CAIO of One
[ ← Journal ]

Your company has an AI policy. Who is allowed to skip it?

Covers 2026-09-10 to 2026-09-24 CAIO of One Editorial

If you are a new Chief AI Officer, a policy is probably near the top of your list. A survey EY published on September 15 suggests the policy is rarely the missing piece. The missing piece is what happens on the day someone senior says the launch cannot wait.

What the survey found

EY surveyed 202 senior AI decision-makers at US public companies with at least $1 billion in annual revenue. The fieldwork ran from May 28 to June 15, 2026, with a margin of error of plus or minus 7 points. EY sells assurance services, so read the numbers as a company-reported survey from a firm with a stake in the answer.

The headline pair:

  • 98% say their organization has a formal AI governance policy.
  • 47% say their organization has, at some point, not applied its governance process for an urgent deployment.

The agent numbers are sharper. 91% say their organization uses agentic AI. Among those:

  • 49% say their governance framework has not yet been updated for it.
  • 85% say at least a handful of these systems take actions with no person involved in real time.
  • 26% say they cannot detect unauthorized AI agents inside the company.

And 36% report an AI incident or failure in which the impact was materially negative.

CIO Dive’s coverage adds that among organizations using agentic AI, about one in four said accountability for monitoring those systems after deployment was undefined, and about two-thirds worry they lack the in-house expertise to design, implement or evolve governance controls. It quotes Richard Jackson, EY’s Americas Assurance CTO: “Effective AI governance should be more than a piece of paper or a set of policies that is filed away.”

These are large public companies, not the mid-size firms where many CAIOs work alone. The pattern still transfers. If companies with full compliance departments skip their own process under pressure, a company with one AI leader will face the same request sooner.

The bypass is a design problem

A policy with no fast lane gets skipped. When the only choices are “full review in three weeks” and “no review,” urgent work picks the second one, and the policy loses the argument without anyone deciding to abandon it.

So the useful question for a CAIO of one is not “how do I stop people skipping review?” It is “what is the smallest review that must survive any deadline?” Write that down now, while nothing is on fire.

A bypass rule you can adopt this month

Here is a one-page rule. Adjust the details to your company and have counsel read it before you publish it; it is a starting template, not legal advice.

1. Anyone may request the expedited path. It is not a favor. Put it in the policy so people use it in the open.

2. The expedited path still requires four things, in writing, before launch:

  • An owner. One named person who answers for the system after go-live. Not a team, a person.
  • A data line. What data the system can see, and a statement that it does not see the categories your policy bans.
  • An action list. What the system can do on its own: send, pay, delete, change a record, contact a customer. If the list is empty, say so.
  • An off switch. Who can turn it off, and how, in under an hour.

3. Some things never go through the fast lane. Pick your own short list. A reasonable starting point: any agent that can move money, change customer records, or contact people outside the company without a person approving each action. For those, the answer to “it’s urgent” is a smaller pilot, not a skipped review.

4. Every expedited launch gets a full review within 30 days. Put the date in the inventory when the system launches.

5. The CAIO reports the count. How many launches took the fast lane this month, and how many completed their follow-up review. That number tells the CEO whether the policy is working better than any statement of principles.

Notice what this rule is built around. EY’s three agent findings (frameworks not updated, actions without a person in real time, agents nobody can see) all come back to the same gap: nobody knows which systems can act, and nobody is named to watch them. The four written items close exactly that gap, and they can be written in an hour, not three weeks.

What to do this week

  • Start the inventory with one column that matters most: can this tool take an action on its own? Ask each department head for the tools their team uses, not only the ones the company bought.
  • Name an owner for every system that answers yes. If nobody will take it, that is your first escalation to the CEO.
  • Draft the bypass rule above and circulate it to the two or three executives most likely to invoke it. Their objections now are cheaper than their workarounds later.
  • Add one line to your monthly report: expedited launches this month, and follow-up reviews completed.

The policy you inherited may be fine. The test is whether it holds on the worst week of the quarter. Design for that week.

Sources

  1. EY survey finds that autonomous AI implementation outpaces oversight, yielding an AI governance gap · EY · 2026-09-15
  2. Businesses sidestep AI governance policies as concerns mount · CIO Dive · 2026-09-16

Researched and drafted with AI assistance, checked against the sources above.

Run it as a business of one.

Begin →