Insight · AI delivery and governance
The reviewer is the bottleneck
Four independent surveys fielded between December 2025 and April 2026 say the same thing. The hard part of shipping AI is no longer building it. It is getting it past the people who have to sign it off, and keeping it governed once it runs.
Governance now ranks level with engineering skill
Salesforce asked 1,050 IT leaders at organizations of 1,000 or more employees, across 9 countries, what blocks their AI and agent work. Risk, compliance and legal came in at 42 percent. A shortage of AI and agent design expertise came in at 41 percent. Legacy infrastructure came in at 37 percent.
One point of separation on a sample of 1,050 sits within the margin of error, so governance and engineering skill rank level in that data. It has caught up to the thing everyone already knew was hard.
McKinsey, surveying around 500 organizations, found that close to two-thirds name security and risk as the top barrier to scaling agentic AI. Deloitte, surveying 3,235 technology and business leaders across 24 countries, found that 21 percent have a mature governance model for autonomous agents. So four in five are running or planning agent work without one.
How many organizations run unsanctioned agents, and how many know who owns them
Cloud Security Alliance, State of AI and Security Survey, April 2026. 445 practitioners. Sponsored by Zenity. These are two separate questions from the same survey.
Agents are already running without an owner
The Cloud Security Alliance put the same question to 445 practitioners in April 2026. More than half said they had agents running that nobody had sanctioned. More than half said an agent had exceeded the permissions it was given. Almost half had a security incident involving an agent in the past year. The survey found 15% could say who owns most of their agents.
BlackFog, surveying 2,000 employees in November 2025, found that 51 percent had connected an AI tool to a work system without asking IT.
None of this describes a modeling problem. It describes systems in production that nobody signed for.
Building for the reviewer on day one
We build for the reviewer on day one. That means five things exist before a pilot goes anywhere near a review gate.
- A named owner for the system, written down
- Bounded permissions, with the boundary written as a rule and enforced as one
- An audit trail the reviewer can read without asking an engineer to explain it
- A test that shows what the system does when it is wrong, and what it does when it is right
- A defined path for taking it out of production
A system the reviewer cannot pass is a system that does not exist. Building the evidence at the end costs more than building it as you go, and it usually arrives too late to change the outcome.
No published research links governance maturity to shipping more AI. What the survey does show is where the blocker sits now, and that most organizations have not moved with it.
30 minutes with the engineer who would do the work. Bring the pilot that is waiting on a review, and you will leave knowing what it takes.