AI has yet to reach full adoption across most GRC teams, report finds
What you'll learn:
- Most GRC teams are still in the early stages of AI adoption.
- Data privacy and AI accuracy/hallucinations are the top barriers to adoption, reflecting concerns that flawed AI outputs could create compliance, audit and risk management issues.
- About 70% of practitioners believe AI's biggest impact will be automating these administrative tasks so teams can focus more on analysis, risk evaluation, and decision-making.
Nearly half of governance, risk management and compliance teams are still experimenting with AI while only 13.5% said the technology is embedded across their workflows, according to a recent survey.
This new report from Onspring, provider of integrated GRC software, revealed that 44.4% of respondents said AI is still in the experimental or pilot phase at their organizations while 25.4% said it's being used for specific tasks. Another 16.7% said AI isn’t in use at their organizations at all.
See also: Industrial AI has transitioned to the ‘application phase’
The 2026 GRC Benchmarking Study is based on survey responses from 126 GRC practitioners in North America this March and April. Respondents included IT staff, risk and compliance, finance, operations and legal counsel functions, and they varied in the seniority level from managers, to VPs or C-suite executives to director-level positions.
“These findings suggest that many GRC functions are beyond initial awareness but have not yet reached broad operational use. AI is being evaluated, tested and applied in targeted areas, but most organizations have not fully connected it to the workflows that define day-to-day GRC execution,” the report reads.
Poll: Pressure high
on CIOs to adopt AI
Pressure to effectively adopt AI is particularly intense on chief information officers, according to another recent survey.
A recent Dataiku/Harris Poll showed almost three quarters—71%—of CIOs said their roles are at risk if their companies fail to deliver measurable business gains from AI within the next two years.
About 62% of CIOs also said they have faced challenges from their CEOs over vendor selection, according to the report. Harris conducted a survey of 600 CIOs globally on behalf of Dataiku, the technology vendor that commissioned the report.
The survey also revealed that 85% of IT leaders say traceability and explainability gaps have delayed or stopped AI projects from reaching production or "scale."
"The honeymoon is over,” the Harris Poll said as CIOs admit struggle after years of experimentation with and investment in AI.
Added Florian Douetteau, co-founder and CEO of Dataiku, vendor of software for data science, analytics, and AI: “CIOs are moving from experimentation into accountability faster than most organizations expected.”
According to Onspring, this gap matters because CISOs and CIOs also are being asked to prove the value of security, risk, and compliance programs in business terms, even as they manage the threats themselves.
While GRC practices are valuable, it can be difficult to put a clear price on its value. AI can potentially help this, according to Onspring, by reducing the manual work that burdens GRC teams and giving leaders clearer ways to show what their programs are accomplishing.
In terms of concerns limiting AI adoption, respondents identified data privacy and accuracy/hallucinations as the top concerns at 28.6% and 25.4%, respectively.
These concerns reflect the reality of GRC workflows. Practitioners are responsible for information that must be accurate and documented, and an imperfect AI output can create opportunities for compliance risk, misstate exposure, weaken audit readiness or cause leadership to make decisions based on incomplete information, according to Onspring.
Onspring suggested that, because GRC workflows require the exchange of sensitive information, organizations need confidence that AI-enabled processes will protect that information and support access controls.
Onspring suggested that GRC teams face specific barriers when it comes to adoption. For example, GRC functions operate within complex requirements—such as different industry frameworks and mixed compliance environments—which can be difficult to manage when repetitive work depends on fragmented systems and manual follow-up.
See also: Manufacturers should price AI by considering ‘outcome economy,’ expert argues
“The survey findings show that GRC practitioners are still spending a significant amount of time on necessary, but highly repetitive, manual work. Respondents identified evidence collection and documentation as the most time-consuming activity, representing 25.9% of selections. Risk assessments followed at 19.8%, while third-party reviews accounted for 16.5%,” according to the study documentation.
This work creates a need for “operational relief,” Onspring argues, with workflows that reduce repetition, make information accessible and create more time for analysis and related insights, with centralized systems that allow practitioners to reuse evidence without repeatedly requesting the same information.
The survey findings show that GRC practitioners are still spending a significant amount of time on necessary, but highly repetitive, manual work.
Respondents reflected this as well, with nearly 70% saying AI would have the greatest impact on simplifying repeatable, administrative GRC operations.
“AI’s near-term value in GRC may come from helping practitioners perform these repetitive tasks more efficiently. That could include summarizing information, identifying missing documentation, helping prioritize follow-up, surfacing patterns or improving the flow of routine tasks. The common thread is time. If AI can reduce the administrative lift around GRC work, practitioners can spend more time interpreting findings, assessing risk and supporting better decisions,” the report reads.
See also: Successful AI products win long after the sales contract is signed
In terms of what GRC teams need from their AI moving forward for effective, meaningful adoption, Onspring listed five areas of focus:
- Reduce manual burden where it’s most visible: Start with repeatable GRC operations that consume the most time, including documentation, risk assessments and third-party reviews.
- Build trust before expanding AI across workflows: Privacy, accuracy and audit defensibility should shape how AI is introduced, reviewed and scaled.
- Connect systems before expecting stronger ROI: AI ROI will be limited if data, tasks and ownership remain fragmented.
- Treat third-party risk as an ongoing process: Continuous monitoring, follow-up and accountability need stronger operational support, not just point-in-time questionnaires.
- Measure AI value through practical GRC outcomes: Reduced cycle times, higher throughput and improved decision-making may be the strongest early indicators of AI value.
About the Author
Sarah Mattalian
Staff Writer
Sarah Mattalian is a Chicago-based journalist writing for Smart Industry and Automation World, two brands of Endeavor Business Media, covering industry trends and manufacturing technology. In 2025, she graduated with a master's degree in journalism from Northwestern University's Medill School of Journalism, specializing in health, environment and science reporting. She does freelance work as well, covering public health and the environment in Chicagoland and in the Midwest. Her work has appeared in Inside Climate News, Inside Washington Publishers, NBC4 in Washington, D.C., The Durango Herald and North Jersey Daily News. She has a translation certificate in Spanish.

