Survey highlights frequency of AI-generated misinformation, biased outputs and use of unapproved AI tools
HR professionals should review their organization's oversight practices before the next artificial intelligence (AI) rollout goes live, as new data shows most employers are not slowing down despite mounting risk.
Overall, 86% of organizations experienced at least one AI-related incident in the past year, reports OneTrust.
Despite that, only 27% slowed or paused deployment in response, based on the survey of 1,200 senior business decision-makers across eight markets, including Canada, conducted by Sapio Research on behalf of OneTrust.

Agent use outpaces governance controls
OneTrust report's clearest divide involves AI agents – autonomous systems that take actions on behalf of users. Eighty-seven per cent of respondents said their organizations encourage agent use.
However, only 47% say they have clear governance, oversight and controls in place to manage it, the study found. Another 40% say they encourage agent use while governance and controls are still under development.
That gap has consequences. Nearly half of respondents (48%) reported at least one incident involving unapproved AI or agent actions, and 28% reported two or more such incidents.
Blake Brannon, Chief Innovation Officer at OneTrust in Atlanta, says the findings point to a structural issue. "Every company is trying to hold on to two things at once: the speed they are getting from AI, and control over what AI does," Brannon says. "The research says most are losing the second while working harder than ever to keep it."

Coordination and investment lag behind
Despite active governance programs, just 5% of respondents say coordination and accountability are clear across the full AI lifecycle, reports OneTrust. Organizations perform an average of four governance activities, yet lifecycle-wide coordination remains rare.
The workload behind that gap is also growing. Four in 5 (80%) respondents say their function spends more time managing AI-related risk than 12 months ago, with an average increase of 26% in working hours.
In response, 98% of organizations plan to increase AI governance technology budgets in the next financial year, with an average planned increase of 25%.
Marta Sanz, Head of AI Governance at BBVA, says her team now brings governance questions earlier into use-case design. "We have learned that friction increases when questions are addressed too late, after key design choices have already been made," Sanz says.
Employers weighing similar changes may find OneTrust's AI governance frameworks for Canadian workplaces coverage useful, alongside its reporting on shadow AI risks and unapproved employee tool use and employee AI literacy training programs.

Best practices for employers
Here's a table of evidence-based recommendations for organizations that keep deploying AI despite incidents – drawn from AI governance research bodies, standards organizations, and industry analysts:
|
Recommendation |
What the data shows |
Source |
|
Classify AI systems and agents by autonomy tier rather than applying one policy to all |
Gartner predicts that by 2027, 40% of enterprises will demote or decommission autonomous AI agents due to governance gaps discovered only after incidents, because they treat governance as "binary, either locked down or fully trusted." A four-tier classification tied to a system's autonomy and potential consequences, proposed as an extension to the U.S. National Institute of Standards and Technology's (NIST) AI Risk Management Framework, recommends scaling oversight requirements to match each tier. |
Gartner, "Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure" (May 26, 2026) |
|
Deactivate only the specific system causing unacceptable risk, not the whole AI program |
NIST's AI Risk Management Framework calls for teams to immediately stop development and deployment when a specific AI system shows unacceptable risk, then keep that system offline until the risk is properly managed. This targeted approach aligns with OneTrust's 2026 finding that only 27% of organizations paused deployment broadly after an incident, while most expanded monitoring or training instead. |
NIST AI Risk Management Framework (AI RMF 1.0), National Institute of Standards and Technology |
|
Build and rehearse AI-specific incident response playbooks before an incident occurs |
Analysts note that a common governance pitfall is "skipping AI-specific incident playbooks and rehearsals before production emergencies strike." Gartner's Shiva Varma, Senior Director Analyst, said that without strong security testing, audit trails, and agent-specific incident response procedures, approvals "can degrade under time pressure or approval fatigue, creating a false sense of safety." |
NIST AI RMF implementation guidance; Gartner press release (May 26, 2026) |
|
Move from periodic AI security reviews to continuous, real-time monitoring |
The World Economic Forum's Global Cybersecurity Outlook 2026 found that the share of organizations conducting periodic security reviews of AI tools before deployment rose from 37% to 64% year over year, but warns governance "must transition from periodic verification to continuous assurance" as systems become more autonomous. Highly resilient organizations were far better prepared for incidents: only 15% reported insufficient incident response planning, compared with 37% of less resilient firms. |
World Economic Forum, Global Cybersecurity Outlook 2026 (with Accenture) |
|
Treat incident response capability as a declining asset that needs reinvestment, not a solved problem |
Stanford HAI's AI Index 2026 recorded 362 documented AI incidents in 2025, up 55% from 233 in 2024, while the share of organizations rating their own AI incident response capability as "excellent" fell from 28% to just 18% over the same period. This suggests response readiness is falling even as incident volume rises. |
Stanford Institute for Human-Centered Artificial Intelligence (HAI), AI Index Report 2026 |
|
Match governance investment to the scale of the risk, not just the scale of adoption |
OneTrust's 2026 AI-Ready Governance Report found that 98% of organizations plan to increase AI governance technology budgets in the next financial year, with an average planned increase of 25%, even as only 47% report clear governance controls over AI agent use. The gap suggests spending intent alone will not close the oversight gap without structural changes to how that budget is deployed. |
OneTrust, 2026 AI-Ready Governance Report (Sapio Research survey) |