Organizations are starting to govern generative AI with policies, testing, human oversight and incident-response plans, but adoption does not mean those controls are ready. Recent surveys show AI use spreading faster than formal rules and the ability to investigate or stop a harmful system. The figures below describe distinct respondent groups, not a single trend across all organizations.
How widely are organizations using generative AI?
Use is already present, but the evidence points to different levels of adoption and maturity depending on the sector and who was surveyed.
- European insurers: The European Insurance and Occupational Pensions Authority (EIOPA) says its February 2026 report draws on 347 undertakings across 25 countries. Nearly two-thirds actively use generative AI, while most remain at the proof-of-concept stage. This describes European insurance undertakings, not employers generally. EIOPA’s survey and report.
- European business and IT professionals: In ISACA’s survey of 561 professionals, fielded March 28–April 14, 2025, 83% believed employees in their organization were using AI. Separately, the release headline says nearly three-quarters of European IT and cybersecurity professionals reported staff were already using generative AI. These are distinct formulations and respondent populations; the survey also included more than 3,200 respondents worldwide. ISACA’s 2025 findings.
These snapshots should not be read as a time series: they involve different populations, questions and fieldwork. They do, however, illustrate why an organization needs to know which tools and use cases are actually in use rather than assume adoption is limited to formally approved projects.
What do the surveys say about governance and readiness?
Written policy is not yet universal
In ISACA’s 2025 European survey, 31% of respondents said their organization had a formal, comprehensive AI policy. The same release reported that 63% were very or extremely concerned that generative AI could be turned against their organization. These are reported views and policy status, not verified measures of attacks or resulting harm. ISACA’s 2025 survey release.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Concern about synthetic media exceeds reported investment
In that survey, 71% expected deepfakes to become sharper and more widespread over the following year, while 18% said their organization was investing in deepfake-detection tools. The first figure is an expectation; neither figure establishes actual incident frequency or the effectiveness of detection tools. ISACA Chief Global Strategy Officer Chris Dimitriadis said, “With the EU AI Act setting new standards for risk management and transparency, organisations need to move quickly from awareness to action.” ISACA’s June 25, 2025 release.
Incident response and accountability remain uncertain for many
ISACA’s February 2026 fieldwork among 681 European digital-trust professionals found that 59% did not know how quickly their organization could halt an AI system during a security incident; 21% said it could do so within half an hour. Forty-two percent expressed confidence in investigating and explaining a serious AI incident, including 11% who were completely confident. A third (33%) did not require employees to disclose AI use in work products, and 20% did not know who would ultimately be accountable if an AI system caused harm. These responses describe the surveyed professionals, not measured incident outcomes. ISACA’s 2026 incident-readiness findings.
Rank #2
ISACA’s Dimitriadis described the operational challenge this way: “Risk management, prevention controls, detection mechanisms, incident response and recovery strategies are the foundations of good cybersecurity practice, and they need to be applied to AI with the same rigour and urgency.” ISACA’s March 23, 2026 release.
What should an AI policy cover?
A useful policy connects permission to practical controls across the system lifecycle. It should make clear what is allowed, who approves it, what information can be used, how outputs are checked, and what happens when something goes wrong.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
- Inventory approved systems and use cases. Record each system, its intended use, accountable owner, data involved and risk tier. Define who may approve a new tool or use case and how exceptions are handled.
- Set rules for data entry. Specify which confidential, personal, regulated or proprietary information may be entered into which approved systems. Give employees a clear alternative when a tool’s data handling is unsuitable or unknown.
- Require proportionate testing. Test before deployment and after material changes to models, prompts, tools or workflows. Document known limitations, expected use and points where a person must review the output.
- Assign accountability and oversight. Name an owner who can make decisions about the system. Require appropriate human review, especially when outputs affect people or inform consequential decisions.
- Keep evidence and prepare for incidents. Log relevant use and preserve records that let responders reconstruct what happened. Establish how to halt or contain a system, escalate the issue, investigate, disclose as appropriate and recover.
- Train staff for the actual rules. Cover approved uses, output verification, privacy, security and synthetic-media awareness. Training can support policy, but ISACA’s survey findings do not show that any particular course resolves governance gaps.
How can a company stop employees from putting sensitive data into AI tools?
Start with enforceable boundaries rather than a blanket warning. Identify approved tools and permitted data for each, then explain which information must not be submitted and where employees should go instead. Where practical, use access controls and approved work environments to make the safe path easier than an unapproved public service. Assign an owner to review exceptions and update the rules when tools or data practices change.
Make the rules specific enough to guide real decisions: distinguish public material from internal business information, personal data, regulated records and trade secrets; state whether anonymized or summarized information is permitted; and explain how to report an accidental disclosure. Do not claim that a policy alone prevents data exposure. The organization also needs visibility into use and a response process for suspected disclosure.
Rank #4
What threats should controls address beyond inaccurate output?
Generative AI risk is not limited to plausible-sounding errors. NIST’s 2025 adversarial machine-learning taxonomy identifies evasion, poisoning, privacy and misuse attacks among the categories relevant to generative AI. These are threat classes to consider, not reported incident rates. NIST’s adversarial machine-learning taxonomy.
That broader view supports controls for data handling, security, testing, access, human review and incident response—not just fact-checking the text a model produces.
Best Value
How can organizations use NIST guidance?
NIST’s AI Risk Management Framework (AI RMF) is voluntary guidance intended to help organizations incorporate trustworthiness into AI design, development, use and evaluation. NIST says the framework was released January 26, 2023, and its Generative AI Profile was released July 26, 2024. NIST’s live page says the AI RMF is being revised; the revision should not be described as complete unless NIST updates that status. NIST AI Risk Management Framework.
The GenAI Profile says organizations may use existing risk tiers or adapt them for generative-AI-specific risks. Because these systems may be less understood and behave differently across contexts, NIST identifies circumstances where additional human review, tracking and documentation, and management oversight may be warranted. It also frames governance, pre-deployment testing, content provenance and incident disclosure as relevant considerations. The profile is guidance, not proof of implementation or a universal legal requirement. NIST’s Generative AI Profile.
For an organization, the practical value is a structure for asking who is responsible, what could go wrong, what evidence is needed and how risks will be managed as the system changes. The right controls depend on the use case and its possible impact; a low-impact drafting assistant and a system influencing consequential decisions do not call for identical oversight.
How to assess whether controls are working
Do not judge readiness by the existence of a policy alone. Check whether people can use the rules and act on them in practice.
Quick Recap
- Governance: Is there a current inventory, an approval route and a named owner for each material use?
- Lifecycle: Are systems assessed before launch, monitored in operation, reviewed after significant changes and covered by an incident process?
- Data and security: Can staff tell which information is permitted in each tool, and are access and security responsibilities clear?
- Human oversight: Is review assigned where outputs affect people or consequential decisions, with a clear accountable decision-maker?
- Testing and evidence: Are limitations, test results and relevant usage records retained so the organization can explain how an output or incident occurred?
- Workforce readiness: Do employees know approved uses, verification expectations and how to report misuse or accidental disclosure?
- Response and recovery: Can the right people halt or contain the system, investigate, communicate and restore safe operations?
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

