Companies have done the homework on AI governance. They've written the policies, built the frameworks, and filed the documentation. And 91% of executive leaders say their organizations have them. Gold star, everyone.Â
But when you dig a little deeper, it turns out that the rules are a beautiful theoretical object, like a unicorn or a balanced budget. They exist in the document, but they're not in the room with us.
According to a new Zapier survey of 548 U.S.-based directors, VPs, and C-suite executives at companies with 500 or more employees, nearly 4 in 5 say their employees are actively bypassing or working around governance processes to deploy or modify AI-powered workflows faster.
The organizations that got ahead of this didn't do so by writing a better PDF. They got ahead of it by building the governance into the tools themselves, so that following the rules isn't a thing you have to remember to do—it's the only thing the tool will let you do.
This report digs into what's driving the workarounds and what tighter oversight looks like when it's more than a PDF.
Key findings:
41% of executives say their organization's goal is to move fast and refine governance as they go, even if it risks compliance
Start with the scale of the problem: 52% of executives say employees bypassing governance processes is a widespread problem at their organization. Another 27% say it's concentrated within specific teams. Only 1 in 5 say it rarely or never happens. Which means 4 in 5 executives are essentially describing their own organization as a governance suggestion box.

At organizations with 500 to 4,999 employees, roughly 81%–82% of executives report employees working around governance processes. It's only at companies with 5,000 or more employees that the number drops, dipping to 64%.
That gap makes it sound like the largest companies have their act together—until you think about it for one more second and realize it probably means the opposite: at these massive organizations, there are countless layers between leadership and the actual work, which means many executives simply can't know how much rule-skirting is happening. Less rule-breaking reported isn't the same as less rule-breaking happening.
Part of what's driving this visibility problem is a split in how companies approach deployment. 41% of executives say their company's primary approach is to move fast and iterate, getting workflows into production quickly—even if that means refining governance and compliance guardrails along the way.Â
Meanwhile, 47% say their organization holds off on deployment until governance and testing are fully locked in. Those numbers are close enough to call it a coin toss, which means employees aren't really bypassing governance so much as picking a side in a debate their own leadership hasn't settled. If the executive suite can't agree on the approach, the policy document was never going to hold the line anyway.
It's the same tension that has existed in software deployment forever: ship it and fix it later, or get it right before it goes out. The difference is that when a buggy feature ships, you push a patch. When an ungoverned AI workflow touches your CRM, Slack, and billing system simultaneously, the patch becomes a little harder to write.
The consequences are often tangible. 47% of executives say AI workflow issues have led to increased manual workload or operational costs. 41% say it caused client- or customer-facing errors. 26% say it has affected revenue, which tends to be the number that finally makes a policy document feel urgent. And with 85% of executives saying AI is running highly critical or mission-critical workflows across their entire enterprise, this clearly isn't the time or place to wing it.
Governance that travels with the work is exactly what Zapier is built for, giving employees the freedom to build and run AI workflows while IT keeps control over what agents can access and act on, across every connected app.
80% of execs say their companies have audit processes, but 28% say their AI policies aren't actually consistently enforced
Having an audit process and actually enforcing what it surfaces are two separate challenges.Â
The audit infrastructure is mostly there. 80% of executives say their organization has a formal process for reviewing its AI governance policy on a regular schedule.Â
At the same time, 28% of the executives we surveyed say their formal policies exist on paper but are not consistently enforced across teams or use cases. This lack of governance can stall AI transformation: employees use AI in isolation and you don't have a way to meaningfully or reliably scale AI usage throughout your organization.

64% of executives at organizations that don't consistently enforce policies say their AI-powered workflows support critical business functions where disruptions would cause noticeable operational or financial impact. That means finance approvals, customer communications, and HR processes are running on workflows that don't consistently follow the rules the organization set for them. Apparently, the guardrails are optional.
Company size tells an interesting story here. Mid-sized organizations are struggling the most with consistent enforcement. At companies with 1,000 to 2,499 employees, 41% of executives report that while formal policies exist, they aren't consistently enforced. That's compared to 26% at companies with 500 to 999 employees, and 23% at companies with 2,500 or more employees.
Most executives have at least a vague sense that something needs to change. Nearly half (49%) say their organization has an appropriate system of checks and balances in place, but feel improvements could be made. Almost all of the remaining respondents land on the opposite end: 46% say their current approach is appropriate and needs no changes, which is way more optimism than the data warrants. The executives who say governance is actively failing them are a small minority at only 4%. But considering what's running on these workflows, that's not a completely reassuring number.
And some companies aren't checking in much at all. 29% of executives say their organization reviews its AI governance policy quarterly or less often, while 2% review it annually or less often. For workflows touching finance approvals and customer data, reviewing governance quarterly is roughly the same energy as checking your smoke detector batteries when you smell smoke.
AI capabilities are moving fast, and the way teams use them is changing just as quickly. Keeping governance strategies on track through it all is harder than it sounds. Building more resilient governance means implementing AI tools that control access and track actions in real time, so oversight moves at the same speed as the tools themselves.
When AI is running mission-critical workflows, checking in quarterly isn't a control strategy. Zapier acts as the managed layer between your AI agents and the apps they connect to. Every connection is OAuth-authenticated, and nothing runs outside of what your policies allow.Â
41% of executives say AI governance ownership varies by department, leaving accountability inconsistent across the organization
Organizations are almost evenly split on who owns AI governance. More than half (51%) of executives say their company has one dedicated team responsible for AI governance, while 41% say ownership varies by department or business unit. In practice, that means two employees at the same company could be operating under entirely different rules.
We asked executives what happens when a workflow fails, and they often say the blame typically lands on several parties, including:Â
A centralized AI team: 57%
The individual or team operating the workflow: 51%
The person who built or configured it: 46%
Those groups frequently overlap, making it easy for actual accountability to be lost entirely when something breaks. In practice, this means the answer to "who owns this?" is technically everyone, which in meetings means nobody.
With ownership this fragmented, AI ethics questions about data use, bias, and accountability don't have a clear home either.
Thankfully, a few things tend to actually make a difference, and none of them involve writing a better policy document.
Know exactly what's running across your organization
If you can't answer—without asking someone first—how many AI workflows are active across your organization and who authorized each one, that's the gap. Centralizing access management is a decision that has to come from the top because IT can only enforce what leadership has actually mandated.
When agents and automated processes connect to company tools without IT's knowledge, things can go sideways fast. With Zapier, secure, OAuth-managed authentication across thousands of apps makes this significantly easier to enforce at scale, without relying on shared passwords or manual credential tracking.
Define ownership before deployment, not after
Accountability gets murkier as AI workflows grow more complex and touch more teams. The question of who answers when something breaks should be decided before a workflow goes live, not after an incident forces the conversation. Nearly 1 in 4 executives say accountability is shared across teams but is inconsistently assigned, suggesting ownership often isn't resolved before launch.
Anyone who's been in a post-incident meeting knows how this goes. Something breaks, and people look around the table like deer in headlights. With AI workflows touching multiple systems and teams simultaneously, nobody ever seems to have a straight answer; it's just whoever's left in the room when everyone else finds a reason to leave.
Build guardrails into the workflow itself
Written policies only go so far when employees are incentivized to move fast, and the tools themselves don't enforce any boundaries. Governance that travels with the workflow means the rules are in effect, whether or not anyone remembers to read the handbook. The goal is to give teams the freedom to use AI productively while the organization retains control over what those tools can access and act on.
A policy document doesn't stop an agent from doing something it shouldn't. Whatever model or agent your team is using, Zapier's AI Guardrails keep an eye on the workflow and flag if anything looks off.
The problem was never whether we should govern AI. It was always whether governance could keep up with the people deploying it. As AI agents take on more critical work across more connected systems, keeping governance enforcement on track requires more than a well-written policy. The organizations getting ahead of it have built oversight directly into how AI operates, how access gets managed, and how actions get tracked across every tool in the organization.
This is where Zapier comes in: it's the governed layer between AI agents and the apps they need to get work done. Because if governance only covers one model or one set of tools, it stops working the moment things get even a little messy.Â
Governance has to move with the work, across every agent, every app, and every team using them. Zapier handles authentication, permissions, and oversight across 9,000+ integrations, so IT retains visibility without slowing anyone down.
Methodology
The survey was conducted by Centiment for Zapier. The survey was fielded between May 7, 2026, and May 11, 2026. The results are based on 548 completed surveys. To qualify, respondents were screened to be U.S. directors, VPs, and C-suite executives at companies with 500 employees or more that use AI in core business workflows. Respondents have direct knowledge of their company's AI strategy and governance practices. Data is unweighted, and the margin of error is approximately ±4% for the overall sample with a 96% confidence level.









