Schellman published its State of AI Governance Report 2026 yesterday, and the headline writes itself: 74% of organisations believe they could pass an AI compliance audit today, while only 27% describe their governance programmes as fully mature. The survey covers 525 US-based professionals involved in evaluating, deploying, securing or governing AI, fielded by Researchscape. Ninety per cent have already allocated funding for AI governance, so the shortfall isn’t budget.
The confidence gap is the quotable bit, and it’s the least interesting thing in the report. A survey finding that people rate themselves better than their own maturity criteria suggest is roughly as surprising as finding that most drivers consider themselves above average.
The number I’d actually put in front of a board is further down. Among organisations with mature AI governance, 78% have agents running in production. Among those still in the developing phase, it’s 22%. Same appetite, near enough: 86% of all respondents have tested or piloted agents. Very different rates of getting them past the pilot.
That reframes what governance is doing in the sentence. The default assumption in a lot of enterprise AI work is that the model comes first and the process catches up later, and that security is the department that says no. Schellman’s split points the other way, and the mechanism isn’t mysterious. Defining who owns which system, running AI-specific incident response, putting real oversight around agentic use and bounding what an agent can reach are the things that make it possible to let an agent touch production data at all. Without them, the only safe move is to keep agents away from anything that matters, which looks like caution and functions as containment.
Two caveats I’d want stated before anyone quotes this at a budget meeting. The first is that this is correlation presented in a causal shape. Organisations with mature governance programmes tend to be larger, better resourced and further along in general, and those same properties independently predict getting anything into production. The report shows the two travel together. It doesn’t isolate governance as the cause, and the press release doesn’t claim to.
The second is who’s asking. Schellman is an attestation and compliance firm, the first ANAB-accredited ISO 42001 certification body and the first authorised AIUC-1 auditor. A report from an audit company concluding that organisations need mature, demonstrable, audited governance is not a neutral instrument. That doesn’t make the 78/22 split wrong, and the methodology is disclosed, which is more than a lot of vendor research manages. It does mean the framing deserves the same scrutiny you’d give any other piece of commissioned research.
Read with those held in mind, it’s still the most useful governance datapoint I’ve seen this month, mostly because it gives the argument a number. “Trust matters” has never once moved a roadmap. “Organisations with mature governance are about three and a half times more likely to have agents running in production” might.