Closing the AI Governance Gap: Takeaways from the 2025 AI Governance Survey
Generative AI models are moving from practice into production pipelines, transforming how modern organizations operate. But while innovation surges forward, unfortunately (and scarily), the same cannot be said for AI governance.
To better understand this disconnect, my company, Pacific AI, in partnership with Gradient Flow, launched the 2025 AI Governance Survey. While we suspected governance would be lagging behind, we were surprised at just how far, as well as the divide between large and small companies. But despite the differences, one very clear pattern emerged: AI adoption is accelerating, and maturity around governance is not.
For data scientists, ML engineers, and technical leaders, the message is critical: delivering real-world AI impact requires more than great models. It demands thoughtful, embedded, and proactive governance.
The False Sense of Progress: Policies without Practice
Many organizations think they’re ahead of the curve. In fact, three out of four respondents say they have an AI usage policy in place. Yet, fewer than 60% have designated governance roles, and even fewer have playbooks for managing incidents like bias, data leaks, or misuse.
Among small firms, these numbers drop dramatically. Only 36% have formal governance roles, and just 41% provide annual AI training. This signals a major policy-practice gap. Writing policies is one thing; embedding governance into daily operations is something else entirely.
Key takeaway: Policies must translate into workflows, training, and ownership. If your team doesn’t know who’s accountable for AI risk, your system isn’t governed.
Governance is a Technical Problem (and Opportunity)
Technical leaders are nearly twice as likely to be targeting three to five generative AI use cases in the next year. They are more likely to lead hybrid build-and-buy strategies and to oversee production deployments. Yet they also face the highest governance pressures, report lower training rates for their teams, and encounter unique blind spots — such as limited use of tools for AI incident reporting.
From tracking data drift to setting model thresholds to building red-teaming protocols, mature organizations understand that governance needs to be part of the engineering and product development lifecycle. Automated guardrails can reduce risk while enabling faster deployment.
Key Takeaways: The most successful tech teams integrate monitoring, testing, and risk evaluation into their MLOps stack. In practice, this looks like:
- Observability dashboards for tracking model behavior in production
- Prompt injection and adversarial testing baked into CI/CD
Custom playbooks for handling AI incidents - AI ownership spread across product, engineering, and ML teams
Caution isn’t the Same as Safety
Despite the generative AI hype, most organizations are still in the early stages of adoption. Only 30% have deployed systems in production, and just 13% run multiple deployments. Unsurprisingly, large enterprises are five times more likely to do so than small firms.
Yet this cautious adoption hasn’t led to stronger safeguards. About 48% of companies don’t monitor their AI systems post-deployment — a critical failure point. For small firms, that number plummets to just 9%.
Key takeaway: Being cautious about deployment won’t protect you if you’re not monitoring what’s already in production. Integrate AI safeguards like consistent and automated model monitoring or human-in-the-loop capabilities from the start for validation purposes.
Speed-to-Market Undermines Governance
The biggest obstacle to better AI governance isn’t technical complexity or regulatory confusion. It’s speed. Nearly half of survey respondents, and more than half of technical leaders, cited pressure to move quickly as the top AI governance hurdle.
This is a familiar tension for data teams: governance is seen as slowing progress. But ironically, lack of governance often causes more slowdowns through bugs, rework, or even crisis management after AI failures.
Key takeaway: Developers are playing with fire. It’s not an oversight or lack of awareness hindering AI governance. It’s a decision to prioritize speed over safe deployments. That’s a calculated risk that can land organizations in big trouble.
Small Firm Risk Multiplier
One of the most alarming findings from the survey is the vulnerability of smaller companies. They’re far less likely to monitor models, assign governance roles, conduct training, or understand emerging standards.
Only 14% of small firms report familiarity with leading frameworks like the NIST AI Risk Management Framework. In a tech ecosystem where small vendors often build and deploy advanced models, these blind spots present a significant systemic risk.
Key takeaway: Be it time, resources, or talent, the onus of AI governance by default falls to the larger organizations outsourcing technology. They can ensure their vendors are handling their data with care by:
- Supporting training and governance tooling
- Sharing best practices and templates
- Requiring alignment on standards like ISO 42001 and NIST AI RMF
The Main Takeaway? Stop Treating Governance like a Bottleneck
The organizations seeing the most success with generative AI are those that view governance as a performance enabler, not a barrier. These teams build resilience into their pipelines, assume models will fail, and prepare for recovery. They don’t wait for regulation to force governance, but instead, build it into their culture and systems. This mindset shift is the key difference between ad hoc experimentation and scalable, production-grade AI.
Article by David Talby, CEO, John Snow Labs and Pacific AI
