Someone still has to put their name behind the decision. That is easy to forget in the rush to bring artificial intelligence into governance, risk, and compliance. AI can collect information faster, summarize evidence, identify patterns, and accelerate work that once consumed hours, but when an assessment reaches an executive, an audit finding is challenged, or a risk decision turns out to be wrong, the explanation cannot simply be that the system produced it. A person is still accountable for what happens next.
That responsibility helps explain an apparent contradiction in the 2026 Onspring GRC Benchmarking Report. Interest in AI is widespread, yet only 13.5% of respondents said it had been embedded across their workflows. Most remain somewhere between experimentation and selective use. It would be easy to interpret that gap as evidence that GRC is simply moving slowly on AI. We think it points to something more consequential: AI is arriving inside governance environments that were not built for it and, in many cases, were never particularly well connected to begin with.
For years, those environments could still function. A risk team might keep one set of records while audit kept another. Evidence could live in one system, ownership in another, and the latest context somewhere in an email thread. A spreadsheet might bridge two processes that were never designed to speak to each other. Someone knew who to call when the formal process stalled. Someone remembered which document was current. Someone understood the exception that had never quite made it into the official procedure.
The work continued because people filled the gaps. What AI is beginning to reveal is how much of the apparent coherence of GRC may have depended on people doing exactly that.
AI is meeting the GRC environment that already exists
There is something familiar about the current moment. Early internet adoption was uneven too. Organizations experimented before they fully understood where the technology belonged, tools were awkward, use cases were inconsistent, and expectations often moved faster than the systems around them. AI is advancing far more quickly, but GRC appears to be experiencing a similar tension. Teams can demonstrate that AI works in an isolated task and still struggle to make it work across the wider function.
The distinction matters because the question is no longer simply whether an AI model can summarize a document, assist with evidence collection, or identify a pattern. Increasingly, the question is whether the information and processes surrounding that model are reliable enough for someone to act on what it produces. GRC carries years of accumulated structure. Risk, compliance, audit, security, legal, and procurement functions have often developed in response to different requirements, under different owners, using different systems. What looks from a distance like one governance environment can, up close, be a collection of processes held together by habit, institutional knowledge, and human effort.
AI inherits all of it. It inherits the evidence stored in one place and the ownership recorded somewhere else. It inherits the manual follow-ups, disconnected systems, inconsistent information, and processes whose written version may not completely resemble the way the work happens in practice. A model can perform exactly as intended within one part of that environment while the organization still struggles to connect its output to everything around it. This is one reason a successful pilot can remain just that: a successful pilot.
Seen this way, the adoption problem starts to look different. The technology may be new, but much of the friction surrounding it is not. AI has simply made that friction more difficult to absorb quietly because machines do not compensate for fragmented processes in quite the way people do. People improvise. They remember that the spreadsheet is more current than the official system. They know that a particular control operates differently in practice. They recognize that a colleague changed roles six months ago even though the ownership record was never updated. They understand which exception has become so routine that nobody calls it an exception anymore. Over time, this knowledge becomes part of how work gets done, and because the work continues to get done, the system itself can appear healthier than it really is.
That distinction matters well beyond AI. People can often navigate exceptions, inconsistent information, and processes that were never fully standardized. Their competence can make those systems work despite the gaps.
AI changes that equation. It can reduce manual work, but only when the underlying work and information are consistent enough to support it. What once looked like a technology problem can therefore reveal something more fundamental: a process that depended on people continuously making sense of its inconsistencies.
Trust does not begin with the technology
The Onspring research found that privacy and output accuracy remain the two most significant barriers to broader AI adoption. Those concerns are often framed as a question of whether practitioners trust AI, but in GRC, trust has never belonged to the tool alone.
Consider what happens when someone receives an AI-assisted risk assessment and asks a deceptively simple question: Why should we believe this? A credible answer depends on much more than the sophistication of the model. The practitioner needs confidence in the information the system received, where that information came from, whether it is current, who owns it, what may be missing, and whether the path from evidence to conclusion can be understood. If that conclusion later influences an audit, regulatory response, or leadership decision, someone may need to reconstruct that path long after the original assessment was made.
A sophisticated model sitting on top of unreliable information does not eliminate uncertainty. In some circumstances, it can make uncertainty harder to see because the output appears more coherent than the environment that produced it.
This is why we believe much of the current trust gap is organizational rather than purely technical. McKinsey’s 2026 research on AI trust points to a similar tension, finding that only about 30% of organizations surveyed had reached maturity level three or higher across AI strategy, governance, and agentic AI governance and controls. Technical capability is advancing quickly, but the structures required to govern its use are not necessarily developing at the same pace.
For GRC practitioners, that mismatch has a particularly human consequence. AI may assist with the work, but responsibility for the work does not transfer with it. The person reviewing the assessment, signing off on the finding, advising leadership, or explaining what went wrong remains accountable. Seen from that position, hesitation can look less like resistance to technology and more like a rational response to uncertainty in the environment around it.
The third-party risk findings illustrate this tension particularly well. Only 25.6% of respondents said they were very confident in their third-party risk management (TPRM) programs, while nearly 40% were unsure about AI’s role in TPRM. These findings raise the possibility that organizations may not always introduce AI where the underlying need is greatest, but where trust is easiest to establish.
Third-party risk would appear, at least in principle, to be well suited to AI assistance. It involves large volumes of information, recurring assessments, questionnaires, monitoring, and the difficult work of identifying meaningful signals among considerable noise. Yet these same characteristics make confidence in the underlying information especially important. The areas where AI could relieve significant pressure may therefore also be the areas where practitioners are least comfortable relying on it.
There is something worth learning from that hesitation. Experienced practitioners carry context that rarely fits neatly into a system. They know where information tends to break down, which exceptions matter, and when the official record does not tell the whole story.
That does not make human judgment infallible. But it can make caution reasonable. A practitioner may hesitate not because they distrust AI, but because experience has taught them how much sits outside what the technology can see. Before asking why that person does not trust the technology, it may be more revealing to ask what the environment has taught them not to trust.
What AI is really showing us
The same shift in perspective helps make sense of another finding in the report. Only 16.7% of respondents reported demonstrable financial returns from AI, even as organizations described improvements in efficiency, cycle times, and task throughput. If direct financial return is treated as the first proof of value, those numbers can look disappointing. But much of the cost of GRC has always been hidden in something less visible: time.
Consider evidence collection. A practitioner may spend hours locating documents, determining whether they are current, following up with owners, recording what has been received, and preparing it for someone else’s review. If AI meaningfully reduces that burden, the first thing returned to the organization is not necessarily money. It is attention.
The value of that recovered attention depends on what happens to it. It can simply be absorbed by another administrative task, or it can create more room for analysis, judgment, conversation, and the kinds of questions that routine work often leaves little time to ask. Financial return may eventually follow those operational improvements, but it is often a lagging consequence rather than the first visible result. The more useful question may therefore be not only how much work AI removes, but what people are able to notice once some of that work is gone.
This brings us to a larger point about AI governance itself. There is understandable pressure to create new policies, assign new responsibilities, establish inventories, and develop controls specifically for AI. Some of that work is necessary. But the current moment also invites a more uncomfortable question: what if the ability to govern AI depends, in part, on whether the governance surrounding it already works?
Connected information, clear ownership, documented controls, consistent evidence, accountable decisions, and the ability to explain how an important conclusion was reached are not new requirements created by generative AI. They are ordinary foundations of governance. Where those foundations are strong, AI governance has something to attach itself to. Where they are weak, AI encounters the same disconnected information, ambiguous ownership, and manual workarounds that people have quietly compensated for over the years.
That may be the deeper significance of the gap between AI enthusiasm and AI maturity in GRC. For years, people have carried context that systems could not. They have reconciled information that did not line up, remembered poorly documented exceptions, and kept processes moving despite the distance between how work was designed and how it actually happened. Because they carried that burden so routinely, it became easy to mistake their ability to keep the system functioning for evidence that the system itself was functioning well.
AI is making that distinction harder to ignore. It depends on information, ownership, and processes being coherent enough to act upon. Where they are not, weaknesses that people once absorbed quietly become visible constraints. What appears to be an AI readiness problem may therefore be something older: a governance problem that AI has made newly difficult to hide.
That changes the question worth asking. Instead of beginning with whether a GRC function is ready for AI, consider what AI would encounter if it had to rely on that function exactly as it exists today.
Where would it find the information it needs? Which record would it trust? Who actually owns the decision? Which exceptions exist only in someone’s memory? And how much of what appears to be a functioning process is functioning because someone, somewhere, knows how to work around it? Those questions existed before AI. We simply had people answering them. AI is giving us a reason to finally ask them.

