The "oversight gap": why 60% of the companies run AI without a full picture of it
AI no longer just answers questions. It drafts, analyzes, recommends and, increasingly, acts. Yet in most companies, nobody can say precisely where it operates, what it produces or which decisions it influences. This mismatch between the speed of deployment and the capacity to control it has a name: the oversight gap.

The studies published in recent months paint a consistent picture. According to Dataiku's Global AI Confessions Report, conducted in July 2026 among 685 CIOs in eight countries including France, 60% of companies have no central AI governance layer. 81% of CIOs admit they lack full visibility into AI agents built outside official IT channels, and 72% cannot reliably verify that those agents deliver the intended results.
Other surveys point the same way. EY's Technology Pulse Poll, conducted in early 2026, found that 52% of department-level AI initiatives operate without formal approval or oversight. Kiteworks reports that 65% of organizations discovered AI use they had never authorized over the past twelve months. In other words, six companies in ten have no central view of what AI is doing. The question is no longer whether AI is being used in the company, but who really knows what it is doing there.
A gap that widens as AI becomes autonomous
As long as AI was limited to a chat assistant, the risk stayed contained: an employee asked a question, read the answer and decided whether to use it. The human was, by design, in the loop. AI agents change that. An agent doesn't just suggest: it chains tasks together, queries databases, drafts documents and sometimes triggers actions. And it can be built in a few hours by an employee with no technical skills at all.
The result is that agents multiply faster than companies can keep track of them. In the Dataiku survey, 84% of CIOs agree that employees are building agents faster than IT can govern them, and 67% estimate that more than fifty agents are already running in production. EY, for its part, finds that 26% of senior AI executives at large US companies using agentic AI say their organization cannot detect unauthorized agents operating internally.
Three blind spots that feed the oversight gap
The first blind spot is inventory. Many companies cannot list the AI tools and agents their teams are using. Subscriptions taken out by business units, assistants built into existing software by default, agents cobbled together by enthusiastic employees: all of it flies under the radar. You cannot oversee what you cannot see.
The second blind spot is the gap between rules and practice. EY finds that 98% of large publicly traded US companies say they have a formal AI governance policy, yet 47% admit they have bypassed their own process to speed up an urgent deployment. Governance exists; it simply isn't applied when it gets in the way. And 85% of technology executives surveyed by EY acknowledge prioritizing speed to market and managing risks as they go.
The third blind spot, and the most underestimated, concerns decisions themselves. A market analysis, a regulatory summary or a recommendation produced by AI can travel all the way up to the executive committee without anyone knowing exactly where the figures came from, which assumptions were made or which sources were left out. The risk is not only operational or legal. It is strategic. A major decision can rest on an analysis that nobody has really checked.
What leaders can do right now
Closing the oversight gap does not mean slowing AI down, but making it visible and defining roles and responsibilities. A few workstreams are enough to regain control.
The first is to take a full inventory. Which tools are being used, by whom, with what data, to produce what? This inventory, often revealing, is the precondition for everything else. It must include informal usage, which is precisely what escapes control.
The second is to assign an owner to every significant use. Every agent and every tool that feeds a process or a decision must have an identified owner who can explain what it does, what data it relies on and how its outputs are checked. An agent without an owner is an agent out of control.
The third is to scale oversight to the stakes. Not every task deserves the same level of control. Rewording an email needs no particular check; an analysis meant to inform an investment, an acquisition or a reorganization requires systematic expert review before it reaches leadership.
The fourth is to take the subject to board level. According to Grant Thornton, 48% of boards have set no expectations for AI governance, even as they approve major AI investments. And only 20% of companies have a tested response plan for when an AI system fails. Overseeing AI is a governance responsibility, not a technical matter to delegate to IT.
The wrong answers
Faced with the scale of the problem, some reactions are understandable but counterproductive. Three are worth avoiding.
The first is prohibition. Blocking AI tools doesn't make use disappear; it makes it invisible. Employees keep using AI on their personal devices, with company data, and the oversight gap grows even wider.
The second is governance for show. Writing a charter, having it signed and considering the matter closed changes nothing about how AI is actually used. A policy that is not supported by tools, not monitored and not applied under pressure is just a document.
The third is blind faith in monitoring tools. Agent supervision solutions are useful, but they tell you an agent is running, not that it is producing the right results. As Dataiku co-founder and CEO Florian Douetteau puts it: "Monitoring tells you an agent is running. Managing tells you whether it's earned the right to keep running." Human judgment remains irreplaceable.
Oversight as a condition for value
The oversight gap is not just another compliance issue. It is one of the reasons so many companies invest in AI without seeing measurable results. A technology you cannot see is a technology you cannot improve, measure or scale with confidence.
The companies that capture value from AI are neither those that deploy it fastest nor those that control it most strictly. They are the ones that know, at any moment, where it operates, what it produces and who is accountable for it. That visibility is not a brake. It is what makes it possible to accelerate without taking reckless risks.
For a business leader, then, the right question is not "are we using AI responsibly?", to which everyone answers yes, but "could I explain to my board tomorrow what AI is doing in my company and who has checked it?" If the answer is hesitant, the oversight gap is already there.
Hymeria's position
At Hymeria Consulting, oversight is not optional: it is the foundation of our model. Our analyses are produced by more than 40 specialized AI agents, but none reaches a client without being reviewed, challenged and validated by an expert with over 15 years of experience who takes responsibility for it. Every deliverable, whether a study, an analysis or a business plan, is sourced and traceable: leaders know where the figures come from and which assumptions the conclusions rest on. All in 5 to 10 days, within a fixed budget agreed before the project starts.
Do you know what AI is doing in your company, and who has checked it?
Book one hour with a Hymeria expert, or start a free four-question strategic assessment.
Sources
- Dataiku, Global AI Confessions Report: CIO Edition (2026)
- EY, AI Risk and Governance Survey (2026)
- EY, Technology Pulse Poll (2026)
- Grant Thornton, 2026 AI Impact Survey Report (2026)
- Kiteworks, Data Security and Compliance Risk: 2026 Annual Survey Report (2026)