Eighty-one percent of executives say they believe more AI is running across their organizations than they can account for.
That's according to a ServiceNow survey of 550 C-suite executives across eight industries and 13 countries, conducted with independent research firm ThoughtLab. The finding points to a control gap many companies may not realize they have. Most executives can’t say how much AI is running inside their own organizations.
Control breaks in five places: seeing AI, acting on it, governing it, owning it, and accounting for it. Most organizations fall short in every one of these areas, and the challenges compound.
Under pressure to deploy AI and show results, nearly half of organizations have taken a deploy-now, govern-later approach.
Only 29% of executives say their organizations can trace what an AI agent or automated workflow did across every system it touched, according to our research. About half (49%) can mostly trace it with gaps. Nearly two out of 10 (19%) can only trace the primary system where the action started.
Most organizations govern AI, workflows, and AI agents with frameworks designed for static software, not autonomous systems. Only 20% maintain a live, auto-updating inventory of their AI assets. Nearly a third (31%) work from a static list or keep no inventory at all.
The cost of not seeing extends beyond a single metric. Organizations lose visibility into ungoverned spend, face compliance exposure, carry security risks, and lose the ability to apply consistent controls across systems.
In most organizations, detection trails behind incidents. Only 27% get an automated alert the moment an AI agent or workflow behaves outside its intended limits. The rest find out later: 52% rely on scheduled monitoring, and 20% depend on someone reading logs or activity reports.
But manual monitoring and schedules create lag time. An agent that starts misbehaving at 2 a.m. may not be detected until the next scheduled scan, hours later. In that window, it might have accessed multiple systems, exfiltrated data, modified records, and cascaded failures across infrastructure.
Most organizations are governing AI with frameworks built for a pre-AI world.
Picture a policy written for one AI platform. It works there. If a workflow moves the same task to a different tool, the policy doesn't follow.
Only 27% of organizations define a central AI policy and enforce it consistently across every tool and system on which AI runs. Just 19% say formal governance covers nearly all their AI agents and AI-enabled workflows. Nearly half of executives surveyed (47%) say AI deployment is significantly outpacing or somewhat ahead of governance and controls.
Policy written for one platform doesn't travel with the AI tools on a different one.
Fragmented ownership makes it harder to act when something goes wrong. Fifty-nine percent split accountability across functions, relying on a coordinating body that often lacks authority to act.
When decisions require consensus across silos, decisions can stall. Even where a single leader or team owns the full lifecycle—just 29% of organizations—only 37% of those leaders have authority that fully matches their accountability. They're accountable for outcomes but often can't control the budget, policy, or system access needed to change them.
Unattributed AI spend is invisible waste. Only 28% of organizations can attribute nearly all AI spend to specific teams or use cases. The rest track it more loosely: 47% attribute most spend, 20% about half, and 5% some or none.
On average, organizations estimate that 15% of their AI spend is unaccounted for or ungoverned. That's material spend flowing through the organization with no clear owner and no clear value. Without visibility into spending, optimization suffers.
As AI spending accelerates, manual reviews become bottlenecks. Fifty-one percent set budgets but enforce them manually, checking spend against limits by hand rather than through automated controls.
If you can track spend, you can direct it—investing more where it's delivering and pulling back where it isn't. That's how visibility into spend can lead to stronger AI return on investment.
AI doesn't stay contained to a model or a dashboard. The moment it acts, it's doing work: triggering processes, changing decisions, consuming budget. Governance built outside that workflow will always be one step behind it.
Effective AI control lives inside the work itself: automated, not bolted on after the fact. Learn about five strategies for governing AI across work, boundaries, systems, and teams in our report.