75% of organizations report having AI usage policies.
Yet a cross-regulatory analysis of AI incidents found that 77.1% lacked evidence of EU AI Act post-market monitoring and 99.6% lacked documented impact assessment evidence.
That is where the real governance gap appears.
Most organizations are reasonably good at pre-deployment governance, but operational governance is different.
It means being able to prove that AI systems are monitored, escalated, corrected, and controlled while they are running.
Operational AI governance is what turns that assumption into control.
If you are preparing to move AI from experimentation into production, I break this down in my Pega Community blog post:
Before You Deploy AI: The Predictability Checklist You Need
Sources:
Gradient Flow 2025 AI Governance Survey reports that 75% of organizations have AI usage policies and fewer than half monitor production AI systems for accuracy, misuse, or drift. [ gradientflow.com]
EU AI Act Article 72requires providers of high-risk AI systems to establish and document post-market monitoring systems. [ai-act -ser…europa.eu]
NIST AI RMF MANAGE includes post-deployment monitoring, incident response, recovery, override/deactivation, and change management. [airc.nist.gov]
Post-Deployment Accountability in AI Governance reports the 77.1%, 99.6%, 87.5%, and 5.3% incident-analysis figures. [arxiv.org]
BCG “Where’s the Value in AI?” provides the closest support for the value-realization framing, with 22% generating some value and 4% creating substantial value. [bcg.com]