Start: Q3 2027
Publication: Q4 2027
Region: Global Research
Authors: Kevin Petrie, Timm Grosser
Enterprise AI is now embedded in business processes, but governance maturity still lags behind adoption. Many organizations have policies and human approval in place, yet enforcement, continuous monitoring, and automated response remain limited. Building on BARC’s The State of Data and AI Governance, this global follow-up study tracks how governance structures, responsibilities, technologies, and controls are developing over time. It examines how leaders translate policies into enforceable controls, where they automate governance, and how they connect CISO, CDO, CAIO, and architecture teams. The study adds a focused assessment of enterprise AI security, including identity and access, shadow AI, runtime protection, and incident response. Readers can benchmark their maturity, identify gaps between oversight and enforcement, and learn which practices help leaders govern and secure AI without slowing productive use.