banking, model-risk-and-incident-readiness angle (model governance/validation as the #1 scaling barrier; synthetic-data and automated DQ errors as the dominant data risk; >70% weakest on regulatory reporting and model kill-switch readiness; automation bias as the leading human-centric risk). Added as Key Points, a Detail note, and an Open Question on US-vs-UK/EU generalisability. Updated 2026-06-05 based on S-2026-06-05-weekly-briefing — weekly synthesis: five independent practitioner surveys (CCAF, KPMG, Grant Thornton, Informatica, ProSight) landed in a single week, all converging on data and governance maturity (not model capability) as the binding constraint; the briefing reads this convergent body as the market-demand evidence base for Paul’s Taxonomy Knowledge Tool (whose design premise is exactly the data-substrate problem the surveys name), and adds a relates-to edge to that project on that basis. Updated 2026-06-04 based on S-2026-06-kpmg-global-ai-finance — KPMG 2026 Global AI in Finance Report (n=1,013 finance leaders, fielded March 2026) given a dedicated Source page; its finding that agentic-AI deployers separate from peers by ~32pp on performance adds a separation dimension to the maturity gap (the dividend concentrates in firms that operationalise — and must govern — agentic AI). Scoped as cross-sector finance-function research, distinct from the unconfirmed “$10–50m per firm” KPMG spend figure already on this page. Updated 2026-06-03 based on S-2026-05-gt-ai-impact-banking — Grant Thornton 2026 AI Impact Survey (banking cut) given a dedicated Source page; its finding that banks are the industry most likely to report untested AI controls, with only ~18% fully confident in their AI controls, now properly attributes the previously loosely-cited ~18% figure to a named survey. Updated 2026-06-02 based on S-2026-01-27-informatica-cdo-insights-2026 — dedicated Source page created for the Informatica CDO Insights 2026 survey; its figures (76% governance-lag; 86% increasing data-management investment; 41% prioritising AI governance) were previously cited without an S-tag and are now sourced, satisfying the schema’s attribution rule. Updated 2026-06-01 based on S-2025-11-prosight-cro-outlook-2026 — ProSight 2026 CRO Outlook figures (12% “highly developed” AI governance; 54% AI in production; project blockers — staff capability 30%, data quality 27%, immature risk framework 26%) given a proper S-tag and integrated; back-fills a prior citation gap. Updated 2026-05-29 based on S-2026-05-29-weekly-briefing — weekly-synthesis connection added: this week’s data-as-AI-risk captures (BIS FSI 73, CCAF) and the EBA reporting-simplification consultation share one through-line on governing and evidencing the data substrate. Updated 2026-05-29 based on S-2026-05-04-grant-thornton-treasury-urgency — Grant Thornton practitioner commentary integrated; reinforces practitioner consensus that the maturity gap is a near-term supervisory and commercial exposure. Updated 2026-05-28 based on S-2026-04-ccaf-global-ai-fs-report — Cambridge CCAF 2026 Global AI in FS Report citation back-filled and additional findings integrated.

TL;DR

A consistent practitioner signal across 2026 industry surveys is that AI adoption is outpacing governance maturity. Only ~18% of banking leaders are confident they could pass an independent review of AI controls within 90 days; only ~12% of CROs describe their AI governance framework as “highly developed”; 76% of organisations report governance is not keeping pace with AI usage. Boards and senior leaders lack readiness for agentic AI specifically. This gap is the practice’s positioning opportunity — demand is rising for independent assurance over AI inventories, model accountability, and data-governance evidence, not more policy documents.

Key Points

  • Agent-control confidence runs 30–55 points ahead of evidenced controls (cross-sector engineering leadership, 2026): 77% inventory confidence vs 44% discovery tooling; 76% kill-switch confidence vs 33% instant kill switch; 74% testing confidence vs 19% automatic gate; “secure end to end” respondents had incidents at 88% vs 87% overall (Harness / Sapio, n=700, US/UK/FR/DE/IN, July 2026; vendor-commissioned; committed adopters only) [S-2026-09-10-harness-state-of-agent-dlc-2026].
  • ~18% of banking leaders are fully confident they could pass an independent review of AI controls within 90 days; ~50% cite governance / compliance as a barrier to AI performance (Informatica CDO Insights 2026; Grant Thornton; Cambridge CCAF 2026 Global AI in Financial Services Report) [S-2026-03-23-fifai-ii-agile][S-2026-04-ccaf-global-ai-fs-report][S-2026-01-27-informatica-cdo-insights-2026][S-2026-05-gt-ai-impact-banking].
  • Banks are the industry most likely to report untested AI controls, and only ~18% of banking respondents say they are fully confident in their AI controls (Grant Thornton 2026 AI Impact Survey, banking cut) [S-2026-05-gt-ai-impact-banking]. (This ~18% “fully confident in AI controls” figure and the “pass an independent review within 90 days” framing above may be the same underlying signal measured differently; not yet reconciled — see Open Questions.)
  • Data availability and quality is the leading constraint on AI adoption, cited by 66% of AI vendors, 46% of regulators, and 40% of industry; 72% of vendors cite data quality and completeness with their clients; 46% cite legacy systems and siloed environments; 41% cite data-sharing restrictions [S-2026-04-ccaf-global-ai-fs-report].
  • Data privacy and protection is the top perceived risk across all stakeholders — 73% of respondents [S-2026-04-ccaf-global-ai-fs-report].
  • Vendor-versus-firm gap on adversarial AI and resilience: AI vendors place less priority than industry and regulators on both adversarial AI threats (35% vs 50% industry, 57% regulators) and cyber / operational resilience (32% vs 46% industry, 59% regulators) [S-2026-04-ccaf-global-ai-fs-report].
  • 95% of surveyed architects report AI projects delayed or cancelled over data governance, compliance or regulatory challenges (Cloudera global survey, n=1,500 enterprise/cloud/data architects, Aug 2026) — the highest project-stopper figure on this page, though its denominator and timeframe are unretrieved and the source is a twice-relayed vendor survey [S-2026-08-14-cloudera-ai-rearchitecture-survey].
  • 57.3% of organisations are piloting or operating AI agents, but only 8.4% say the data feeding those systems is “sufficiently trustworthy for production” — the widest adoption-versus-data-trust spread recorded on this page, with data quality and trust, missing context and lineage, and security all ranked above skills and tooling as barriers (The Modern Data Company interim survey, n=540+ data leaders, reported week of 21 Aug 2026). ⚠️ Low authority: the vendor sells a governed-context product that the finding supports, and methodology, geography, industry mix and the definition of “sufficiently trustworthy” are all undisclosed; ingested via a trade-press roundup, primary release not fetched [S-2026-08-21-solutionsreview-dm-roundup].
  • ~12% of CROs describe their AI governance and approvals framework as “highly developed” (ProSight 2026 CRO Outlook Survey) [S-2025-11-prosight-cro-outlook-2026].
  • 54% of banks have AI in production; 48% plan AI deployment in risk functions within two years [S-2025-11-prosight-cro-outlook-2026].
  • AI projects are most held back by limited staff capability / training (30%), data quality and availability (27%), and immature risk-management frameworks (26%) — i.e. the binding constraints are people, data and framework maturity, not the technology [S-2025-11-prosight-cro-outlook-2026].
  • 76% of organisations report AI governance is not keeping pace with employee AI usage; GenAI integration has risen to 69% of companies (from 48% a year earlier) [S-2026-01-27-informatica-cdo-insights-2026].
  • Three out of four organisations admit governance has not kept pace with AI adoption [S-2026-01-27-informatica-cdo-insights-2026]; data quality is the top barrier (cited by 66% of AI vendors and 46% of regulators) [S-2026-04-ccaf-global-ai-fs-report].
  • 75% of data leaders say employees need data-literacy upskilling and 74% need more AI-literacy training to use AI responsibly [S-2026-01-27-informatica-cdo-insights-2026]. (Earlier wiki phrasing cited “61% trust / 96% need training / 57% of CDOs / 93% critical”; these specific figures could not be confirmed against the Informatica 2026 release retrieved this run and are flagged for re-checking — see Open Questions.)
  • A third of respondents (US bank CEOs, directors, CROs and senior executives) say they do not understand agentic AI — autonomous decision-making AI — at all, despite reporting baseline understanding of machine learning, AI use cases and data governance; Bank Director and Baker Tilly frame this as a board-governance gap, arguing “governance needs to be part of the conversation from the very beginning” (Bank Director 2026 Risk Survey, sponsored by Baker Tilly) [S-2026-03-30-bank-director-risk-survey].
  • AI-enabled fraud is the dominant AI concern among US bank leaders: fraud/scams targeting customers (84%) and the organisation itself (77%) far outrank the competitive threat from other institutions and nonbanks (38%); 20% believe their bank or its customers were already hit by AI/deepfake fraud in the prior 18 months [S-2026-03-30-bank-director-risk-survey].
  • Strategic-risk concern rose to 42% (from 30% a year earlier) — attributed partly to AI-driven competitive change and fintechs seeking bank charters — while regulatory-risk concern fell to 28% (from 55%) under a friendlier US supervisory posture; the regulatory-risk-receding finding is the inverse of the UK/EU direction and is US-specific (Bank Director 2026 Risk Survey) [S-2026-03-30-bank-director-risk-survey].
  • Only about one-third of firms report maturity level 3+ in strategy, governance and agentic-AI governance — i.e. only ~30% at level 3+ on agentic AI controls; average responsible-AI maturity rose to 2.3 in 2026 (from 2.0 in 2025), and TMT and financial services lead on RAI maturity, driven by stronger risk-management and data foundations (McKinsey “State of AI trust in 2026: Shifting to the agentic era”, ~500 organisations) [S-2026-06-mckinsey-ai-trust].
  • Leading firms are 1.7× more likely to have a Responsible AI framework [S-2026-03-23-fifai-ii-agile].
  • 86% of firms increasing data management investment; top drivers data privacy/security (43%), data & AI governance (41%), and data/AI literacy upskilling (39%) [S-2026-01-27-informatica-cdo-insights-2026].
  • KPMG-cited spend of $10–50m per firm being directed at securing agentic architectures, hardening data lineage, and tightening model governance. (Source not yet confirmed; not established as originating from the KPMG 2026 Global AI in Finance Report — see Open Questions.)
  • Agentic-AI performance separation: organisations deploying agentic AI in the finance function separate from peers by ~32 percentage points on average (rising to ~40 on forecast accuracy and ROI), with reported gains in decision-making quality (70%), decision-making speed (71%) and forecasting accuracy (64%) (KPMG 2026 Global AI in Finance Report, n=1,013 finance leaders, fielded March 2026) [S-2026-06-kpmg-global-ai-finance]. The maturity gap therefore has a widening-divergence character: the dividend concentrates in firms that can operationalise — and so must govern — agentic AI. (Cross-sector finance-function survey, not bank-governance-specific; correlation not established as causation — see Open Questions.)
  • Grant Thornton (4 May 2026) frames the US Treasury AI Risk Framework for Financial Services as a catalyst that makes AI “a core risk issue for financial institutions” and argues banks must “embed governance now or face regulatory gaps and weaker performance” [S-2026-05-04-grant-thornton-treasury-urgency].
  • The Grant Thornton article reinforces the practitioner consensus already established by Cambridge CCAF, Oliver Wyman / ProSight, McKinsey, and Informatica that the maturity gap is a near-term supervisory and commercial exposure, not a future-looking concern [S-2026-05-04-grant-thornton-treasury-urgency].
  • More than one-third of US banking institutions name model governance and validation as the primary barrier to scaling AI — ahead of fairness and explainability “by a significant margin” (Wolters Kluwer H1 2026 US Banking AI Risk and Governance Index, n=230 senior leaders) [S-2026-05-27-wolters-kluwer-ai-risk-governance-index].
  • Nearly two-thirds of data-risk concern concentrates in synthetic-data misrepresentation and automated data-quality errors, framed as a shift toward compounded, system-level data risk; and over 70% of institutions report weakest preparedness in regulatory reporting and model kill-switch capabilities — the incident-response functions Wolters Kluwer argues regulators will demand first [S-2026-05-27-wolters-kluwer-ai-risk-governance-index].
  • Automation bias is the leading human-centric AI risk (surpassing incentives and skills gaps), making governance design a behavioural as well as technical problem; collections and recovery ranks as the highest-risk function for AI-driven customer harm (>10pp ahead of credit risk / underwriting) [S-2026-05-27-wolters-kluwer-ai-risk-governance-index].
  • 62% of FS organisations have already deployed AI agents and 93% of agent-users have granted them some form of autonomy, yet many lack visibility into AI-related risk: 20% reported a known AI-security incident and a further 21% did not know whether one had occurred — an incident-visibility gap of ~41% (CSA “State of Cloud and AI for Financial Services 2026”, n=340 FS professionals) [S-2026-06-09-csa-fs-ai-governance].
  • “AI risk is a data problem”: sensitive-data leakage through AI interactions is the top AI security concern (61%), far exceeding model attacks or adversarial techniques — corroborating the data-substrate framing of this page from a security angle [S-2026-06-09-csa-fs-ai-governance].
  • CSA frames the sector as having shifted from debating AI adoption to grappling with how to govern it “before autonomy outstrips control”, with executive support high (91% report moderate-to-strong leadership backing) but visibility, identity governance and real-time controls lagging deployment [S-2026-06-09-csa-fs-ai-governance].
  • Financial services leads all sectors on autonomous-AI deployment — 25% run fully autonomous AI in production, more than double the 11% rate across the full 800-organisation sample — yet ~30% still operate on informal AI guidelines and a further ~25% are still building their frameworks (a combined ~55% on informal/immature frameworks), described as “a gap where regulatory and reputational risk accumulates” (Coastal / Oxford Economics 2026 AI Operations Survey, FS cut, n=150) [S-2026-06-24-coastal-ai-operations-fs]. (Sits in tension with the same source’s claim that FS “leads the survey on formal AI governance frameworks” — relative leadership vs absolute immaturity; see Open Questions.)
  • 61% of FS firms say AI has fallen short of expected ROI, 71% report data accuracy or availability issues affecting AI performance after launch, and 68% cite internal team bandwidth as the biggest limiter on pilots (wealth management highest at 82%) — the source locates the binding constraint in post-deployment AI operations rather than getting AI deployed [S-2026-06-24-coastal-ai-operations-fs].
  • 45% of FS firms measure AI success primarily through user-reported time savings / efficiency — “metrics that imply savings but don’t prove a return” — i.e. an evidencing/measurement gap as well as a controls gap [S-2026-06-24-coastal-ai-operations-fs].
  • Confidence in AI is high but readiness is not, with data integrity (governance, quality, integration, enrichment) positioned as the foundation for trustworthy AI — another 2026 research source landing on the adoption/ambition-outpaces-readiness conclusion (Precisely 2026 State of Data Integrity and AI Readiness, with Drexel LeBow; vendor-sponsored, no specific figures or FS cut retrieved — directional only) [S-2026-06-26-precisely-ai-readiness-report].
  • AI-governance accountability is fragmented — “no clear ownership”: responsibility for AI-related data risk is split across IT (30.2%), security teams (29.8%), CDOs (20%) and governance committees (18.7%), and securing AI data flows is now the #1 driver of DSPM (Data Security Posture Management) investment at 64.4%, overtaking exfiltration prevention (56%) for the first time; 45.3% cite inconsistent multi-cloud policy (residency/key-management) as their top concern (EMA “Leveraging DSPM and AI to Solve Data Security Challenges”, n=225 North American leaders, sponsor-funded — directional for EU/UK) [S-2026-06-30-ema-dspm-ai-data-security].
  • The agentic-AI deployment-vs-governance gap now shows up as ROI pressure: among 1,500+ CFOs / senior finance leaders using AI agents, 92% feel career pressure to demonstrate AI-agent ROI (half “significant”) yet half report only limited measurable ROI to date, with Avalara framing the pattern as “the race to deploy AI agents is outrunning financial governance” — accountability and internal controls lagging deployment (Avalara “Agents of Change”, July 2026, US/UK/India/Australia; vendor-commissioned, finance-function respondents — directional only) [S-2026-07-21-avalara-agents-of-change].
  • Stated CFO confidence in AI governance is high even as the substantive gaps persist: in Deloitte’s Q2 2026 CFO Signals release (n=200 North American CFOs at ≥$1bn-revenue firms), 96% say they are “somewhat or very confident” in their AI governance framework and 93% use AI across key operations, yet 59% name balancing deploy-fast pressure against risk as their top governance-framework barrier, 51% cite a lack of governance authority, 43% insufficient visibility into AI tools/use, and only 19% of CFOs claim primary ownership of AI governance (behind CISOs and CIOs) [S-2026-07-23-deloitte-cfo-signals-q2-2026]. (The 96%-confident figure sits in tension with the “highly developed” readings elsewhere — see Tensions. The confidence bar differs and the population is non-FS corporate finance.)
  • Litigation over protected/private content is the top external AI concern for CFOs (43%), ahead of cybersecurity (41%) and regulatory complexity (36%); the biggest internal concern is cost uncertainty / transparency (46%) (Deloitte Q2 2026 CFO Signals) [S-2026-07-23-deloitte-cfo-signals-q2-2026]. (The content-litigation concern may connect to the AI Act’s GPAI copyright-policy / training-data-summary obligations tracked on EU AI Act — flagged, not asserted.)
  • The policy layer now outruns the evidence layer: 55% of regulated organisations have core AI policies, training and review steps in place, but only 19% have the logging, retention, detection and scoring controls “needed to prove what happened” with AI-assisted communications and decisions — without which they “cannot confidently demonstrate what AI produced, who reviewed it, where it went and whether the record was kept” (Arctera State of AI Governance 2026, Hanover Research survey, n=500 compliance decision-makers/influencers, Americas+EMEA, cross-sector incl. finance; vendor-commissioned — directional only) [S-2026-07-21-arctera-ai-governance-2026].
  • A Big Four assurance provider’s own research restates the gap while expanding to compete in the same market: Deloitte’s 12 Aug 2026 “State of AI in the Enterprise” report finds 74% of companies plan to deploy agentic AI within two years, but only 21% report a mature governance model for autonomous agents, cited to launch expanded end-to-end “AI Controls and Assurance” services (governance/risk frameworks, model validations, standards-based readiness assessments, and “regulatory readiness” including SOC reports and certifications) — no regulatory standard is named in the release, and the figure is not independently verified [S-2026-08-12-deloitte-ai-controls-assurance].
  • The policy-to-proof gap, quantified for financial services: an AAA-ICDR Institute study (relayed by Technology Reseller, 12 Aug 2026) reports 96% of FS respondents have formal AI governance policies, only 53% have translated them into specific technical controls, and just 21% are “very confident” they could produce centralised, complete and auditable evidence for regulators, auditors or courts — the near-universal-policy / thin-evidence pattern in an FS-specific cut. Reinforces Arctera’s cross-sector “55% policy vs 19% proof” and the confidence-vs-maturity Tension. Low authority / partial traceability: trade-press relay of a study not directly retrieved; figures from a WebSearch summary, not independently confirmed (⚠️) [S-2026-08-12-tech-reseller-aaa-icdr-ai-governance-gap].
  • 78% expect AI communications risk to rise over the next 12–24 months, 45% say AI is core or extensively used in regulated workflows, and 60% say compliance is primarily accountable for AI governance — a compliance-function ownership reading that contrasts with the fragmented IT/security/CDO split EMA found (see Detail) (Arctera 2026) [S-2026-07-21-arctera-ai-governance-2026].
  • 41% of organisations are piloting (12%) or scaling (29%) agentic AI without the governance to manage it — those scaling ungoverned outnumber those piloting >2:1 — while 43% have agentic AI in governed production; organisations whose governance fully keeps pace with AI activity are 3.9x as likely to reach governed agentic production (67.5% vs 17.2%) and fully-integrated-governance firms are >3x as likely to report significantly improved AI delivery velocity (75% vs 23%) (Domino Fifth Annual Enterprise AI Report, BARC Research fieldwork, n=639, NA/UK/Europe, Apr 2026) [S-2026-07-22-domino-enterprise-ai-report].
  • FS, banking and insurance lead every vertical measured on both governance maturity and production velocity — the report’s reading is that these firms “built governance infrastructure first, then scaled” (a causal gloss on a correlation, preserved as the source’s own); Europe reports the lowest fully-integrated-governance rate of the three regions (42.6% vs ~51% NA/UK), with nearly half of European organisations piloting/scaling agentic AI ungoverned; the enterprise AI ROI plateau persists — 57% say ROI fails to outpace spend, unchanged since 2025, even as 93% report improved production capability [S-2026-07-22-domino-enterprise-ai-report].
  • A UK industry-body cut names the same gap from the deployment side: techUK’s “Agents of Change: Generative and Agentic AI in Financial Services 2026” reports 61% of surveyed firms using or assessing generative AI and 42% agentic AI in 2025, with agentic AI “moving from experimentation to live deployment”, and frames the open question as whether governance, assurance and operational-resilience frameworks can keep pace; it names behavioural drift, human oversight at scale, AI supply-chain concentration and cyber resilience as the live governance challenges and calls for a dedicated agentic-AI governance workstream (BoE/FCA AI Consortium), expanded shared testing (FCA Supercharged Sandbox / AI Lab) and stronger AI supply-chain resilience under the UK Critical Third-Party regime (techUK, 24 June 2026; member-sourced, promotional framing, full report gated — directional only) [S-2026-06-24-techuk-agents-of-change].
  • The gap is now framed as examination risk under existing rules, across three jurisdictions: ACA Group (via FinTech Global, 17 Aug 2026) reports the SEC’s 2026 Examination Priorities embedding AI oversight, FINRA’s 2026 oversight report demanding evidence of testing, supervision, governance, vendor diligence and recordkeeping for AI tools, the FCA relying on principles-based adaptation of existing rules, and a DFSA circular to all DIFC-authorised firms on governance/accountability, risk, operational risk and third-party arrangements; ACA’s survey adds that 84% of compliance/ops professionals use desktop AI tools while the average firm applies AI in fewer than two of 20 surveyed functions (⚠️ ACA’s own survey, methodology undisclosed; regulator characterisations are ACA’s summaries) [S-2026-08-17-aca-ai-governance-examination-priority].
  • A Big Four banking-specific survey quantifies the gap after go-live and in agentic AI: Deloitte’s “Banking on Trust” (14 Aug 2026; 135 respondents across G-SIBs/D-SIBs and other large banks) finds weekly AI use among bank employees doubled to 63% (from 30% in 2025) while only 13% of banks reach “optimized” AI-governance maturity and 87% have scope to strengthen; the weakest pillars are organisational structure and people/skills (not procedures); and controls thin post-deployment — 72% apply mandatory controls at design but only 55% at monitoring, 72% have under half their AI use cases in a central register, and only 44% have lifecycle risk monitoring for agentic AI (vs 61% traditional, 59% generative). Deloitte reports optimized banks run far more AI in production (5.5 vs 0.7 fully-implemented solutions) and finds a governance–revenue association (10-point Governance-Index rise ≈ 10pp higher revenue growth) it explicitly cautions is not causal. Reinforces the thesis and adds the sharpest lifecycle/agentic-monitoring cut on this page. Authority medium / date caveat: self-reported, gated, G-SIB/D-SIB-weighted, relayed via The Financial Brand; report dated 14 Aug 2026 (just outside the 7-day window, not previously ingested) [S-2026-08-14-deloitte-banking-on-trust].
  • The maturity gap is an operating-model gap, not a technology gap: across structured interviews with the sitting Chief AI Officer (or equivalent) at 42 banks and insurers (24 banks incl. 11 G-SIBs; 18 insurers; >$41tn AUM/in-force), Intelligine Group finds “the dispersion in operating-model maturity … is significantly larger than the dispersion in technology stack” — technology choices are converging while operating models diverge, and the firms with the cleanest operating economics are those with the most disciplined operating model, not the most advanced stack. The discipline shows up in three artefacts: only 19/42 firms have at least one kill criterion specified at the unit-economic level and continuously instrumented (those held their portfolio within 12% of the approved cost envelope over the last fiscal year, vs a 68% median overrun for the 23 without), only 7/42 have a written escalation path that can move from a kill-criterion breach to a decision inside 72 hours without a board calendar event (24 require quarterly board review at the earliest; 11 have no written escalation path at all), and cleanest audit reconciliation occurs where the runtime audit trail and the governance artefact are maintained by separate teams on separate reporting lines. ⚠️ Low authority: single consulting firm’s own primary data, self-described methodology, gated instrument, global G-SIB-weighted with no UK/EU cut; byline Feb 2026 [S-2026-02-intelligine-governance-benchmark].
  • A practitioner three-tier scheme keys AI controls to proximity to a regulated decision: 31 of the 42 firms report a formal tiering scheme (23 three-tier), the modal pattern distinguishing workloads that finalise a regulated decision (tier 1: documented model risk management, instrumented kill criteria at unit-economic and quality level, board-visible escalation, full audit trail), materially influence one (tier 2: documented MRM, unit-economic kill criteria, escalation below board, summary audit trail), and operate outside the regulated surface (tier 3: unit-economic kill criteria, workflow-owner escalation, no formal audit trail) — a concrete operating-model articulation of tiered controls that connects the maturity gap to Model Risk Management and Agentic AI and the evidence-layer thesis [S-2026-02-intelligine-governance-benchmark].
  • Incidents are not slowing adoption, and approval friction is producing shadow AI: OneTrust’s 2026 AI-Ready Governance Report (14 Sep 2026; n=1,200 senior decision-makers in eight countries incl. UK, FR, DE, ES) finds 87% encourage AI-agent use but only 47% have clear governance, oversight and controls, 28% had two or more incidents of AI systems or agents taking unapproved actions, and 86% experienced at least one AI-related incident (vendor-defined basket) — to which organisations most often responded with more training (49%) and least often by pausing or slowing deployment (27%); 33% have seen employees use unapproved AI because sanctioned tools or processes were not available quickly enough; 80% spend more time on AI risk than a year ago (+26% hours) and 98% plan to raise AI-governance technology budgets (+25% average). ⚠️ Vendor-commissioned (OneTrust sells the “runtime” governance the release prescribes), no methodology beyond sample and countries, no EU/UK or FS cut, incident basket not comparable to GDPR/DORA definitions [S-2026-09-14-onetrust-ai-ready-governance-report-2026].

Detail

The pattern across surveys

Every major 2026 practitioner survey lands in the same neighbourhood: a minority of firms describe themselves as ready; agentic AI is poorly understood; data quality and lineage are the dominant blockers. The signal is stable across Informatica (CDO Insights 2026), Oliver Wyman (CRO Outlook 2026), McKinsey (“State of AI trust in 2026”) [S-2026-06-mckinsey-ai-trust], Cambridge CCAF (2026 Global AI in Financial Services Report) [S-2026-04-ccaf-global-ai-fs-report], Grant Thornton, and the FIFAI II forum commentary [S-2026-03-23-fifai-ii-agile].

Implication of the vendor-versus-firm risk-priority gap

The Cambridge CCAF data point that AI vendors materially underweight adversarial-AI threats and cyber / operational resilience relative to industry and regulators has a direct assurance consequence: firms cannot rely on vendor self-assessment of AI risk and must apply independent challenge — particularly to vendor model risk and resilience claims [S-2026-04-ccaf-global-ai-fs-report]. This reinforces the BCBS d605 retention-of-accountability principle and the Three Lines of Defence for AI 2LoD priority.

The convergence in industry framings

Practitioner consensus converges on three immediate priorities: board-level AI risk literacy, model governance / data lineage hardening, and adaptive controls for agentic AI. The FIFAI II AGILE framing — Awareness, Guardrails, Innovation, Learning, Ecosystem Resiliency — is now cited as a practical organising structure for financial services [S-2026-03-23-fifai-ii-agile]. Grant Thornton’s 4 May 2026 commentary adds the framing that US Treasury guidance has converted AI from experiment-stage to core enterprise risk and pushes integrated (rather than parallel) AI governance as the urgent design choice [S-2026-05-04-grant-thornton-treasury-urgency].

The data substrate as the convergence point (week to 29 May 2026)

A cross-source signal across the week’s captures is that the practitioner data-as-AI-risk findings and the supervisory data-architecture agenda are pointing at the same substrate from different directions: BIS FSI 73 and the CCAF survey frame data quality, privacy and lineage as the dominant AI-risk axis, while the EBA’s supervisory-reporting-simplification consultation is actively reshaping the data-architecture substrate banks must evidence — meaning the reporting-simplification work is, for assurance purposes, a data-governance story feeding the same BCBS 239 lineage programmes the AI-governance maturity findings depend on, not merely a compliance-burden reduction [S-2026-05-29-weekly-briefing].

In the single week to 5 June 2026, five independent practitioner surveys were captured — CCAF 2026 Global AI in FS, KPMG 2026 Global AI in Finance, Grant Thornton 2026 AI Impact, Informatica CDO Insights 2026, and ProSight 2026 CRO Outlook — and all land on the same conclusion: the binding constraint on safe AI adoption is data and governance maturity, not model capability [S-2026-06-05-weekly-briefing]. Treated together, this convergent body is the market-demand evidence base for the Taxonomy Knowledge Tool, whose design premise (ECB-driven attribute-level lineage for in-scope CDEs) directly addresses the data-substrate problem the surveys name — the demand case and the product were captured the same week [S-2026-06-05-weekly-briefing]. Separately, the FCA AI Input Zone (call for views, closing 19 June 2026) opens a supervisory channel for exactly the working-controls evidence these surveys show almost no firm can yet supply, which is the Independent Governance Assurance opportunity stated precisely: firms (and advisers) able to evidence working controls now help shape the forthcoming “good practice” benchmark [S-2026-06-05-weekly-briefing].

The US-banking corroboration and where its emphasis differs (27 May 2026)

The Wolters Kluwer H1 2026 US Banking AI Risk and Governance Index (n=230 senior banking risk, compliance and AI leaders) adds a US-banking datapoint to the 2026 convergence and corroborates the headline signal — adoption has outpaced governance maturity, with deployment now embedded across credit, fraud, compliance and collections [S-2026-05-27-wolters-kluwer-ai-risk-governance-index]. Its emphasis differs in instructive ways from the UK/EU/global surveys already on this page: it puts model governance and validation (not data quality) as the single largest barrier to scaling AI, and foregrounds operational readiness — regulatory reporting and model kill-switch capabilities, where over 70% report the weakest preparedness — as the binding constraint on safe scaling. It also elevates two risks the other surveys under-weight: synthetic-data integrity (two-thirds of data-risk concern, alongside automated DQ errors) and automation bias as the leading human-centric risk. The data-risk and operational-readiness findings reinforce the same data-substrate and 2LoD/3LoD assurance themes named elsewhere on this page; the model-governance-first framing is a US-banking emphasis that may or may not transfer to UK/EU firms (see Open Questions) [S-2026-05-27-wolters-kluwer-ai-risk-governance-index]. Caveat (in source framing): the figures are self-reported and the full Index is gated, so the headline percentages are not independently verifiable from the public page.

The agentic-autonomy and visibility dimension (9 June 2026)

The Cloud Security Alliance’s “State of Cloud and AI for Financial Services 2026” (n=340 FS professionals worldwide, vendor-commissioned by Anjuna) adds an agentic-autonomy and incident-visibility cut to the 2026 convergence [S-2026-06-09-csa-fs-ai-governance]. It corroborates the headline signal — adoption has outpaced governance — but locates the gap specifically in control visibility over autonomous agents: 62% have deployed AI agents and 93% of agent-users have already granted them some autonomy, while a combined ~41% either had a known AI-security incident (20%) or could not tell whether one had occurred (21%). Its “AI risk is a data problem” finding (sensitive-data leakage the top concern at 61%) reinforces the same data-substrate theme the CCAF, Informatica and Wolters Kluwer sources name. The reliability caveat matters: the survey is vendor-commissioned, self-reported and the full report is gated, so the figures are directional rather than authoritative (see Open Questions) [S-2026-06-09-csa-fs-ai-governance]. The agentic-autonomy and “agentic finance” findings are developed further on Model Risk Management and Agentic AI.

The post-deployment “AI operations” cut (24 June 2026)

Coastal’s 2026 AI Operations Survey (conducted with Oxford Economics; n=800 US leaders, FS subset n=150, all AI-active) reframes the maturity gap as an operations problem rather than a deployment problem [S-2026-06-24-coastal-ai-operations-fs]. Its distinctive contribution is to separate “can deploy AI” from “can run AI well after launch”: FS leads every sector on autonomous-AI deployment (25% fully autonomous in production) but reports some of the largest ROI shortfalls (61%), with the failure concentrating post-launch — 71% hit data accuracy/availability issues after go-live, 58% stall at the value-evaluation stage, and 68% are bandwidth-constrained. The governance-specific finding is that ~55% of FS firms are on informal or still-building AI frameworks even as a quarter run fully autonomous AI, and that the autonomy-vs-human-oversight boundary keeps moving as agentic platforms gain capability — so a static policy set decays. This reinforces, from a US AI-active angle, the same data-substrate and adaptive-controls themes the CCAF, Informatica, Wolters Kluwer and CSA sources name, and adds a measurement dimension: 45% still judge AI by user-reported time savings rather than hard business-outcome checkpoints, which is an evidencing weakness directly in scope for independent assurance [S-2026-06-24-coastal-ai-operations-fs]. Caveat (in source / ingestion): vendor survey, self-reported, full report gated, US AI-active sample, respondents “business and technology leaders” (not specifically CDO/CRO) — directional corroboration, not authoritative evidence (see Open Questions). Practitioner inference (not in source): the “~55% on informal/immature frameworks while running autonomous AI” and “45% measuring activity not outcomes” findings are a precise statement of the Independent Governance Assurance demand — firms able to evidence working, outcome-tied controls over autonomous use cases are scarce [inference].

The data-security-posture and accountability-ownership cut (30 June 2026)

EMA’s 2026 research “Leveraging DSPM and AI to Solve Data Security Challenges” (n=225 North American IT, security, data-governance and technology-business leaders; independent but sponsor-funded by F5, IBM, Selcore, Skyhigh Security and Virtru) adds a data-security-posture angle to the 2026 convergence [S-2026-06-30-ema-dspm-ai-data-security]. Its distinctive contribution is to locate part of the maturity gap in ownership: responsibility for AI-related data risk is fragmented across IT (30.2%), security (29.8%), CDOs (20%) and governance committees (18.7%), so “many organizations [are] without clear ownership” — the accountability problem that DORA ICT-risk governance, GDPR data-security accountability and FCA/PRA operational-resilience senior-management ownership expectations are designed to force firms to resolve. It also reports that securing AI data flows has become the top driver of DSPM investment (64.4%, past exfiltration prevention for the first time) and that multi-cloud policy inconsistency — residency controls, key management, security architecture — is the top concern for 45.3%, a data-sovereignty dimension directly relevant to EU-residency requirements. EMA’s analyst framing is that DSPM should be “a prerequisite for AI deployment—rather than an afterthought.” Caveat (in source / ingestion): North American sample, self-reported, full report gated, and sponsor-funded by five security vendors (potential DSPM-tooling framing bias) — directional corroboration, not authoritative EU/UK evidence. Practitioner read (not in source): fragmented ownership of AI-related data risk is precisely the condition Independent Governance Assurance and Governance Framework Design engagements exist to remediate — a named accountability owner and an evidenced RACI is the deliverable [inference].

The US bank-board cut and a divergent regulatory-risk signal (30 March 2026)

Bank Director’s 2026 Risk Survey (sponsored by Baker Tilly; respondents are predominantly US community and regional bank CEOs, directors, CROs and senior executives) adds a board-level cut to the 2026 convergence and, usefully, sources the “a third do not understand agentic AI” figure that previously sat untagged on this page [S-2026-03-30-bank-director-risk-survey]. Its distinctive emphases are (i) AI risk experienced first as a fraud problem — AI/deepfake fraud against customers (84%) and the organisation (77%) dominate AI concern, with 20% already reporting impact — and (ii) the gap located at board literacy: a third of leaders do not understand agentic AI at all, which Baker Tilly argues makes “governance from the very beginning” the binding requirement rather than tooling or policy volume. This reinforces the board-AI-risk-literacy priority already named on this page from the FIFAI II AGILE framing. One finding runs the opposite way to the rest of the corpus and is flagged rather than smoothed: regulatory-risk concern fell to 28% from 55%, attributed to a friendlier US regulatory posture — the inverse of the UK/EU supervisory tightening (FCA, EBA) that drives the assurance-demand thesis elsewhere on this page. The divergence is jurisdictional (US deregulatory cycle vs UK/EU tightening), not evidence against the maturity gap itself; if anything a receding-enforcement environment makes voluntary, board-led assurance the live driver in the US, mirroring the EU “receding-deadline + voluntary assurance” reading. Caveat (in source framing): only high-level findings are public; the full results are gated behind Bank Services membership, and the sample skews to US community/regional banks [S-2026-03-30-bank-director-risk-survey].

The finance-function ROI-pressure cut (21 July 2026)

Avalara’s “Agents of Change” survey (1,500+ CFOs and senior finance leaders across the US, UK, India and Australia who have deployed, piloted or evaluated AI agents in the past year) adds a mid-2026, finance-function angle to the convergence [S-2026-07-21-avalara-agents-of-change]. Its distinctive contribution is to locate the maturity gap in the incentive structure around agentic AI: 92% of respondents feel moderate or significant career pressure to prove AI-agent ROI (half calling it significant), while half report only limited measurable ROI so far — and the report’s thesis is that deployment is outrunning the governance, accountability and internal-control layer. This dovetails with the Coastal / Oxford Economics finding that the binding constraint has shifted to post-deployment operations and evidencing value (45% measure activity not outcomes), and with the EMA fragmented-ownership datum: firms are under pressure to show returns on agentic AI they have not yet built the controls or the outcome-measurement to govern. Caveat (in source / ingestion): Avalara is a tax-compliance software vendor, the survey is vendor-commissioned and self-reported, and respondents are corporate finance leaders (CFOs) rather than specifically CDO/CRO governance owners — so it is directional corroboration, not FS-governance-specific evidence [S-2026-07-21-avalara-agents-of-change]. Practitioner inference (not in source): ROI pressure without a controls/measurement substrate is a precise statement of the Independent Governance Assurance demand — the scarce, saleable capability is evidencing that an agentic use case is both delivering value and under control [inference].

The large-company CFO cut and the confidence-vs-maturity question (23 July 2026)

Deloitte’s Q2 2026 CFO Signals AI-governance release (n=200 North American CFOs at companies with ≥US$1bn revenue, fielded 22 May–7 June 2026) adds a large-company, cross-sector, finance-owner cut to the 2026 convergence [S-2026-07-23-deloitte-cfo-signals-q2-2026]. Its distinctive contribution is to hold two findings together: very high stated confidence (96% “somewhat or very confident” in their AI governance framework, 93% using AI across key operations) alongside a candid account of the substantive gaps — 59% cannot yet balance deploy-fast pressure against risk, 51% lack governance authority, 43% lack visibility into AI tools/use, and AI-governance ownership is fragmented (CISOs/CIOs lead; only 19% of CFOs own it). Read against the rest of this page, the confidence figure is the outlier and is treated as a Tension rather than smoothed away: the “somewhat or very confident” bar is materially lower than the “highly developed” bar ProSight (12%) and others use, and Deloitte’s population is large-cap corporate finance functions in North America, not UK/EU FS CDO/CRO governance owners. The substantive findings, by contrast, reinforce the page’s existing themes precisely — the governance-authority gap (51%) is the same fragmented-ownership problem EMA names (IT/security/CDO/committee split) and the visibility gap (43%) mirrors the CSA incident-visibility finding. The external-risk ranking is also instructive for assurance scoping: litigation over protected/private content (43%) tops cybersecurity (41%) and regulatory complexity (36%), a data-provenance/IP signal that plausibly connects to the AI Act GPAI copyright-policy and training-data-summary obligations. Caveat (in source / ingestion): self-reported, North American, cross-sector, CFO-function (not CDO/CRO) — directional for UK/EU FS. Practitioner read (not in source): a 96%-confident / 59%-can’t-balance-risk split is itself the Independent Governance Assurance opening — stated confidence that independent review can test against evidenced controls [inference].

The compliance-function “policy to proof” cut (21 July 2026)

Arctera’s State of AI Governance 2026 (Hanover Research survey, n=500 full-time professionals in finance, healthcare and energy/utilities across the Americas and EMEA, all decision-makers or influencers in compliance decisions, fielded May 2026) adds a communications-governance and record-keeping angle to the 2026 convergence [S-2026-07-21-arctera-ai-governance-2026]. Its distinctive contribution is to decompose “governance” into a policy layer (policies, training, human review — which a 55% majority now report having) and an evidence layer (logging, retention, detection, risk scoring — which only 19% report having), locating the maturity gap precisely in the latter: the release’s framing is that “AI governance must move beyond policy creation and into evidence-based accountability”, and its prescription — “treat evidence as part of the AI workflow itself, not something to be recreated after the fact” — is the record-keeping restatement of the evidence-ready-frameworks demand this page tracks. Two secondary findings are instructive: 60% place primary AI-governance accountability with compliance, a more consolidated ownership picture than EMA’s fragmented IT/security/CDO/committee split — plausibly because Arctera surveyed compliance decision-makers specifically (sample-frame effect, flagged not resolved); and 71% self-assess as “very or extremely prepared” to produce a defensible audit trail, which the report itself holds against the 19% evidence-controls figure as overconfidence — a second confidence-vs-capability pair for the Tensions entry. Caveat (in source / ingestion): vendor-commissioned by an archiving/communications-compliance vendor whose product narrative the “evidence layer” framing directly serves; panel-recruited, self-reported, gated full report, cross-sector, no published FS-only cut — directional corroboration only. Practitioner read (not in source): a 55%-policy / 19%-proof split is the Regulatory Readiness & Evidence service line stated as a survey statistic — the deliverable clients lack is the evidence chain, not the policy set [inference].

The governance-dividend cut on agentic AI (22 July 2026)

Domino Data Lab’s Fifth Annual Enterprise AI Report (fieldwork independently conducted by BARC Research, n=639 director+ AI leaders at ≥$100M-revenue organisations across North America (397), the UK (148) and continental Europe (94), fielded April 2026; sectors: FS & insurance, life sciences, public sector) is the first source on this page to put numbers on the governance dividend for agentic AI rather than only the governance deficit [S-2026-07-22-domino-enterprise-ai-report]. Its distinctive contribution is the paired finding: 41% pilot or scale agentic AI without governance (the deficit, consistent with the CSA, Coastal and Avalara cuts), while the governed cohort shows a measurable advantage — 3.9x likelier to reach governed agentic production and 3x likelier to report significantly improved delivery velocity. This converts the maturity-gap thesis from a risk argument into a performance argument: governance-first firms ship agentic AI faster, which is the commercially persuasive framing for board conversations (and parallels KPMG’s ~32pp agentic-performance separation from a governance-explicit angle). Its FS finding — FS/banking/insurance lead every vertical on governance maturity and production velocity — is a relative leadership claim carrying the same caveat as Coastal’s “FS leads on formal frameworks”: leading a cross-sector field is compatible with absolute immaturity (see Open Questions). The regional finding is directly relevant to the practice: continental Europe has the lowest fully-integrated-governance rate (42.6%) and the highest ungoverned agentic share (~half), landing just as EU AI Act obligations approach — a gap statement for EU-based clients. Caveat (in source / ingestion): vendor-commissioned (Domino sells the governance/platform layer the “govern early” conclusion favours) though independently fielded; self-reported; gated report; FS vertical tables not seen — figures rest on the Computer Weekly relay; causal direction is the source’s interpretation of correlation [S-2026-07-22-domino-enterprise-ai-report]. Practitioner read (not in source): the 3.9x/3x pairing is the strongest single citable statistic yet for selling governance-first agentic adoption — “governance is the accelerant, not the brake” — provided it is quoted as a vendor-survey correlation, not causation [inference].

The UK industry-body cut and the frontier-AI pairing (24 June 2026)

techUK’s “Agents of Change: Generative and Agentic AI in Financial Services 2026” adds the trade-association voice to the convergence, and matters less for its adoption numbers (61% gen-AI, 42% agentic in 2025 — directionally consistent with the FCA/BoE 2024 survey’s 75% and the CCAF/CSA cuts) than for what it names as the binding problems and who it addresses them to [S-2026-06-24-techuk-agents-of-change]. The four challenges it foregrounds — behavioural drift, human oversight at scale, AI supply-chain concentration, and cyber resilience — are the industry’s own articulation of exactly the surface the EU and UK supervisors are converging on: the same day’s synthesis run pairs this report with the ESA Statement on frontier AI models (31 July 2026) S-2026-07-31-esas-frontier-ai-statement, which raises AI supply-chain / CTPP concentration and cyber resilience from the supervisory side. That the deployers (techUK members) and the supervisors (ESAs, FCA/BoE) are independently naming the same short list is itself the demand signal: the governance questions are agreed; what is missing is agreed practice — which is what techUK’s first recommendation (a dedicated agentic-AI governance workstream via the BoE/FCA AI Consortium) explicitly asks for. For Paul’s practice the useful read is that the industry is asking, in writing, for the practical agentic-governance guidance and shared assurance approaches that Independent Governance Assurance and Governance Framework Design exist to supply. Caveats: techUK is an advocacy body and its contributors are self-selected technology providers and large FS firms; the report is dated 24 June 2026 (not a past-7-day item) and was ingested this run because it was not previously in the vault; the survey base is unstated and the full report is gated — figures are from the public summary ⚠️ [S-2026-06-24-techuk-agents-of-change].

The architect-population cut and the “Great AI Re-Architecture” (week to 14 August 2026)

Cloudera’s survey of 1,500 enterprise architects, cloud infrastructure leads and data architects adds the population every other cut on this page has lacked: the people who build the estate rather than govern or fund it [S-2026-08-14-cloudera-ai-rearchitecture-survey]. Its distinctive contribution is that even from the infrastructure side, governance is the named blocker — 95% report projects delayed or cancelled over data governance, compliance or regulatory challenges, while 72% say the architecture itself needs significant change for AI and 75% have already changed storage/architecture practice. Cloudera’s framing (“Great AI Re-Architecture” toward hybrid environments bringing “trusted AI to trusted data”) is marketing language serving its hybrid-platform story and is preserved as such, not adopted. Caveats (in source / ingestion): vendor-commissioned; relayed via CRN Asia and Solutions Review with no methodology, fieldwork dates, geography split or FS cut retrieved; what “delayed or cancelled projects” measures (any project ever vs AI projects in a defined window) is unknown, so the 95% should be quoted only with that qualification [S-2026-08-14-cloudera-ai-rearchitecture-survey]. Practitioner read (not in source): directionally, this is demand-side evidence that governance and regulatory readiness are the binding constraint on AI delivery as seen from the build side — corroborating, from a fourth professional population, what the CDO/CRO, CFO, compliance and board cuts above already show [inference].

The Big Four’s own research and service expansion (12 August 2026)

Deloitte’s announcement of expanded “AI Controls and Assurance” services adds a distinctive angle absent from every other source on this page: it is research and positioning from a firm competing directly in the independent-assurance-over-AI market rather than a neutral survey house [S-2026-08-12-deloitte-ai-controls-assurance]. Its cited statistic — 74% planning agentic AI deployment within two years against only 21% with mature autonomous-agent governance — sits comfortably alongside the page’s existing convergence (ProSight’s ~12%, Grant Thornton’s ~18%, Domino’s 41% ungoverned) without adding a new number so much as a new source type: the gap is now attested to by a firm whose commercial interest is in selling the fix, not merely measuring the problem. Deloitte’s four-part offering (governance/risk frameworks including model validation; AI-enabled internal-audit/controls transformation; ecosystem/hyperscaler integration; regulatory readiness including SOC reports and certifications) is a direct positioning statement into the same buyer conversation Paul’s four service lines address, and is read here as sharpening — not resolving — the Big Four competitive-context question already tracked on Big 4 Differentiation Frame [inference]. Caveat (in source): no regulatory standard (EU AI Act, ISO/IEC 42001, SR 11-7, SS1/23) is named anywhere in the release; the release is US-dated with no explicit statement of UK/EU service scope; no named client; the underlying “State of AI in the Enterprise” report was not independently fetched or read this run, so the 74%/21% figure is recorded as Deloitte-reported, not independently corroborated [S-2026-08-12-deloitte-ai-controls-assurance].

The examination-risk framing and a second assurance-market competitor (17 August 2026)

ACA Group’s “AI governance is becoming a global examination priority” post (relayed by FinTech Global, 17 Aug 2026; primary not fetched) contributes two things distinct from the survey corpus above [S-2026-08-17-aca-ai-governance-examination-priority]. First, a consequence framing: where the surveys measure the gap, ACA states what the gap now costs — examination findings under existing frameworks, with the SEC (2026 Examination Priorities), FINRA (2026 Annual Regulatory Oversight Report GenAI section: evidence of testing, supervision, governance, vendor diligence, recordkeeping), the FCA (principles-based adaptation; AI Lab, AI Live Testing, Mills Review) and the DFSA (DIFC-wide circular: governance/accountability, risk management, operational risk, third-party arrangements) all cited as already examining AI without waiting for AI-specific rules. Its emphases — senior management must genuinely understand AI risk rather than delegate to technology teams; third-party accountability stays with the firm even for procured AI; recordkeeping extends to AI-enabled communications — restate the board-literacy, third-party-accountability and evidence-layer themes this page tracks, now phrased as examiner expectations. Second, a competitive-market datum: like Deloitte’s 12 Aug service expansion [S-2026-08-12-deloitte-ai-controls-assurance], ACA both attests to the gap and sells the remedy (independent assessments to benchmark governance “before gaps become examination findings”) — a second firm commercialising independent-assurance-over-AI in the same week’s captures, which is itself evidence the market Paul’s Service Line — Independent Governance Assurance addresses is being actively contested [inference]. Caveats (in source / ingestion): trade-press relay; ACA’s regulator characterisations were not re-verified against the primary SEC/FINRA/FCA/DFSA documents this run (the regulatory-intelligence scan owns those primaries); the 84% / “<2 of 20 functions” figures are ACA’s own survey with undisclosed methodology, and the “<2 of 20” statistic measures AI application while the article frames it as a governance gap — the underlying survey question is not visible from the relay ⚠️ [S-2026-08-17-aca-ai-governance-examination-priority].

The Big Four banking-specific lifecycle-and-agentic cut (14 August 2026)

Deloitte’s “Banking on Trust: AI Governance for Growth, Resilience and Scale” (14 Aug 2026) is the second Deloitte item on this page in a fortnight, but a different artefact from the 12 Aug service-expansion release: this is primary banking survey research (135 respondents — 24 AI-governance leaders at G-SIBs/D-SIBs across 14 countries plus 111 senior technology/AI/data staff across 16 countries) [S-2026-08-14-deloitte-banking-on-trust]. It corroborates the headline signal from a banking-specific angle — weekly AI use doubled to 63% while only 13% of banks reach “optimized” governance maturity and 87% have scope to strengthen — but its distinctive contributions are two. First, it decomposes maturity into five pillars and finds the binding weaknesses are human/organisational, not procedural: organisational structure is weakest (27% ad hoc) and half of banks are ad hoc or rudimentary on people and skills, while procedures and controls are comparatively mature — the same “policy/controls outrun the operating model” pattern Arctera (55% policy vs 19% proof) and the AAA-ICDR FS cut (96% policy vs 53% controls) name from the evidence angle, here stated from the accountability-and-skills angle. Second, it gives this page its sharpest lifecycle-and-agentic quantification yet: mandatory controls drop from 72% at design to 55% at monitoring, 72% of banks have under half their AI use cases in a central register, and agentic AI lifecycle risk monitoring sits at just 44% (vs 61% traditional, 59% generative) — a precise restatement, in banking, of the “governance ends at deployment” and “agentic oversight lags” threads developed on Model Risk Management and Agentic AI. Deloitte also reports a deployment dividend (optimized banks average 5.5 fully-implemented AI solutions vs 0.7 at ad hoc) and a governance–revenue association (10-point Governance-Index rise ≈ 10pp revenue-growth rise) that it explicitly cautions is association, not causation — preserved as the source’s own hedge, echoing Domino’s govern-early-scale-faster correlation without over-reading it. A notable methodological point: Deloitte’s own heads of AI governance rated their banks more conservatively than the broader executive group, which is a direct, citable argument for independent assessment — a framework can look mature from the top and much less so to the people applying it. Caveats (in source / ingestion): self-reported; Deloitte is both researcher and a seller of AI-assurance services; the full report is gated and figures are from The Financial Brand’s 14 Aug relay, not the primary PDF; the sample is large global banks (G-SIB/D-SIB-weighted), so the UK/EU read-across is directional (cf. Domino’s finding that Europe lags on fully-integrated governance). Date caveat: 14 Aug 2026, just outside the strict past-7-day window but not previously ingested and the strongest research-grade practitioner signal available this run [S-2026-08-14-deloitte-banking-on-trust]. Practitioner read (not in source): the design-to-monitoring drop, the thin central register and the 44% agentic-monitoring figure are the Independent Governance Assurance and Regulatory Readiness & Evidence demand stated as banking statistics — the scarce capability is evidenced, lifecycle-long oversight of AI (especially agentic) use cases, not more policy [inference].

Where the regulatory and practitioner pictures align

EBA observes that “only about half of EU banks have introduced dedicated policies or committees to oversee AI” and that “2LoD / 3LoD AI oversight is inadequate at most firms” [S-2025-11-eba-ai-act-mapping]. The regulator-side signal therefore matches the practitioner-side signal — both point to a market gap for evidence-ready frameworks rather than more policy [S-2026-03-17-paul-positioning].

Positioning consequence for Paul’s practice

The gap is named in Paul’s positioning notes as a direct demand signal: “CDOs / CROs are looking for evidence-ready frameworks rather than more policy” [S-2026-03-17-paul-positioning]. The four service lines — Governance Framework Design, Independent Governance Assurance, Programme Governance Specialist, Regulatory Readiness & Evidence — are structured to capture this demand.

The operating-model cut: discipline, not stack (February 2026 benchmark)

Where most 2026 sources on this page measure the gap by maturity self-ratings or policy-vs-proof spreads, Intelligine Group’s benchmark measures it by what the operating model does — and finds that the dispersion in operating-model maturity across 42 banks and insurers is wider than the dispersion in their technology stacks, i.e. the binding constraint is governance discipline rather than tooling [S-2026-02-intelligine-governance-benchmark]. Three findings sharpen the evidence-layer thesis this page tracks. On kill criteria: only 19 of 42 firms specify at least one kill criterion at the unit-economic level and instrument it continuously, and that discipline maps to a large operating-economics difference (median portfolio within 12% of the approved cost envelope, vs a 68% median overrun and a 340% tail case where it is absent) — the source’s own reading of a cross-sectional association, preserved as such, not as proven causation. On escalation: only 7 of 42 firms can move from a kill-criterion breach to a decision inside 72 hours without a board calendar event, 24 depend on a quarterly board review, and 11 have no written escalation path at all — a concrete, quantified version of the “controls exist but the decision path does not” problem, captured in the source’s interview quote that the missing piece was “a path from the breach to a decision that did not require a board agenda item”. On audit posture: the cleanest reconciliations occur where the runtime audit trail (what the system did) and the governance artefact (what it was permitted to do) are owned by separate teams on separate reporting lines and reconciled quarterly — a direct, practitioner-observed argument for the independence principle in Three Lines of Defence for AI and for the evidenced, lifecycle-long oversight that Service Line — Independent Governance Assurance and Model Risk Management and Agentic AI develop [inference]. The benchmark’s modal three-tier scheme — keying documented MRM, instrumented kill criteria and audit depth to a workload’s proximity to a regulated decision — is a usable design pattern for exactly the tiered-controls conversations Paul’s Governance Framework Design line runs. Caveats: single-firm self-reported primary data (n=42), gated instrument, global G-SIB-weighted with no UK/EU cut, and dated February 2026 — directional, low-authority, reinforcing (not contradicting) the existing thesis [S-2026-02-intelligine-governance-benchmark].

Practical Applications

  • Use the survey statistics as opening-call evidence in CDO / CRO conversations. The ~12% / ~18% / 76% numbers are durable and credible across multiple 2026 sources.
  • Map clients to the AGILE pillars to surface gap areas quickly.
  • Build Maturity Assessment Tools (data governance, AI governance) per Paul’s Phase 1 plan [S-2026-03-17-paul-practice-build-plan] — clients prefer scored profiles to narrative findings.

Open Questions

  • Whether the survey signals reflect real maturity or under-confidence in self-reporting.

  • Whether the gap will close materially during 2026–2027 as supervisory programmes mature.

  • Whether Grant Thornton’s “~18% fully confident in AI controls” (banking cut) is the same underlying data point as the “~18% could pass an independent review within 90 days” framing, or an independent corroborating measure; the two are currently cited together but not reconciled [S-2026-05-gt-ai-impact-banking].

  • Re-confirm the “61% trust / 96% need training / 57% of CDOs / 93% critical” figures against the published Informatica CDO Insights 2026 report; the 2026 release retrieved this run confirmed 76% governance-lag, 69% GenAI integration, 75%/74% literacy gaps and 86%/43%/41%/39% investment drivers, but not those four figures [S-2026-01-27-informatica-cdo-insights-2026].

  • Does KPMG’s ~32pp agentic-AI performance separation hold within regulated financial-services firms specifically, and what governance/control posture sits behind the high-performing cohort? The KPMG summary reports performance gains but not the governance maturity behind them, and the survey spans 13 sectors and the finance function broadly [S-2026-06-kpmg-global-ai-finance].

  • Confirm whether the “$10–50m per firm” agentic-architecture spend figure originates from the KPMG 2026 Global AI in Finance Report or a different KPMG publication; it is currently cited without a confirmed S-tag [S-2026-06-kpmg-global-ai-finance].

  • How much weight to place on the CSA “State of Cloud and AI for FS 2026” figures given the survey is vendor-commissioned (Anjuna), self-reported, fielded Jan–Mar 2026 and the full report is gated — and whether the ~41% incident-visibility gap reflects genuine under-instrumentation or respondent uncertainty [S-2026-06-09-csa-fs-ai-governance].

  • Is Bank Director’s board-level “a third do not understand agentic AI at all” measuring the same underlying gap as McKinsey’s “only ~one-third of firms reach maturity level 3+ on agentic-AI governance” — i.e. board literacy and organisational governance maturity as two ends of one constraint — or two distinct phenomena? And does the survey’s US-specific regulatory-risk-receding finding (28%, down from 55%) hold any read-across to UK/EU firms, where the supervisory direction is the opposite [S-2026-03-30-bank-director-risk-survey]?

  • Do the Wolters Kluwer US-banking emphases — model governance/validation as the #1 barrier (vs the data-quality / framework-maturity emphasis of the CCAF, ProSight and Informatica surveys), and synthetic-data integrity and automation bias as leading risks — generalise to UK/EU regulated firms, or are they US-specific? The surveys may be measuring different layers (model-control maturity vs data-substrate readiness) rather than genuinely disagreeing [S-2026-05-27-wolters-kluwer-ai-risk-governance-index].

  • How should Arctera’s finding that 60% place primary AI-governance accountability with compliance be reconciled with EMA’s fragmented-ownership finding (IT 30.2% / security 29.8% / CDO 20% / committees 18.7%, “no clear ownership”)? The most plausible explanation is a sample-frame effect — Arctera surveyed compliance decision-makers, EMA surveyed IT/security/data leaders — but if real, the difference matters for who buys assurance [S-2026-07-21-arctera-ai-governance-2026][S-2026-06-30-ema-dspm-ai-data-security].

  • Is Domino’s governance-dividend correlation (3.9x governed agentic production; 3x delivery velocity) causal, or selection — do better-resourced firms simply do both? And does its “FS leads every vertical” finding hold within the EU/UK FS subset specifically, given the same survey’s Europe 42.6% fully-integrated-governance figure — i.e. is the FS lead driven by North American institutions [S-2026-07-22-domino-enterprise-ai-report]?

  • How should the Coastal / Oxford Economics finding that FS “leads on formal AI governance frameworks” be reconciled with its own finding that ~55% of FS firms are on informal or still-building frameworks — i.e. is FS’s lead purely relative to less-regulated sectors while remaining absolutely immature? And does the survey’s “operational gap, not deployment problem” framing reflect a genuine sector finding or a vendor narrative oriented to Coastal’s AI-operations services [S-2026-06-24-coastal-ai-operations-fs]?

Tensions

On whether regulatory risk is a rising or receding driver of AI-governance demand:

  • Bank Director 2026 Risk Survey [S-2026-03-30-bank-director-risk-survey] (medium, US) reports regulatory-risk concern falling to 28% (from 55%), attributed to a friendlier US supervisory posture — implying enforcement pressure is a weakening driver.
  • The UK/EU sources on this page — FCA “existing frameworks apply” tightening and EBA’s 2LoD/3LoD inadequacy findings [S-2025-11-eba-ai-act-mapping] — point the opposite way: supervisory expectations are rising, and assurance demand with them.
  • Where they actually disagree: only on the direction of the enforcement cycle by jurisdiction, not on the existence of the maturity gap. Both sides agree adoption has outpaced governance; they differ on whether the near-term pull is mandatory (UK/EU) or voluntary/board-led (US).
  • Status: unresolved — jurisdictional divergence, not a factual conflict. Tracked, not reconciled.

On how ready firms actually are — high stated confidence vs low measured maturity:

  • Deloitte Q2 2026 CFO Signals [S-2026-07-23-deloitte-cfo-signals-q2-2026] (medium; North American, ≥$1bn, cross-sector, CFO-function) reports 96% of CFOs “somewhat or very confident” in their AI governance framework.
  • Arctera State of AI Governance 2026 [S-2026-07-21-arctera-ai-governance-2026] (low; vendor-commissioned, cross-sector, compliance-function) supplies the pattern within a single survey: 71% say they are “very or extremely prepared” to produce a defensible audit trail, while only 19% report having the logging/retention/detection/scoring controls to prove what happened — the source itself flags the confidence as unsupported (“confidence alone is not enough”).
  • The maturity-focused sources on this page point the other way: only ~12% of CROs describe their AI governance as “highly developed” [S-2025-11-prosight-cro-outlook-2026]; ~18% of banking leaders are fully confident in AI controls [S-2026-05-gt-ai-impact-banking]; ~55% of FS firms are on informal/still-building frameworks [S-2026-06-24-coastal-ai-operations-fs]; and Avalara frames deployment as outrunning governance [S-2026-07-21-avalara-agents-of-change].
  • The AAA-ICDR relay [S-2026-08-12-tech-reseller-aaa-icdr-ai-governance-gap] (low; trade-press relay, FS cut) lands on the low-confidence side of the same axis with the sharpest evidence-readiness figure yet — only 21% “very confident” they could produce auditable AI evidence for regulators/auditors/courts (against 96% having written policies) — the mirror image of the high-confidence self-reports, and the strongest single datapoint for the “policy exists, proof does not” reading.
  • Where they actually disagree: partly a measurement-bar artefact (“somewhat or very confident” is a far lower threshold than “highly developed” or “could pass independent review in 90 days”) and partly a population difference (large-cap cross-sector CFOs vs FS CROs/CDOs and banking risk leaders). Deloitte’s own substantive findings (59% can’t balance deploy-fast vs risk; 51% lack governance authority; 43% lack visibility) are consistent with the low-maturity readings — so the conflict is confined to the single self-reported “confidence” headline.
  • Status: unresolved — most plausibly a self-report/confidence-bar effect rather than a genuine maturity disagreement; connects to the standing Open Question on whether survey signals reflect real maturity or under/over-confidence in self-reporting. Tracked, not reconciled.

Sources