Explore our AI courses, practical training for non-technical teamsExplore courses Explore AI courses
AI GovernanceRisk & OversightLeadership

The AI Governance Gap: Why Trust Is Outpacing Oversight

Adoption moved faster than the structure built to hold it, and closing that gap is a smaller job than most mid-size leaders assume.

TLDR: AI trust is running ahead of AI oversight at most mid-size companies, and the fix is a short list of questions, a named owner, and a habit of writing things down before they become a problem, not an enterprise compliance department.
58%of U.S. workers admit to relying on AI-generated output at work without properly evaluating it first, KPMG, "Trust, Attitudes and Use of Artificial Intelligence: A global study 2025," April 2025
59%of U.S. workers believe someone at their company is actually accountable for overseeing AI use, meaning roughly four in ten don't know who is, or don't think anyone is, same KPMG 2025 study
77%of organizations surveyed are actively working on AI governance, climbing to near 90% among those already using AI in production, IAPP and Credo AI, "AI Governance Profession Report 2025" (671 respondents, 45 countries)

Share this article

The Short Version

Most employees are already trusting AI outputs more than their company’s oversight can actually support. KPMG’s 2025 global trust study found 58% of U.S. workers admit to relying on AI-generated output at work without properly evaluating it first. This piece lays out what a lightweight, genuinely usable governance approach looks like for a mid-size company, not a case for enterprise-grade compliance: the questions it needs to answer, who owns it when there’s no dedicated team, and a starting point you can put in place this quarter, not next year.

The gap in one sentence: adoption is outrunning oversight

Picture a 180-person insurance brokerage on an ordinary Tuesday. The head of client services mentions, almost as a side note, that the renewals team has been using an AI tool to draft policy renewal emails for the last three months. The COO asks who approved that.

Nobody answers right away. The tool works well enough that nobody flagged it, and well enough that nobody thought to check.

That’s the actual shape of the AI governance gap at most mid-size companies. That’s not because leadership rejected the idea of oversight, or because nobody cares about risk. AI simply got useful faster than anyone wrote down the rules for using it, and once a tool starts saving people real time, nobody wants to be the one who slows it down by asking questions.

You’ll see the same pattern in finance, HR, and legal, wherever someone found a shortcut and kept it because it worked. The gap is trust moving faster than the structure built to hold it, nothing more mysterious than that.

The research backs up what that scene suggests. In KPMG’s 2025 global study on trust and use of AI, 58% of U.S. workers admit to relying on AI-generated output at work without properly evaluating it first.[1] Fifty-nine percent believe someone at their company is actually accountable for overseeing AI use, which leaves roughly four in ten who either don’t know who that is or don’t think the role exists at all.[1]

That’s more than half a workforce treating an AI answer the way they’d treat a fact from a trusted coworker, not something that needs a second look.

The Governance Speed Rule

If nobody in the room can say who approved an AI use case, you don’t have oversight. You have a habit that hasn’t gone wrong yet.

The fix isn’t a 40-page policy nobody reads. Most mid-size companies don’t have a governance gap because they’re missing a framework. They have one because nobody sat down and wrote out the three or four questions that AI use at their company actually needs answered.

That’s a smaller job than it sounds. It’s what the rest of this piece walks through.

What 'good enough' governance actually means for a mid-size company, not an enterprise compliance department

Here’s a hypothetical, and it’s easy to picture because some version of it is probably happening in your building this week. A finance analyst at a 90-person manufacturer is behind on a board deck. She pastes last quarter’s unreleased revenue numbers into a public AI chatbot to get help reformatting them into talking points.

She’s not being reckless. Nobody ever told her not to, and nobody set up an approved alternative that’s just as fast.

This is where most mid-size leaders freeze. They hear “AI governance” and picture an enterprise compliance department: a standing committee, a risk taxonomy, quarterly audits, maybe a chief AI officer with a dedicated budget. That version is real at large enterprises, and it’s genuinely the wrong size for a 60 to 400 person company.

Good enough governance for a company that size answers three things: what data can go where, who checks an AI output before it reaches a customer or a regulator, and who’s accountable when it doesn’t. Call it the PAC check: Purpose, Access, Consequence. What is this tool for, what can it actually touch, and what happens if it’s wrong.

If your policy can’t answer those three in a paragraph each, you’re looking at an announcement, not governance.

Worth being honest about how far even large, well-resourced organizations are from finished on this. The IAPP and Credo AI’s 2025 AI Governance Profession Report found 77% of surveyed organizations actively working on some form of AI governance, climbing to near 90% among organizations already using AI in production.[2] Most of those respondents work inside large enterprises that already have dedicated privacy or compliance teams in place.

That detail matters for a smaller company specifically. If organizations with the budget for full compliance departments still treat this as unfinished work rather than a solved problem, a mid-size company doesn’t need to solve it perfectly either. It needs to solve it enough to answer the three questions above, honestly, in writing.

Quick Read: Do You Have a Governance Gap Right Now

QuestionScore 1 if true
More than one team uses an AI tool nobody selected or approved1
No one could name, today, who signs off on a new customer-facing AI use case1
Someone has pasted client, financial, or HR data into a public AI tool in the last month1
You don’t know how many AI tools are in active use across departments1
Nobody has looked at an AI output and asked how you’d know if it were wrong1

Score 3 or more and the gap is already operational, not theoretical. At that point it’s a next-quarter priority, not a compliance exercise.

This is close to what we’ve written about before as shadow AI, the tools people adopt on their own because the sanctioned path is slower or doesn’t exist yet. Most of it happens because nobody wrote the rule down, not because anyone’s trying to get around one. Our guide to shadow AI covers the fuller pattern of how and why it spreads.

The questions a governance approach should actually answer

A governance approach that actually gets used answers a short list of concrete questions, not abstract principles. “We’re committed to responsible AI” means nothing to the analyst deciding whether to paste a client contract into a chatbot at 4pm on a Friday. What she needs is a specific answer to a specific question.

These are the ones worth writing down first:

  • What data is this tool allowed to see, and what’s explicitly off-limits: client PII, unreleased financials, anything under NDA
  • Which AI use cases need a human to check the output before it goes external, and which are low-stakes enough to skip that step
  • Who is the named person accountable if an AI-assisted decision turns out to be wrong or unfairly biased
  • How does someone request a new AI tool, instead of just starting to use one quietly
  • What gets logged, so you can reconstruct six months later which tool touched which decision

None of these questions require a lawyer to answer, though a lawyer should weigh in if you have one. They require someone to sit down, probably for less than a day, and actually decide.

If you haven’t mapped out what to plan for before rolling anything else out, that’s a related but separate job. Our AI Adoption Checklist covers what to think through before the rollout. This is what happens after something is already live and people are using it.

Starter AI Governance One-Pager (Filled Example)

FieldExample answer
Approved toolsMicrosoft Copilot and Claude, on company-licensed accounts. Personal or free accounts not approved for company data.
Data that can never go into an AI toolClient PII, unreleased financials, anything under NDA, employee health or HR records
Human check required before external useAny AI-drafted content going to a customer, regulator, or the board
Who owns this policyOps lead, with IT/security and legal counsel as reviewers
How to request a new toolOne-line request to the ops lead, reviewed within five business days
Review cycleEvery quarter, or immediately after any incident

Copy this structure into a shared document with your own answers filled in. A one-pager people actually read beats a policy nobody opens.

Once those six fields have real answers, most companies have more usable governance in place than a good number of organizations twice their size.

Who should own it when there is no dedicated AI governance team

In a company with a dedicated AI governance team, this question doesn’t come up. In a 120-person company, it comes up constantly, usually in the form of someone asking whether this is even on anyone’s plate.

It usually lands on someone without “AI” anywhere in their title, and that’s normal, as long as it’s named out loud rather than left to whoever raises a concern first.

A few roles tend to split the work, and they don’t split it the same way:

  • A CFO usually ends up owning vendor risk: the contract language with AI vendors around data handling, and the cost of tools sprawling across departments unchecked
  • An ops lead or COO typically owns the day-to-day rules, the one-pager itself, and the tool request process
  • IT or security owns access control: what data can physically reach which tool, and what gets shut off when someone leaves
  • Legal counsel, in-house if you have one or outside counsel on retainer if you don’t, owns contract terms, liability exposure, and anything touching regulated data

If none of those exist as dedicated roles at your company, the responsibility usually still lands on whoever already owns operational risk day to day. That’s frequently the ops lead or the COO, not a new hire, and not necessarily whoever is most enthusiastic about AI.

The Ownership Rule

Someone at your company already owns the risk of a bad customer email or a mishandled dataset. That person owns AI risk too, whether or not it’s written on their business card.

Getting agreement across departments on who owns what is its own small project, and it’s easy to underestimate. If you haven’t lined up buy-in from the teams that can slow this down before you finalize anything, it’s worth reading Stakeholder Engagement for AI Adoption first.

Once ownership is named, the next question is where the line actually sits between what the AI does and what a person still has to check.

Where AI Stops and a Human Takes Over

What AI doesWhat the human still ownsHow it gets checked
Drafts a client renewal or proposal emailWhether the numbers, tone, and commitments are accurateNamed reviewer reads it before it sends; spot-checked monthly
Summarizes a contract or policy documentLegal interpretation and the final risk callLegal counsel or the ops lead confirms before anyone acts on it
Screens or ranks job applicantsThe actual hiring decision, and a bias check on the rankingsHR reviews rankings against a fairness spot-check before shortlisting
Answers routine customer questionsEscalation for anything outside a defined scriptLogged conversations reviewed weekly for drift or errors

Use this as a template. List your own top four or five AI use cases and fill in the middle and right columns before you approve a fifth.

A lightweight governance starting point you can put in place this quarter

None of this needs to wait for a steering committee, a new hire, or a line item in next year’s budget. It needs someone to block out an afternoon.

The Scale Rule

Governance built for a Fortune 500 legal team will sit unopened in a shared drive at a 200-person company. Match the governance to the company you actually run, not the one in the compliance textbook.

Start with a record of what’s actually in use before you write another rule. You can’t govern what you can’t see, and most mid-size companies genuinely don’t know how many AI tools are live across departments until someone asks directly.

AI Use Case Register (Starter Columns)

Use caseToolData touchedOwnerHuman checkLast reviewed
Draft renewal emailsCopilotClient name, policy termsClient services leadReviewed before sendQ3 2026
Summarize vendor contractsClaudeContract text, no PIIOps leadLegal counsel confirms termsQ3 2026

Start this in a shared spreadsheet with your two riskiest use cases. Add a row every time a new one appears instead of trying to build the whole thing at once.

From there, the sequence is short:

  1. Write the one-pager from the earlier section, with real answers, not placeholders
  2. Name the owner out loud, in writing, this week
  3. Start the use case register with your two highest-risk AI uses
  4. Put a 90-day review date on the calendar before you move on to anything else

Writing any of this down usually isn’t what trips up mid-size teams. Getting legal, IT, and department heads to agree on the same answers, in the same room, without the conversation dragging on for two months, is the harder part.

That’s the part an expert-led workshop is actually built for. A focused half-day session with the right people in the room can get a one-pager and a use case register signed off across departments in an afternoon, instead of the draft sitting in someone’s inbox until an incident forces the issue. You can absolutely start with the internal version above. A workshop just compresses the buy-in step that otherwise eats months.

Pick one thing from the list above and do it this week, even if it’s just the one-pager in a shared doc with three real answers filled in. That’s the whole first move.

Hina Mian
Hina Mian, Co-Founder of Future Factors AI

Hina is a marketing strategist with over a decade of hands-on campaign experience across B2B and consumer brands. She writes about using AI to run leaner, sharper marketing without losing the human touch. Future Factors helps professionals and teams build practical AI capability through role-based training, workflow design, and hands-on adoption.

More about Hina →

Frequently Asked Questions

What does AI governance actually mean in practice?

It means a working answer to three things: what data your AI tools can touch, who checks the output before it goes anywhere that matters, and who’s accountable when something goes wrong. It isn’t a mission statement about responsible innovation. A useful test is whether a new hire could read your governance approach and know, within five minutes, what they’re allowed to paste into an AI tool and who to ask if they’re unsure. If it can’t pass that test, you have a document, not governance.

Does a small or mid-size company really need formal AI governance?

Yes, though formal doesn’t mean what it does at an enterprise. You need a written answer to what data is off-limits, who reviews outputs before they reach a customer, and who owns the decision when something breaks. Run the scored checklist earlier in this piece: if you score three or more, the gap is already operational rather than theoretical, and it’s worth addressing this quarter rather than after a mistake forces the conversation.

Who should be responsible for AI governance if there is no dedicated team?

It usually falls to whoever already owns operational risk day to day, most often an ops lead or a COO, with IT or security controlling data access and legal counsel, in-house or on retainer, weighing in on contracts and liability. A CFO typically ends up owning vendor risk and tool spend. The person’s title rarely says AI anywhere in it, and that’s normal. What matters is that the responsibility is named in writing rather than left to whoever happens to raise a concern first.

What questions should an AI governance policy actually answer?

At minimum: what data a tool is allowed to see and what’s explicitly off-limits, which use cases need a human check before anything goes external, who is the named person accountable if an AI-assisted decision is wrong, how someone requests a new tool instead of adopting one quietly, and what gets logged so you can reconstruct later which tool touched which decision. The starter one-pager earlier in this article has a filled-in example of all six fields.

What is the difference between AI governance and an AI usage policy?

A usage policy is the written rules, the front door: what’s allowed, what isn’t. Governance is the ongoing system around it: ownership, a review cadence, a register of what’s actually in use, and a clear answer for who’s accountable when something goes wrong. A usage policy with nobody maintaining it tends to get circulated once and never opened again. Governance is what makes people actually follow the policy six months later.

About This Article

The two statistics anchoring this piece come from primary sources checked directly at the publisher on 31 August 2026. The 58% and 59% figures are from KPMG’s own press release summarizing its “Trust, Attitudes and Use of Artificial Intelligence: A global study 2025,” a survey of over 48,000 people across 47 countries, including 1,019 in the U.S., conducted with Melbourne Business School and published April 29, 2025. We used the U.S.-specific figures rather than the global ones, which run higher, closer to two-thirds, because mixing global and national numbers in the same paragraph tends to overstate precision for a piece aimed at U.S. and similarly structured mid-size companies. The 77% and near-90% figures are from the IAPP and Credo AI’s “AI Governance Profession Report 2025,” based on a spring 2024 survey of more than 670 professionals across 45 countries. Worth flagging plainly: that survey’s respondent base skews toward larger organizations with existing privacy or compliance functions, which is exactly why it’s used here as a caveat about the scale of the challenge rather than as a benchmark for what a mid-size company should build. No widely circulated AI governance statistic was excluded during research for failing verification; the two used here were the ones that held up cleanly against their original publisher.

Sources

  1. KPMG, in collaboration with Professor Nicole Gillespie and Dr. Steve Lockey of Melbourne Business School, “The American Trust in AI Paradox: Adoption Outpaces Governance” (press release summarizing “Trust, Attitudes and Use of Artificial Intelligence: A global study 2025”), published April 29, 2025. Global survey of over 48,000 people across 47 countries, including 1,019 respondents in the United States, fielded November 2024 to January 2025. https://kpmg.com/us/en/media/news/trust-in-ai-2025.html
  2. IAPP and Credo AI, “AI Governance Profession Report 2025,” published April 16, 2025. Based on the IAPP’s spring 2024 annual governance survey of more than 670 individuals across 45 countries and territories, plus seven organizational case studies. https://iapp.org/resources/article/ai-governance-profession-report

Psst, Hey You!

(Yeah, You!)

Want helpful AI tips flying Into your inbox?

Weekly tips. Real examples. Practical help for busy professionals.

We care about your data, check out our privacy policy.