AI Adoption: Ethics and compliance functions lag behind their organisations

Ethics and compliance (E&C) functions are increasingly involved in governing the use of artificial intelligence across their organisations. The new The State of AI Adoption in Ethics & Compliance report examines to what extent E&C functions are themselves adopting the technology they help to govern.

The report is based on a June 2026 survey of E&C leaders at 134 organisations. According to the survey, 67.2% of respondents describe their organisations as having reached broad or advanced AI adoption, whereas only 21.6% report the same level of adoption within their E&C functions. The report accordingly identifies a 45.5-percentage-point gap between enterprise-level and E&C adoption.

The survey also indicates that E&C functions already play a significant role in AI governance. According to the report, 63% of E&C leaders have a formal role in enterprise AI governance, while 85.5% of responding E&C functions have written AI policies or guidance and 77.8% maintain approved-tool lists. At the same time, 84% of responding E&C teams have no dedicated AI budget line, and only 4.5% measure the impact of AI using defined metrics.

Respondents also identified several barriers to responsible AI adoption within their own functions. Accuracy and hallucination risks were cited by 53%, confidentiality, privilege or data-exposure concerns by 47.9%, and privacy or personal-data concerns by 33.3%. Budget constraints, by comparison, were cited by 23.9% of respondents answering the relevant question.

The report’s authors characterise the disparity between enterprise and E&C adoption as the “Cobbler’s Children” problem: E&C functions have been involved in establishing governance structures and guardrails for organisational AI use while adopting AI more cautiously within their own activities.

The report interprets the survey responses as indicating that concerns about trust in the technology, particularly accuracy and information exposure, are more prominent barriers than a lack of organisational appetite. It also identifies four patterns in the survey data relating to centralised E&C structures, large teams, mid-sized teams and E&C functions operating within organisations with advanced AI adoption.

Importantly, some of the explanations offered for these patterns are expressly presented by the authors as interpretations rather than findings directly established by the survey. For example, in discussing lower adoption among very large E&C functions, the report suggests that legacy systems, internal processes and additional stakeholders may contribute to integration difficulties, while acknowledging that this explanation was not directly measured.

Based on its interpretation of the findings, the report sets out a sequenced 12-month approach intended to assist E&C functions seeking to increase their use of AI. Among other matters, the authors advocate addressing accuracy and data-protection concerns before expanding use cases, introducing appropriate human review, establishing metrics to measure impact and treating E&C’s own AI adoption as a structured and adequately resourced initiative.

These elements should be understood as recommendations by the authors, rather than conclusions established by the underlying survey data. The report also proposes a risk-tiered approach to human review as organisations move towards more autonomous or “agentic” AI applications.

The composition of the survey sample is relevant when assessing the findings. 89% of respondents represent organisations with annual revenues exceeding USD 1 billion, and 95% work directly within an E&C function. The authors themselves therefore caution that the results are best understood as directional rather than representative of companies generally.

Overall, the report provides new survey data on the developing relationship between AI governance and AI adoption within E&C functions. It also illustrates the distinction between the empirical evidence generated by the survey, Ethisphere’s interpretation of that evidence and the measures the authors propose in response.

These are the upcoming dates for our Annual General Meetings:

Thursday, 18 March 2027

Thursday, 16 March 2028

If you are an ECS member, you are cordially invited to our Annual General Meetings! Each AGM is followed by discussion on current compliance topics and an networking Apèro.

*****

If you have registered  for an event and you can no longer make it, please cancel your registration from the dashboard if your user profile.