Measure Twice, Deploy Once
So there I was...
This morning I was reading an article at the kitchen table, coffee in hand, stealing thirty minutes before my wife and I got back to the big project in the backyard: a pergola we are building ourselves, which at this stage means post holes, bags of concrete, a string line, and a level we have learned not to argue with. The rule out there is older than both of us. You do not hang the roof until the posts are set, square, and plumb. Nobody debates this. The wood does not care about your schedule.
The article was a compliance news roundup from Corporate Compliance Insights, and two surveys in it kept pulling me back out to those post holes.
The first, from Smarsh and FTI Consulting, asked 114 decision-makers across US enterprise and public sectors about AI. More than half of them, 55 percent, are actively deploying AI systems right now. The number whose governance frameworks are fully aligned with what they deployed: 26 percent. Less than half of that. Fewer than half keep a centralized inventory of their AI agents, APIs, and integrations, which means the majority cannot tell you, on a given Tuesday, everything the machines are doing in their name. Jonathan Roberts of FTI Technology put the risk plainly: shadow IT, and with it growing exposure on data privacy, data protection, and governance itself.
The second survey, Onspring's 2026 benchmark of 126 governance, risk, and compliance practitioners, is the punchline to the first. Eighty-five percent of their companies have adopted AI. Fourteen percent have actually embedded it into their workflows. Seventeen percent can demonstrate a return on the investment, and 44 percent have seen no measurable return at all. Their top worries are the honest ones: data privacy and accuracy, and the machine's talent for confidently making things up.
Set those two studies side by side and you get a picture I recognize from every jobsite I have ever stood on. Everyone bought the lumber. Everyone is swinging a hammer. Very few people dug the holes first.
Here is the thing about our pergola. The post holes are the worst part of the whole build. They are slow, they are ugly, the Texas caliche fights you for every inch, and when you are done, all you have to show for a full day's work is four empty holes and a sore back. There is nothing to photograph. Nobody drives by and admires your holes. Every bit of the visible glory, the beams, the rafters, the shade, comes later and comes fast. And every bit of it stands or falls on the part nobody claps for.
Governance is post holes. An inventory of what your AI is actually doing is post holes. Deciding, before the tool ships, who checks its work and who answers for it, is post holes. The 55 percent deploying without alignment are hanging rafters on posts set in loose dirt, and the 44 percent seeing no return should not be surprised: a structure with no frame does not hold weight, and a tool with no discipline around it does not hold value. The companies in that 17 percent, I would bet, are not the ones with the fanciest models. They are the ones who did the boring digging first.
My wife and I could have skipped the footings. The pergola would have gone up in half the time, and it would have looked exactly as good in the photos, right up until the first real storm out of the hill country, which is not a hypothetical, it is a scheduled event. That is the trade every one of those surveyed companies is making this quarter, whether they have named it or not: speed you can see against strength you cannot, glory now against the storm later.
So here is my question for you this morning, from a man with concrete dust on his boots. Look at the thing your team is building right now, the one with the demo everyone loves. Do you know where its posts are?
And have you actually checked, with a level, that they are plumb, or does it just look straight from the street?
Source: News Roundup, Corporate Compliance Insights, July 8, 2026
#AI #AIGovernance #GRC #Compliance #RiskManagement #STIW