The policy exists. The proof does not.
An Ernst and Young survey published this September found that ninety eight percent of surveyed organisations report having formal AI governance policies in place. The same survey found that forty seven percent admit their organisation has bypassed that process for urgent deployments. Nearly a third have already experienced an AI incident that caused material harm, and roughly a quarter cannot even detect when an unauthorised agent is operating inside their own environment.
This is not a story about organisations failing to think about governance. Most have thought about it carefully, written it down, and had it approved at a senior level. The failure sits somewhere else entirely. It sits in the space between what a policy says should happen and what can actually be proven to have happened when someone asks.