The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI that prepares board governance documentation, meeting minutes, and materials for regulatory examinations and audits. Includes automated minute generation and examination readiness assessment; distinct from compliance planning which manages ongoing compliance rather than preparing for specific governance events.
AI-driven governance documentation has become a regulatory mandate, not a competitive option. The defining shift in 2026: regulators moved from asking "do you disclose AI use?" to "can you prove it and reconstruct every decision?" This practice is production-grade and proven at scale—23% of U.S. banks now use AI for board minutes and meeting prep; nonprofit platforms are GA; 12-week implementation roadmaps and audit-ready templates exist. But adoption patterns remain structurally bifurcated, constrained by a critical governance design tension that has intensified mid-year. Efficiency gains remain real (50–90% time savings in meeting prep, 60% reduction for individual firms), and examination readiness has become a board mandate: auditors now arrive with AI-assisted tools to verify documentation completeness and policy-implementation alignment, shifting from paper compliance to continuous monitoring evidence. Yet the risks from governance documentation itself have crystallized: multiple simultaneous records (transcript, summary, draft, approved minutes, prompt history) invert traditional governance design—privilege waiver exposure, discoverability vulnerabilities, and spoliation duties now surface before any tool failure. Fiduciary law has also hardened: Delaware Caremark doctrine now explicitly covers board oversight of AI governance documentation practices, with personal director liability attaching to inadequate policies and controls. The practice maturity is high; but organizational readiness and governance-aware design (distinguishing between approved formal minutes and discoverable machine artifacts) remain the binding constraint, creating examination risk for firms that implement governance documentation without addressing the legal/discovery architecture.
Regulatory enforcement has hardened into examination requirements with specific documentation demands. The SEC's 2026 examination priorities embed AI oversight across all examinations—not as specialist topic but as core supervisory focus, now requesting three specific artifacts: written AI acceptable-use policy, per-tool vendor-oversight one-pagers, and human-review logs. Examiners shifted from "disclose" to "demonstrate": they demand system logs, audit trails, test results, and decision provenance documentation, not narrative policy. FINRA has designated generative AI a formal supervisory priority, requiring documented pre-deployment assessment, governance framework, testing records, and incident documentation as baseline examination expectations. Federal Reserve guidance (SR 26-2) replaced legacy risk management standards with explicit AI documentation and evidence requirements. Malta Financial Services Authority established AI governance as mandatory supervisory expectation: firms must demonstrate AI systems mapped, risks assessed, board engaged, gaps closed—or face supervisory findings. EU AI Act enforcement (August 2, 2026) requires unredacted access to systemic risk management frameworks within five business days and exhaustive "design history file" documentation (architecture, data provenance, evaluation results, monitoring with 10-year retention); non-compliance fines reach €35M or 7% global turnover. India's RBI FREE-AI framework (August 2025) shifted from voluntary guidance to supervisory expectation. The regulatory cliff is absolute: all major regulatory jurisdictions now require demonstrated governance evidence, not optional disclosure.
Examination readiness remains bifurcated by governance maturity. Schellman's August 2026 survey (525 enterprise leaders) reveals a critical perception-reality gap: 74% of enterprise leaders believe they could pass an AI compliance audit today, yet only 27% describe their governance as truly mature. The gap is operational: organizations have policies on paper but lack the continuous monitoring infrastructure and artifact-level evidence (audit logs, change records, test results) that examiners now demand. Financial services data sharpens the picture: Qapitol's survey of 50 banks finds only 31% report comprehensive governance frameworks, 87% remain below optimized maturity, and 38% score median readiness for EU AI Act enforcement. Shadow AI—unapproved AI systems embedded in third-party software or adopted without formal sign-off—remains the largest governance blind spot across regulated sectors. Decision-boundary documentation also emerges as a critical gap: while 84% of financial institutions have assigned an AI governance owner, 46% of those same organizations only partially understand what their AI systems are permitted to do, creating examination vulnerabilities around explicit prohibited-use documentation.
Vendor platforms have hardened into examination-ready tooling. Diligent's AI Board Member (GA June 2026) autonomously takes minutes, assigns action items, and generates board-ready risk governance with immutable audit trails aligned to examination standards. Diligent's Subsidiary Governance Agent prepares board packs, minutes, and approvals across dozens of entities; Enterprise Risk Governance Agent transforms risk signals into SEC-aligned disclosures. Board Intelligence delivers production minute-writing with explicit governance controls (human approval required, immutable records, version history); Cambridge Building Society reports 40% time savings. Swept's Compliance Trust Report generates examination-ready evidence packages mapped simultaneously to 10+ frameworks (ISO 42001, NIST AI RMF, EU AI Act), reducing audit prep from 12 hours to 2 hours for financial institutions. FairNow automates evidence collection for ISO 42001 compliance (named customers: Dayforce, Cielo). The Art of Service released OWASP-aligned CISO playbooks (April 2026) compressing 6–9 month governance assessments into 120–140 hours with control mappings to NIST AI RMF, ISO 42001, EU AI Act, and MITRE ATLAS. Governance documentation infrastructure has moved from bespoke consulting to productized frameworks and tooling, with 1M+ hours saved and 21K documents processed at scale in enterprise deployments. The emerging standard now requires operationalized governance—continuous auditable evidence through logs, change management, and monitoring—not periodic documentation assembly.
Deployment outcomes now prove governance documentation as enabler, not constraint. Unilever's OpenPages governance deployment reduced undetected model drift by 40%. Bradesco (Brazil's largest bank) deployed agentic AI with 100% audit trail documentation and 100% behavioral logging, achieving 83% resolution rates and 30% cost reduction—a reference architecture for governed agentic systems in regulated sectors. KPMG's financial services data shows organizations capable of producing audit evidence efficiently achieve 3–6× higher error reduction (33% vs 6%) and 3× higher scaling confidence (42% vs 14%). Governance documentation is no longer overhead; it's the infrastructure that enables production AI deployment at scale.
Adoption is bifurcated by an emerging governance design tension that inhibits regulated sectors. Early adopters (education, nonprofits, smaller boards, some financial institutions) scale with proven ROI and defined governance programs; 23% of U.S. banks now use AI for board meeting transcription and minutes preparation. Regulated sectors face simultaneous opposing mandates: examiners demand exhaustive documentation of AI decisions for regulatory compliance, while litigation holds impose discovery obligations that make AI-generated records (transcripts, summaries, drafts, prompt histories) legally discoverable and privilege-waivering. Delaware Caremark doctrine now explicitly covers board oversight of AI governance, establishing personal director liability before tool failure if policies and controls are inadequate. This legal architecture inverts traditional governance design: multiple simultaneous AI-generated records create legal risk even when technology functions perfectly. Only 21% of enterprises have mature governance models despite 85% planning autonomous agent deployment. Only 11–16% of boards report strong AI oversight. Only 16.9% have explicit governance measure owners; 91.4% have not updated plans in six months. The bottleneck has shifted from tool capability to governance-aware organizational design—distinguishing between approved formal minutes (privileged board record) and discoverable machine artifacts (litigation liability). 74% of enterprises with deployed AI agents rolled them back or shut them down entirely (Sinch survey, n=2,527); 81% among organizations with mature guardrails. Examination-readiness frameworks are now operationalized (230 control objectives in FS AI RMF), but structural legal and organizational tensions prevent mainstream adoption in risk-sensitive sectors despite vendor platform maturity and proven deployment in less-regulated segments (education, nonprofits, some financial services). The practice maturity is high; organizational and legal readiness remain constrained.
— Field research of 50 banks: only 31% report comprehensive governance, 87% below optimized maturity, 38% median EU AI Act readiness. Documents critical examination readiness gap in financial services; identifies shadow AI and third-party risk as primary blind spots.
— India's RBI FREE-AI framework (August 2025) shifting from voluntary guidance to supervisory expectation: 6 pillars, 26 recommendations. Documents shadow AI as largest governance blind spot; cross-jurisdictional penalty exposure stacking (EU €35M, GDPR €20M, DORA €5M).
— Identifies AI compliance as fundamentally a data governance problem: lineage traceability, quality standards, access controls, accountability ownership. Regulatory drivers: EU AI Act Article 12 requirements, NIST AI RMF, SEC interpretations demanding end-to-end data provenance documentation.
— Schellman 525-person survey: 74% of leaders believe audit-ready today, only 27% governance truly mature. Gap between perceived and actual maturity directly indicates examination-readiness problem: organizations believe policies suffice but lack operationalized governance capability.
— Critical gap analysis: 84% of financial institutions assigned AI owner, but 46% only partially understand their AI. Governance frameworks address accountability structures, not decision boundaries—the core examination failure pattern. Untested kill-switches and unclear prohibited-use lists signal systemic documentation gaps.
— August 2, 2026 enforcement date for high-risk system requirements: Article 11/Annex IV mandate exhaustive 'design history file' documentation (architecture, data provenance, evaluation results, monitoring). Non-compliance: €35M or 7% global revenue. Creates immediate examination-readiness driver.
— Framework synthesis across 4 operational layers (binding regulation, management systems, risk models, threat taxonomies). Cites HFS/Infosys: only 12% of enterprises have mature governance despite 40% of apps will include agents by 2026. Establishes governance infrastructure gap.
— German court decisions (May 2026) establish AI operators liable for system outputs; EU AI Act requires documented AI inventory, usage policies, and human oversight as legal mandates—translating governance documentation requirements into binding legal obligations.