TL;DR
- Schellman’s State of AI Governance Report 2026 surveyed 525 US-based professionals and found 74% believe they could pass an AI compliance audit today, while 27% describe their governance programmes as fully mature.
- A different split carries more information: 78% of organisations with mature AI governance run agents in production, against 22% of those still developing, with 86% of all respondents having tested or piloted agents.
- The stated mechanism is that defining system ownership, running AI-specific incident response, overseeing agentic use and bounding what an agent can reach are what allow an agent near production data.
- Two limits: this is correlation presented in a causal shape, and Schellman is an attestation firm whose business benefits from the conclusion.
In plain English
An AI compliance audit is an outside check that an organisation can show, with evidence, who owns each AI system, what it is allowed to touch, and what happens when it misbehaves. “Governance maturity” is the organisation’s own rating of how complete that apparatus is. Schellman does this work commercially: it is an attestation and compliance firm, the first ANAB-accredited ISO 42001 certification body and the first authorised AIUC-1 auditor, so its report recommends the service it sells. The methodology is disclosed.
“Correlation presented in a causal shape” describes the 78/22 gap. Organisations with mature governance programmes tend to be larger, better resourced and further along generally, and those same properties independently predict getting any system into production. The survey shows governance and production agents travelling together; it does not isolate governance as the cause.
Schellman published its State of AI Governance Report 2026 yesterday, and the headline writes itself: 74% of organisations believe they could pass an AI compliance audit today, while only 27% describe their governance programmes as fully mature. The survey covers 525 US-based professionals involved in evaluating, deploying, securing or governing AI, fielded by Researchscape. Ninety per cent have already allocated funding for AI governance, so the shortfall isn’t budget.
The confidence gap is the quotable bit, and it’s the least interesting thing in the report. A survey finding that people rate themselves better than their own maturity criteria suggest is roughly as surprising as finding that most drivers consider themselves above average.
The number I’d actually put in front of a board is further down. Among organisations with mature AI governance, 78% have agents running in production. Among those still in the developing phase, it’s 22%. Same appetite, near enough: 86% of all respondents have tested or piloted agents. Very different rates of getting them past the pilot.
That reframes what governance is doing in the sentence. The default assumption in a lot of enterprise AI work is that the model comes first and the process catches up later, and that security is the department that says no. Schellman’s split points the other way, and the mechanism isn’t mysterious. Defining who owns which system, running AI-specific incident response, putting real oversight around agentic use and bounding what an agent can reach are the things that make it possible to let an agent touch production data at all. Without them, the only safe move is to keep agents away from anything that matters, which looks like caution and functions as containment.
Two caveats I’d want stated before anyone quotes this at a budget meeting. The first is that this is correlation presented in a causal shape. Organisations with mature governance programmes tend to be larger, better resourced and further along in general, and those same properties independently predict getting anything into production. The report shows the two travel together. It doesn’t isolate governance as the cause, and the press release doesn’t claim to.
The second is who’s asking. Schellman is an attestation and compliance firm, the first ANAB-accredited ISO 42001 certification body and the first authorised AIUC-1 auditor. A report from an audit company concluding that organisations need mature, demonstrable, audited governance is not a neutral instrument. That doesn’t make the 78/22 split wrong, and the methodology is disclosed, which is more than a lot of vendor research manages. It does mean the framing deserves the same scrutiny you’d give any other piece of commissioned research.
Read with those held in mind, it’s still the most useful governance datapoint I’ve seen this month, mostly because it gives the argument a number. “Trust matters” has never once moved a roadmap. “Organisations with mature governance are about three and a half times more likely to have agents running in production” might.