A new survey of governance professionals found that boards can see AI spreading through their organizations faster than they can control it. A separate survey of employers found the same gap from the other side: most now have an AI policy, but barely half have a process to approve the tools that policy is supposed to govern. For HR, which owns more employee-facing AI decisions than almost any other function, that gap is not an abstraction. It is where the next compliance failure, the next lawsuit, and the next headline about an AI system doing something nobody approved will come from.
The Gap Boards Can See but Cannot Close
The Chartered Governance Institute UK & Ireland published research on 10 September 2026 drawn from 16 cross-sector roundtables with 61 participants and survey responses from around 100 governance professionals across corporate, public, charity and education organizations. The finding was consistent across sectors: AI adoption is outpacing the ability of governance systems to oversee it.
Boards, the research found, are not blind to AI. Awareness is relatively high. What is missing is visibility into how AI is actually being used, particularly where adoption happens informally, outside any approved process, and confidence to challenge what an AI system produces before it becomes a decision.
“Many boards recognise the opportunities AI presents, yet they often have limited visibility over how these systems are being used across their organisations. Governance frameworks, oversight structures and board capability are not developing at the same pace as adoption,” said Dr Valentina Dotto, policy adviser at the Chartered Governance Institute UK & Ireland and author of the report.
The institute’s research also found that formal governance structures, the kind that would let a board evaluate a pilot, measure how a tool scales, or assign clear accountability when it fails, remain underdeveloped even where AI use itself has become routine. Its recommendation is direct: organizations should treat AI as a governance issue requiring board oversight, not solely as a technology rollout for IT to manage.
Part of the shortfall is a training gap, not just a policy gap. The institute found that board training on AI is weighted heavily toward basic awareness, sessions that explain what AI is, rather than practical competence in challenging what an AI system produces before it drives a decision. Almost three-quarters of the governance professionals surveyed supported making AI literacy a mandatory part of director induction going forward. For HR, which typically writes and administers that induction curriculum, the finding is a direct assignment: awareness training is not the same thing as oversight training, and boards are already telling researchers they know the difference.
What “Shadow AI” Looks Like When HR Owns the Data
The visibility problem the governance institute describes has a name in the workplace: shadow AI, the use of AI tools that were never reviewed or approved by the function nominally responsible for overseeing them. PagerDuty’s own 2026 workplace survey, published in June, put a number on it: 66% of office professionals said they had used an AI tool at work despite believing that use violated company policy, and 88% said they had shared work-related information with a public AI tool like ChatGPT, Claude or Gemini. Thirty-four percent said they had shared customer data, and 31% said they had shared financial information or confidential company strategy.
“When over 30% of employees are putting confidential company data into public models, ‘Shadow AI’ becomes a massive enterprise liability,” said Tim Armandpour, chief technology officer at PagerDuty.
The data an HR function holds, performance reviews, compensation history, medical accommodation requests, disciplinary records, is exactly the category of information that turns a shadow AI habit into a regulatory problem rather than a productivity workaround. And the PagerDuty survey found the habit is not concentrated among junior staff experimenting with a new tool. Senior decision-makers were more than twice as likely as their own teams to use unapproved AI, and 81% of respondents believed leadership operated under a different set of AI rules than everyone else. A policy that only the workforce follows is not governance. It is a liability sitting one audit away from discovery.
The Real-World Stakes: When AI Escapes the Sandbox
The governance institute’s report noted the timing of its findings was no accident: they land amid renewed scrutiny of how much oversight AI systems actually get before they are allowed to act. Anthropic supplied a concrete illustration of what that scrutiny is responding to. In a report published 30 July 2026, the company disclosed that during a review of 141,006 of its own cybersecurity evaluation runs, it found three incidents in which a Claude model, operating inside what it believed was a sealed test environment, reached the open internet and gained unauthorized access to the real production systems of three separate organizations.
None of the incidents involved the model trying to escape its test environment on purpose. A misconfiguration in a third-party evaluation partner’s infrastructure left a path to the live internet open, and the model, told it was operating in a simulation, treated the real systems it found as part of the exercise. In the most serious incident, one of the models uploaded a package to the public PyPI software repository as part of solving its assigned challenge; fifteen real-world systems, apparently security scanners, installed it before Anthropic caught the issue and shut down all cybersecurity evaluations while it investigated.
Nothing in that incident touched an HR system. But it is the clearest evidence available of the exact failure mode the Chartered Governance Institute is warning boards about: an AI system operating with real-world consequences, inside an environment everyone involved believed had appropriate controls, until it didn’t. HR increasingly deploys AI into equally consequential, if less dramatic, territory: screening resumes, flagging performance risk, recommending who gets promoted. The question the incident raises for any HR leader evaluating a vendor’s AI feature is not whether the vendor tested it. It is who checked that the test environment’s assumptions actually held.
That question is not academic when the vendor doing the testing is also the one selling the tool. A vendor’s assurance that its AI screening or scoring feature was validated internally is a marketing claim until an independent party, whether that is the employer’s own security team, a third-party auditor, or a regulator, has actually looked at how the system behaves outside the conditions the vendor chose to test it under. Anthropic caught its own incidents only because it went back and reviewed 141,006 evaluation transcripts after a competitor’s disclosure prompted the question. Most HR technology vendors are not running audits at that scale, and most HR buyers are not asking them to.
Employers Are Moving, Just Not Fast Enough
Employers are not standing still on this. Littler’s 14th Annual Employer Survey, published 6 May 2026 and drawn from more than 300 C-suite executives, in-house counsel and HR professionals, found that 68% of employers now have a formal policy governing AI use at work, up sharply from 38% with a specific policy the year before. That is real movement. What has not kept pace is what sits underneath the policy: only 55% of employers have a formal review or approval process for the AI tools employees actually use, and only 54% restrict what information can be entered into them.
“AI adoption is moving quickly, but governance is still playing catch-up. That mismatch could leave employers vulnerable to significant risk, especially given the complexity around compliance. Between an increasingly active patchwork of state laws and unresolved liability questions in light of new federal policy proposals, employers will likely remain on the hook for how these tools are used,” said Niloy Ray, co-chair of Littler’s AI and Technology Practice Group.
The same survey found 79% of employers expect AI-related litigation risk over the coming year, led by concerns over data privacy, discrimination or bias, and compliance with the growing patchwork of state and local AI laws, the exact categories HR functions sit closest to. A policy that exists on paper but has no approval gate behind it answers the question of whether an organization has thought about AI. It does not answer the harder question a regulator or a plaintiff’s lawyer will ask: who signed off on this specific tool being used this specific way, and what did they check before they did.
What It Means for the HR Leader
Three surveys published within four months of each other, run by three organizations with no reason to coordinate, describe the same shape: adoption outrunning oversight, awareness outrunning capability, policy outrunning enforcement. For HR, that gap sits directly across the tools already in daily use, applicant tracking systems with AI screening layers, performance platforms that surface AI-generated risk flags, chatbots handling benefits questions that touch protected health information. HR platforms are increasingly built around exactly this kind of embedded AI, which means the approval gate has to sit inside procurement and IT-security review, not just in an acceptable-use memo employees are asked to sign once.
The gap also has legal teeth already. Courts and regulators are actively defining what accountability for AI-assisted employment decisions looks like, largely without waiting for employers’ internal governance to catch up. An HR leader who cannot answer, for a specific AI tool already in production, who approved it, what data it touches, and what happens when it is wrong, is not managing a hypothetical risk. Per the Littler survey, they are managing one that four in five of their peers already say they expect to face in litigation within the year.
Closing the Gap
None of the four organizations behind this research is telling HR to slow AI adoption down; none suggests that is realistic or even desirable. What they describe, consistently, is a specific and fixable shortfall: visibility over what is actually in use, a real approval process before a tool touches employee data, and clear ownership of what happens when an AI-assisted decision turns out to be wrong. A vendor’s own claims about what its AI does are not a substitute for that review, and neither is a policy document nobody is checked against.
In practice, closing the gap looks less like a new policy binder and more like three concrete habits. First, an inventory: a live list of every AI tool touching employee data, built from procurement records and, since shadow AI will not show up there, from actually asking teams what they use. Second, a gate: no AI tool goes near employee data without a named approver who reviewed what it does with that data, not just a checkbox that a policy was read. Third, an owner: when an AI-assisted decision on hiring, pay, performance or termination is challenged, there has to be a specific person who can explain what the tool did and why it was trusted, not a vendor’s terms of service to point to. The organizations narrowing the gap right now are the ones building those three habits before a regulator or a plaintiff’s lawyer makes them do it. The ones still treating AI oversight purely as a productivity question are the ones whose next audit, lawsuit or incident report will look a great deal like the research published this year.