NewsMacroEnterprises Accelerate AI Adoption and Turn Focus to Governance, OneTrust Report Finds

Enterprises Accelerate AI Adoption and Turn Focus to Governance, OneTrust Report Finds

Author: AI Business·

Key Takeaways

  • •OneTrust's report found that most enterprises are not slowing or pausing AI deployments despite experiencing AI-related incidents such as intellectual property exposure and agents using, delivering, or deleting data.
  • •Board-level pressure to transform operations and avoid disruption is a primary driver of continued enterprise AI adoption, according to OneTrust Chief Innovation Officer Blake Brannon.
  • •Brannon said traditional governance frameworks designed for human-paced activity are breaking down as citizen developers enable anyone to build AI agents, with companies expecting more agents than humans within two years.
  • •Brannon argued that AI models themselves cannot be trusted, so governing architecture must consist of an independent harness separate from the systems being governed.
  • •As enterprises run fragmented sets of models and harnesses, governance is shifting toward placing guardrails at the points where AI systems take actions affecting enterprise data and operations.
Enterprises Accelerate AI Adoption and Turn Focus to Governance, OneTrust Report Finds

Despite calls from leaders of AI frontier labs for a slowdown, most enterprises are prioritizing stronger governance over pausing their use of artificial intelligence, according to a new report from OneTrust, an AI, data privacy and security vendor.

The report found that while many enterprises experienced AI-related problems over the past year, most are not slowing or pausing their AI deployments. Those incidents include intellectual property exposure as well as AI agents using, delivering, and deleting data.

In a question-and-answer session, OneTrust's chief innovation officer, Blake Brannon, discussed why enterprises continue to push forward with AI and how they can focus more on governance than on the rapid advancement of AI models.

Board Pressure Drives Forward Momentum

The report noted that despite the AI incidents, enterprises are still encouraging the use of AI and AI agents. Asked what is fueling the momentum to deploy the technology, Brannon pointed to pressure from the top of organizations.

“From the top down at every company, the number one topic your board is asking you is ‘What are we doing with AI? How are we transforming the way we work, the products and services we build? Are we going to be disrupted by the frontier models, by incumbent startups? What is our moat?’” he said.

“The pressure is causing everyone to be a little aggressive, accelerating and figuring out how to use AI.”

Once organizations begin evaluating and deploying these tools, governance and security concerns quickly surface, Brannon said. Everyone is looking at the reality that within the next two years, there are going to be more agents acting than there are humans in every company in the world.

He argued that the programs and processes companies have built over time to govern themselves were designed in an era when a human instantiated everything the company did — either a person was doing the work, or a person was building a deterministic software system to do it. That made those activities governable because they moved at a human pace.

“Today, you have the citizen developers, the citizen builders. Everybody can build an agent,” Brannon said. That fundamentally breaks down how traditional governance and security have worked in organizations, he explained, because what organizations once did to protect and safeguard their data took weeks — and now it must be figured out in seconds.

From Proof of Concept to Scale

Asked how this shift leads organizations to invest in governance, Brannon said trust is the gating factor for autonomy.

“You can create all this great AI, but if you do not trust it, you cannot turn it loose,” he said. “You cannot let it run autonomously, so you must solve this.”

Investment is becoming critical, he added, because enterprises are moving beyond proof of concepts and getting to scale. With scale comes the simple question of how to trust AI, know what is happening with it, and control it — which is why organizations are devoting more time to the problem.

One way to frame the challenge, Brannon said, is that AI systems must behave the way the organization or one of its employees would. What a company deems an acceptable action is rooted in factors such as compliance, security practices and its brand promise, and agents must mimic those standards. That, he said, is one part of the problem.

The second part is preventing bad things from happening. “You must have the car's emergency brakes on. You must see that this agent is going to take destructive action, and you want to stop it,” Brannon said. That is a nuanced task because AI systems do not inherit things like people's identity and permissions, and “we want humans to be in the middle of something like that.”

Two Principles for Governing Fast-Moving AI

As organizations move quickly with AI while technology vendors update their models at a rapid pace, Brannon outlined two principles shaping the architecture needed to attach trust to these systems.

The first is the recognition that a model itself cannot be trusted. “We see someone post a blog or article almost every weekend saying, ‘Please regulate us, we can't trust our systems, and this is very dangerous,’” he said.

That means organizations must assume a model will break out of its harness, and that a model could manipulate itself into convincing itself that whatever it is doing is acceptable. The governing architecture must therefore be an independent, separate harness from the actual thing being governed.

“This is how society has worked for thousands of years,” Brannon said. “Government power is separated intentionally. Company departments are intentionally separated to create a clear, bias-free distinction between the governing body and the thing being governed.” For AI, he said, that means models and providers need an independent governing agent, or governing harness, to assess what an AI system and agent are doing.

The second emerging principle addresses the complexity of keeping up with constantly changing models and harnesses. Brannon said every organization will run a fragmented set of different model providers, models and harnesses, because marketing wants to use one thing, customer support needs something else and engineering needs something else again. That fragmentation creates tremendous complexity in controlling and governing systems that all behave differently.

The architecture, he said, is shifting toward a simpler question: who cares what the model is doing, or why the model thought what it thought? What matters to an enterprise is when the AI system actually takes an action — when it tries to read data from an enterprise system, send an email or delete a record. In practice, that puts the focus of governance on the points where an AI system can affect enterprise data and operations, rather than on the model in isolation.

“That is when I care about governing something,” Brannon said. “I can design my governing controls around a fixed point where it's connecting to my stuff I care about, and to be able to put the right guardrails and policies in place on that fixed point.”

Editor's note: The Q\u0026A has been edited for style and conciseness.

The Q\u0026A was conducted by AI Business news writer Esther Shittu, who has covered AI technologies and industry trends since 2021 and co-hosts the Targeting AI podcast.

This article is based on reporting published by AI Business on September 21, 2026: Accelerating AI adoption and governance amid an AI slowdown.