Ethisphere and Ethena Research on Compliance Role in Mitigating AI Risk

Ethisphere and Ethena just released a research report that every compliance officer should read carefully, not because it breaks new ground on AI risk, but because it turns the mirror around and asks an uncomfortable question: if ethics and compliance is the function writing the rules for how everyone else uses AI, why is it the function using AI the least itself? The report, based on a survey of 134 ethics and compliance leaders conducted in June 2026, gives this phenomenon a name: the Cobbler’s Children problem. The shoemaker outfits the whole town while his own kids go barefoot.

The Headline Number: A 45.5-Point Gap

The central finding is stark. Sixty-seven percent of organizations surveyed report having reached broad or advanced AI adoption enterprise-wide. Only 22 percent say the same about their own ethics and compliance function. That is a 45.5 percentage point gap between how far the enterprise has moved on AI and how far the function governing that AI has moved on itself.

Break the distribution down further and the picture gets more pointed. Half of E&C teams describe themselves as sitting at “some approved use cases,” the middle of the maturity curve, and more than a quarter remain stuck at limited experimentation. Only 2 percent have reached advanced, governed use of AI within their own function. On the enterprise side, two-thirds of organizations have already moved past that midpoint. This is not a story of compliance dabbling cautiously while the business races ahead. It is a story of compliance functions that, in a meaningful number of cases, have barely started.

It Isn’t a Money Problem

The instinctive assumption is that compliance teams are under-resourced, and to some extent the data supports that: 84 percent of E&C teams report no dedicated AI budget line, and only 4.5 percent measure AI’s impact with any defined metric. But the report is explicit that money is not actually what is holding the function back. Eighty-six percent of teams already have access to enterprise tools like Microsoft Copilot through their organization’s broader licensing. The barrier isn’t access to a tool. It’s whether compliance officers trust the tool once they have it.

When asked directly what stands between their function and meaningful AI adoption, E&C leaders ranked accuracy and hallucination risk first, cited by 53 percent, and data exposure or confidentiality concerns second, at just under 48 percent. Combined, those two technology-trust concerns outrank every resourcing barrier in the survey put together. Budget constraints came in sixth, at under 24 percent. Resistance from leadership, the excuse many might expect to top the list, was cited by only 1.7 percent of respondents. The people best positioned to know exactly how AI fails, because identifying and mitigating those failure modes is their job for the rest of the organization, are precisely the people most reluctant to rely on it themselves.

Four Patterns Explain Where the Gap Is Concentrated

The report identifies four distinct structural patterns worth understanding.

The first is what the authors call the centralization paradox. Centralized global E&C teams are the most common structure in the survey, representing 44 percent of respondents, yet they show the lowest rate of broad or advanced AI adoption of any structure and the highest share stuck at limited or no use at all: only 16.9 percent have reached broad or advanced adoption, and 35.6 percent remain at limited experimentation or none. Hybrid programs that pair central strategy with regional execution do meaningfully better, reaching 25.6 percent broad or advanced adoption. The likely explanation isn’t structure itself but capacity: centralized teams carry global scope on a fixed headcount, leaving little slack to pilot new tools, while hybrid programs distribute that load and teams embedded within Legal appear to borrow capacity from adjacent legal operations functions.

The second is what the report calls the large-team ceiling. Bigger compliance teams might be expected to have more room to experiment, but the data shows the opposite. Fifty percent of teams with more than 100 people cite systems integration as their top barrier to AI adoption, more than double the overall rate, and none of those large teams measure AI’s impact with defined metrics at all. The likely culprit is the bureaucracy that comes with scale itself: more entrenched legacy systems, more layers of process, and more stakeholders required to sign off before any new tool goes live.

The third pattern is the mid-size anomaly, and it may be the sharpest illustration of the Cobbler’s Children problem in the entire dataset. Teams sized between 16 and 30 people sit inside organizations with some of the fastest enterprise AI adoption in the survey, with 79.2 percent working inside broad-or-advanced-AI organizations, well above the 67.2 percent overall average. Yet 87.5 percent of those same teams have no dedicated AI budget line for their own function. The appetite is clearly there, with 96 percent of these teams reporting their AI use increased over the past six months, but the operational discipline, budget, and measurement have not caught up to that appetite.

The fourth is the advanced-org gap, and it’s the most sobering finding for anyone hoping that enterprise AI maturity will simply pull compliance along with it over time. Among the 14 organizations rated as having advanced, governed, and fully integrated AI use across the enterprise, only 14.3 percent have an E&C function operating at that same strict level. Even inside the most AI-mature organizations in the entire sample, compliance adoption is closer to a coin flip than a guarantee. Move one tier down to organizations with broad, if not fully advanced, AI adoption, and the compliance adoption rate falls by more than half, to 23.7 percent. The gap does not close on its own as the enterprise matures. It widens.

Governance Is Ahead of Enablement

One of the more important nuances in the report is the distinction between governance maturity and adoption maturity, and they are not the same thing. Written AI use policies exist at 85.5 percent of organizations surveyed. Approved tool lists exist at 77.8 percent. Roughly 69 percent expect human review before AI-generated work gets used. Compliance functions have, in other words, done real institutional work writing the rules. What they have not done, in large numbers, is build the budget, tooling, and measurement discipline to actually use AI themselves under those same rules. Sixty-three percent of E&C leaders report having a formal role in enterprise AI governance. The function best positioned, by expertise, to close this gap is the same function that has, so far, put its own enablement last.

The Human Review Bottleneck and What Comes Next

The report raises an important forward-looking concern about the durability of blanket human review policies as AI capability shifts from assistive tools toward agentic systems capable of executing multi-step tasks with minimal human input. Currently, 71.4 percent of the most AI-advanced organizations in the survey require human review of every piece of AI-generated work before it is used, and 60.4 percent of the full sample does the same. That approach works cleanly for AI that drafts or summarizes. It becomes a serious bottleneck for agentic workflows, and 56 percent of respondents already rate workflow automation as a high-value AI use case for their function over the next year. The report’s recommendation is to move from a single, universal review requirement toward a risk-tiered model, treating low-risk, reversible tasks differently from high-risk matters tied to investigations, board members, or regulatory disclosures, which should retain mandatory review at every step.

A Practical Path Forward

The report closes with a sequenced action plan rather than a call to overhaul everything at once. In the near term, it recommends tackling the trust barriers directly, investing in vetted tools and clear data-handling guardrails rather than simply asking for more budget, auditing existing policies against how AI is actually being used today, and piloting AI within a single, contained, high-value workflow, an area where mid-sized teams in particular already show real momentum. Over the following two quarters, it recommends securing a dedicated AI budget line, defining a small number of concrete impact metrics, and auditing centralized team capacity rather than defaulting to a structural reorganization. Over the coming year, the recommendation is to move from blanket to risk-tiered human review and to build the business case for further investment using the metrics collected along the way.

Why This Matters

This report should reframe how compliance leaders think about their own AI posture. It is easy, and understandable, for a function whose job is to catalog the ways AI can go wrong to become its most cautious adopter. But that caution carries a real cost. Compliance teams spending their limited bandwidth on manual, repetitive review work, sorting through conflict-of-interest disclosures line by line, triaging hotline reports by hand, are not preserving rigor. They are simply falling further behind the rest of the organization they are supposed to be governing, while the actual risk they are worried about, inaccurate or unverified AI output making its way into a compliance decision, remains just as real whether or not the compliance function itself has built the expertise to manage it. The most credible path to trustworthy AI governance across an enterprise starts with the function writing the guardrails actually living inside them.

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *