September 9, 2026
ISACA Poll: AI Risk Ownership Is the Missing Link in Enterprise AI Governance

Contents
AI is no longer confined to pilot projects and proof-of-concept teams. It has moved into the daily fabric of enterprise operations, but oversight, security readiness, and workforce skills have not kept pace. That imbalance is now landing squarely on the desks of corporate boards, who increasingly treat AI governance as a core business risk rather than a technical afterthought.
The shift in tone is deliberate. Regulatory expectations differ across jurisdictions; the UK and EU, for instance, have taken notably different paths, but organizations everywhere are facing the same underlying pressure: demonstrate accountability, protect operational resilience, and maintain the trust of customers, regulators, and investors.
A Governance Gap Hiding in Plain Sight
ISACA’s 2026 AI Pulse Poll finds that 92% of organizations now use AI in day-to-day operations, yet only 42% have a formal, comprehensive AI policy guiding how employees actually use it. That’s a nearly 50-point gap between adoption and governance, and it shows up in some uncomfortable blind spots:
- 35% of respondents can’t say for certain whether their organization has already suffered an AI-related cyberattack.
- 59% of security leaders don’t know how quickly they could shut down an AI system if one were compromised.
- Only 38% of enterprises have assigned a specific executive or board member to own AI risk, leaving AI risk ownership undefined at the exact moment it matters most.
- A third of organizations don’t require employees to disclose their use of AI tools at all, a gap that fuels unmonitored “shadow AI” and erodes visibility into how the technology is actually being used across the business.
Taken together, the numbers point to a structural problem: most companies deployed AI faster than they built the mechanisms to govern it. Closing that gap means bringing audit, cybersecurity, risk, compliance, legal, business owners, and implementation teams into a single coordinated view of AI risk, rather than treating each as a separate silo reacting after the fact.
The Skills Gap Behind the Governance Gap
Governance frameworks are only as strong as the people who run them, and here too the research points to a shortfall. Nearly 8 in 10 professionals (79%) surveyed say they expect to need to upskill within the next year to keep pace with AI. Yet 21% of organizations still offer no formal AI training at all.
ISACA is responding directly to that gap with three new professional credentials aimed at the specialists who will need to secure, audit, and manage risk across AI systems:
- AAIA (AI Audit): for experienced professionals evaluating AI governance models, internal controls, and regulatory compliance.
- AAIR (AI Risk): for risk officers building deeper expertise in identifying, analyzing, and mitigating exposure across the AI lifecycle.
- AAISM (AI Security Management): for cybersecurity professionals focused on defending against AI-enabled threats while still enabling secure adoption.
The goal of each credential is the same: give organizations the internal expertise to build governance frameworks that satisfy regulators, reassure investors, and keep innovation moving without moving recklessly.
Lumenova AI’s Perspective: Governance Debt Is Now a Balance-Sheet Risk
At Lumenova AI, we don’t think this gap gets closed by writing a longer policy document or hiring one more certified auditor. Policies and credentials matter, but neither one does anything on its own without clear AI risk ownership – someone accountable for the outcome, with visibility into what’s actually running.
That’s the layer we focus on: giving organizations a live, operational view of their AI systems – what’s deployed, who’s accountable for it, and what happens the moment something goes wrong, so governance is something a team can execute under pressure, not just something they can produce for an audit.
Our view is that the winners over the next 12-18 months won’t be the companies with the most AI in production. They’ll be the ones with real AI risk ownership built into how they operate: knowing what’s running, who’s accountable for it, and how fast they can act if it fails. That’s a lower bar than “mature governance”, and it’s exactly the bar we build toward with every customer.