On This Page

Research Brief · AI Governance

AI Guidance and Assurance for ELTs

Bottom line

The concerns keeping ELTs up at night about AI in 2026 aren't vague unease — they're specific, measured, and consistent across a dozen independent surveys. 56% of companies have seen neither higher revenue nor lower costs from AI.[1] This is a rational response to a real gap between adoption speed and governance readiness, and the same research documents what closes it.

The landscape, at a glance

CEOs plan to roughly double AI investment as a share of revenue in 2026[3]

72%

of CEOs now call themselves the primary AI decision-maker[3]

50%

of CEOs say their own job stability depends on getting AI right[2]

The landscape in three numbers

Investment is not slowing down. BCG's 2026 AI Radar found CEOs are set to roughly double AI investment as a share of revenue in 2026, and 82% are more optimistic about AI's ROI than they were a year ago.[3] At the same time, 72% of CEOs now call themselves the primary AI decision-maker — a role that, a year ago, sat with the CTO or CIO in half as many companies.[3] And half of CEOs surveyed believe their own job stability now depends on getting AI investment and strategy right.[2] That combination — rising confidence, rising personal stakes, and a still-thin evidence base — is exactly the condition under which specific, well-grounded concerns deserve a specific, well-grounded answer rather than either blanket reassurance or blanket alarm.

The eight concerns, what the research says, and what to actually do

Two of the eight concerns below resolve into an actual go/no-go gate rather than an ongoing judgment call, diagrammed in the Decision Trees section further down. Click a concern to expand it.

Decision trees

Two of the eight concerns above resolve into an actual go/no-go gate rather than an ongoing judgment call. A third — accountability — resolves into a decision about escalation authority that's worth making explicit before, not during, an incident.

Gate 1: is this agent pilot ready to move past pilot stage?

Pilot showing promise

Baseline cost documented and incident response tested?

No — Hold in pilot

Build baseline and governance first.

Yes — Proceed

Move to the autonomy-level check (Gate 2).

This maps directly onto Grant Thornton's finding that only 20% of organizations currently have a tested AI incident-response plan, even though nearly three in four are already giving agentic AI access to real data and processes — most are moving past this checkpoint without clearing it.[5]

Gate 2: how much autonomy should this agent actually have?

Cleared governance gate

Task involves high-stakes or irreversible decisions?

No — Allow bounded autonomy

Execute with monitoring.

Yes — Require human review

No autonomous execution.

This threshold matches where mature organizations are actually landing: only 5% currently allow agents to execute high-stakes decisions without human review, while 60% cap agents at moderate-risk tasks.[5] The "no" branch is where the real deployment activity is concentrated, not the "yes" branch — which is itself a useful data point to share with an anxious board.

Gate 3: who has authority to stop an agent, and when

AI agent flagged for a problem

Does the flagging owner have standing authority to halt?

No — Needs sign-off

Escalate to CEO or board. Set a maximum response-time SLA.

Yes — Halt immediately

Report to ELT after the fact.

Right now this is close to a coin flip across organizations — 50% of AI governance leaders have full independent halt authority, 42% require CEO or board approval first.[7] Either answer is workable; leaving it undefined until the first real incident is the failure mode. Decide this path before an incident happens, not during one.

Perception vs. reality

Perception (what the anxiety feels like)Reality (what the research actually shows)
"We're behind because we haven't proven ROI yet"56% of companies haven't either — the gap is the norm right now, not a sign of falling behind
"Slowing down over error concerns means we're losing our nerve"60% of CEOs who believe in AI's ROI have done the same thing — it's a rational response from believers, not hesitation from skeptics
"If we don't agree internally on workforce readiness, something's wrong with our team"A 5x perception gap between CIO/CTO and COO views is common enough to be a named finding, not a symptom of dysfunction
"Shadow AI and data leaks mean our policy has failed"Shadow AI is happening at 30–57% of organizations broadly — the fix is a better sanctioned tool, not a stricter memo
"Governance ambiguity means we haven't done the work"Only about a third of organizations have reached real maturity here — this is where most peers currently are, not a sign of falling short of a widely-cleared bar

Practical takeaways for the ELT

  1. Score data/systems readiness and governance maturity as an explicit gate before any agent pilot scales past pilot stage — use Gate 1 as a template, not a suggestion.
  2. Set the autonomy threshold per use case, not per department. High-stakes or irreversible decisions get human review by default; everything else gets bounded autonomy with monitoring.
  3. Decide escalation authority in advance, in writing, and put a maximum response-time SLA on any path that requires CEO or board sign-off.
  4. Communicate the AI strategy to the workforce directly — currently under half of organizations do — and fund training tied to specific roles and workflows rather than generic literacy sessions.
  5. Don't read your own caution as falling behind. The research shows the most confident CEOs are also the ones deliberately slowing specific rollouts; caution and conviction are showing up together in the data, not as opposites.

Companion piece

Why "What Are You Doing With The Extra Time?" Is the Wrong Question

Part of the same series: field studies show AI raises quality-per-hour while hours stay flat.

Companion piece

If AI Makes Employees More Valuable, Why Are Companies Laying Them Off?

Part of the same series: Gartner data on 350 executives shows AI-driven headcount cuts have zero correlation with ROI.

Companion piece

Agent Spend Is Rising Faster Than Proof of Return

Part of the same series: 95% of enterprise generative-AI pilots show no measurable P&L impact — what the CEO, CFO, and CIO should each be watching.

References

  1. PwC, 29th Annual Global CEO Survey (4,450 CEOs, 95 countries), 2026.
  2. World Economic Forum, "CEOs are all in on AI but anxieties remain: What leader confidence indicates for 2026," January 2026, citing BCG AI Radar 2026.
  3. Boston Consulting Group, AI Radar 2026: As AI Investments Surge, CEOs Take the Lead, January 2026 (survey of 2,360 executives, 640 CEOs).
  4. McKinsey & Company, "Responsible AI: Overcoming adoption barriers and risks" / 2026 AI Trust Maturity Survey (approximately 500 organizations), March 2026.
  5. Grant Thornton, 2026 AI Impact Survey Report (950 business leaders, 10 industries), April 2026.
  6. Gallagher (AJG), The 2026 AI Adoption and Risk Survey: AI in Action, April 2026.
  7. EY, Technology Pulse Poll (500 US technology business leaders), March 2026.
  8. Aon, "AI Risk 2026: What Business Leaders Need to Know," 2026.
  9. CFO Dive, "Top 5 AI adoption challenges facing CFOs in 2026," January 23, 2026 (citing RGP survey and legal analysis from Bryan Cave Leighton Paisner).
  10. PwC, "2026 AI Business Predictions," 2026.
  11. The Conference Board, "AI and the C-Suite: Implications for CEO Strategy in 2026," January 2026.

Note: all sources in this brief are original survey research or reporting on it (PwC, BCG, McKinsey, Grant Thornton, Gallagher, EY, Aon, CFO Dive, The Conference Board) rather than peer-reviewed academic studies; several (Gallagher, Grant Thornton, EY) are vendor- or insurer-commissioned surveys with a commercial interest in the topic.