Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

EY survey finds AI rollouts outrunning company controls

Senior AI executives told the consultancy their organisations are deploying autonomous systems faster than they are building the processes to supervise them.

By The Agentic Times ·

A factory floor where robotic arms move at accelerating speed while supervisors watch helplessly from behind, their control panels growing smaller and dimmer in the distance.
A factory floor where robotic arms move at accelerating speed while supervisors watch helplessly from behind, their control panels growing smaller and dimmer in the distance. · Illustration: The Agentic Times

Organisations are putting AI and autonomous systems into production faster than they are building the controls to govern them, according to a survey of senior AI executives published by consultancy EY and reported by Dark Reading on 18 September 2026.

The survey covered senior executives responsible for AI inside their organisations. Its central finding, as reported, is a gap: deployment is rapid, while the processes and controls that are supposed to sit around those deployments are not keeping pace. In other words, the technology is arriving in the business before the oversight does.

That gap matters more for autonomous systems than for earlier forms of AI. An autonomous system, in this context, is software that can take actions on its own rather than simply returning an answer for a person to review. When a model only drafts text, a careless output is a nuisance. When an agent can call tools, move data or trigger a transaction, the same careless output becomes an action that has already happened. Controls are what stand between the two, and the EY findings suggest many organisations are still assembling them.

The survey does not, on the reporting available, point to a specific breach or failure. It is a measure of self-reported readiness rather than a record of harm. That is worth stating plainly, because oversight gaps are easy to dramatise. What the data describes is a mismatch in timing inside enterprises, not a catalogue of incidents.

Still, the shape of the finding will be familiar to anyone who has watched previous technology cycles inside large organisations. Procurement and pilot programmes move quickly when there is executive enthusiasm. Governance functions, which need policies, owners, audit trails and escalation routes, move at the speed of committees. The result is a window in which systems are live and the answer to "who is accountable if this goes wrong" is still being drafted.

For security teams, the practical reading is about sequencing. If autonomous systems are already running in parts of the business, the first question is an inventory one: what has been deployed, by whom, and with what permissions. The EY survey suggests that in many organisations that picture is incomplete, because the deployment has run ahead of the process designed to record and constrain it.

EY's survey is one of a growing number of industry studies tracking how enterprises are adopting agentic systems. As with all vendor-published research, the sample is self-selected and the respondents are describing their own organisations. The headline finding, however, is a straightforward one, and it is the executives themselves saying it: the controls have not caught up with the rollout.

Sources

  1. darkreading.comhttps://darkreading.com/cyberattacks-data-breaches/ey-survey-autonomous-ai-implementation-outpaces-oversight