Perly Consulting │ Beck Eco

The State of Play

A living index of AI adoption across industries — where established practice meets the bleeding edge
UPDATED DAILY

The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.

The Daily Dispatch

A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.

AI Maturity by Domain

Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail

DOMAIN
BLEEDING EDGEESTABLISHED

Governance documentation & examination preparation

LEADING EDGE

TRAJECTORY

Stalled

AI that prepares board governance documentation, meeting minutes, and materials for regulatory examinations and audits. Includes automated minute generation and examination readiness assessment; distinct from compliance planning which manages ongoing compliance rather than preparing for specific governance events.

OVERVIEW

AI-driven governance documentation has become a regulatory mandate, not a competitive option. The defining shift in 2026: regulators moved from asking "do you disclose AI use?" to "can you prove it and reconstruct every decision?" This practice is production-grade and proven at scale—23% of U.S. banks now use AI for board minutes and meeting prep; nonprofit platforms are GA; 12-week implementation roadmaps and audit-ready templates exist. But adoption patterns remain structurally bifurcated, constrained by a critical governance design tension that has intensified mid-year. Efficiency gains remain real (50–90% time savings in meeting prep, 60% reduction for individual firms), and examination readiness has become a board mandate: auditors now arrive with AI-assisted tools to verify documentation completeness and policy-implementation alignment, shifting from paper compliance to continuous monitoring evidence. Yet the risks from governance documentation itself have crystallized: multiple simultaneous records (transcript, summary, draft, approved minutes, prompt history) invert traditional governance design—privilege waiver exposure, discoverability vulnerabilities, and spoliation duties now surface before any tool failure. Fiduciary law has also hardened: Delaware Caremark doctrine now explicitly covers board oversight of AI governance documentation practices, with personal director liability attaching to inadequate policies and controls. The practice maturity is high; but organizational readiness and governance-aware design (distinguishing between approved formal minutes and discoverable machine artifacts) remain the binding constraint, creating examination risk for firms that implement governance documentation without addressing the legal/discovery architecture.

CURRENT LANDSCAPE

Regulatory enforcement has hardened into examination requirements with specific documentation demands. The SEC's 2026 examination priorities embed AI oversight across all examinations—not as specialist topic but as core supervisory focus, now requesting three specific artifacts: written AI acceptable-use policy, per-tool vendor-oversight one-pagers, and human-review logs. Examiners shifted from "disclose" to "demonstrate": they demand system logs, audit trails, test results, and decision provenance documentation, not narrative policy. FINRA has designated generative AI a formal supervisory priority, requiring documented pre-deployment assessment, governance framework, testing records, and incident documentation as baseline examination expectations. Federal Reserve guidance (SR 26-2) replaced legacy risk management standards with explicit AI documentation and evidence requirements. Malta Financial Services Authority established AI governance as mandatory supervisory expectation: firms must demonstrate AI systems mapped, risks assessed, board engaged, gaps closed—or face supervisory findings. EU AI Act enforcement (August 2, 2026) requires unredacted access to systemic risk management frameworks within five business days and exhaustive "design history file" documentation (architecture, data provenance, evaluation results, monitoring with 10-year retention); non-compliance fines reach €35M or 7% global turnover. India's RBI FREE-AI framework (August 2025) shifted from voluntary guidance to supervisory expectation. The regulatory cliff is absolute: all major regulatory jurisdictions now require demonstrated governance evidence, not optional disclosure.

Examination readiness remains bifurcated by governance maturity. Schellman's August 2026 survey (525 enterprise leaders) reveals a critical perception-reality gap: 74% of enterprise leaders believe they could pass an AI compliance audit today, yet only 27% describe their governance as truly mature. The gap is operational: organizations have policies on paper but lack the continuous monitoring infrastructure and artifact-level evidence (audit logs, change records, test results) that examiners now demand. Financial services data sharpens the picture: Qapitol's survey of 50 banks finds only 31% report comprehensive governance frameworks, 87% remain below optimized maturity, and 38% score median readiness for EU AI Act enforcement. Shadow AI—unapproved AI systems embedded in third-party software or adopted without formal sign-off—remains the largest governance blind spot across regulated sectors. Decision-boundary documentation also emerges as a critical gap: while 84% of financial institutions have assigned an AI governance owner, 46% of those same organizations only partially understand what their AI systems are permitted to do, creating examination vulnerabilities around explicit prohibited-use documentation.

Vendor platforms have hardened into examination-ready tooling. Diligent's AI Board Member (GA June 2026) autonomously takes minutes, assigns action items, and generates board-ready risk governance with immutable audit trails aligned to examination standards. Diligent's Subsidiary Governance Agent prepares board packs, minutes, and approvals across dozens of entities; Enterprise Risk Governance Agent transforms risk signals into SEC-aligned disclosures. Board Intelligence delivers production minute-writing with explicit governance controls (human approval required, immutable records, version history); Cambridge Building Society reports 40% time savings. Swept's Compliance Trust Report generates examination-ready evidence packages mapped simultaneously to 10+ frameworks (ISO 42001, NIST AI RMF, EU AI Act), reducing audit prep from 12 hours to 2 hours for financial institutions. FairNow automates evidence collection for ISO 42001 compliance (named customers: Dayforce, Cielo). The Art of Service released OWASP-aligned CISO playbooks (April 2026) compressing 6–9 month governance assessments into 120–140 hours with control mappings to NIST AI RMF, ISO 42001, EU AI Act, and MITRE ATLAS. Governance documentation infrastructure has moved from bespoke consulting to productized frameworks and tooling, with 1M+ hours saved and 21K documents processed at scale in enterprise deployments. The emerging standard now requires operationalized governance—continuous auditable evidence through logs, change management, and monitoring—not periodic documentation assembly.

Deployment outcomes now prove governance documentation as enabler, not constraint. Unilever's OpenPages governance deployment reduced undetected model drift by 40%. Bradesco (Brazil's largest bank) deployed agentic AI with 100% audit trail documentation and 100% behavioral logging, achieving 83% resolution rates and 30% cost reduction—a reference architecture for governed agentic systems in regulated sectors. KPMG's financial services data shows organizations capable of producing audit evidence efficiently achieve 3–6× higher error reduction (33% vs 6%) and 3× higher scaling confidence (42% vs 14%). Governance documentation is no longer overhead; it's the infrastructure that enables production AI deployment at scale.

Adoption is bifurcated by an emerging governance design tension that inhibits regulated sectors. Early adopters (education, nonprofits, smaller boards, some financial institutions) scale with proven ROI and defined governance programs; 23% of U.S. banks now use AI for board meeting transcription and minutes preparation. Regulated sectors face simultaneous opposing mandates: examiners demand exhaustive documentation of AI decisions for regulatory compliance, while litigation holds impose discovery obligations that make AI-generated records (transcripts, summaries, drafts, prompt histories) legally discoverable and privilege-waivering. Delaware Caremark doctrine now explicitly covers board oversight of AI governance, establishing personal director liability before tool failure if policies and controls are inadequate. This legal architecture inverts traditional governance design: multiple simultaneous AI-generated records create legal risk even when technology functions perfectly. Only 21% of enterprises have mature governance models despite 85% planning autonomous agent deployment. Only 11–16% of boards report strong AI oversight. Only 16.9% have explicit governance measure owners; 91.4% have not updated plans in six months. The bottleneck has shifted from tool capability to governance-aware organizational design—distinguishing between approved formal minutes (privileged board record) and discoverable machine artifacts (litigation liability). 74% of enterprises with deployed AI agents rolled them back or shut them down entirely (Sinch survey, n=2,527); 81% among organizations with mature guardrails. Examination-readiness frameworks are now operationalized (230 control objectives in FS AI RMF), but structural legal and organizational tensions prevent mainstream adoption in risk-sensitive sectors despite vendor platform maturity and proven deployment in less-regulated segments (education, nonprofits, some financial services). The practice maturity is high; organizational and legal readiness remain constrained.

TIER HISTORY

ResearchJun-2023 → Jul-2023
Bleeding EdgeJul-2023 → Jan-2026
Leading EdgeJan-2026 → present

EVIDENCE (122)

The State of AI Governance in BFSI 2026Adoption Metrics

— Field research of 50 banks: only 31% report comprehensive governance, 87% below optimized maturity, 38% median EU AI Act readiness. Documents critical examination readiness gap in financial services; identifies shadow AI and third-party risk as primary blind spots.

— India's RBI FREE-AI framework (August 2025) shifting from voluntary guidance to supervisory expectation: 6 pillars, 26 recommendations. Documents shadow AI as largest governance blind spot; cross-jurisdictional penalty exposure stacking (EU €35M, GDPR €20M, DORA €5M).

— Identifies AI compliance as fundamentally a data governance problem: lineage traceability, quality standards, access controls, accountability ownership. Regulatory drivers: EU AI Act Article 12 requirements, NIST AI RMF, SEC interpretations demanding end-to-end data provenance documentation.

— Schellman 525-person survey: 74% of leaders believe audit-ready today, only 27% governance truly mature. Gap between perceived and actual maturity directly indicates examination-readiness problem: organizations believe policies suffice but lack operationalized governance capability.

— Critical gap analysis: 84% of financial institutions assigned AI owner, but 46% only partially understand their AI. Governance frameworks address accountability structures, not decision boundaries—the core examination failure pattern. Untested kill-switches and unclear prohibited-use lists signal systemic documentation gaps.

— August 2, 2026 enforcement date for high-risk system requirements: Article 11/Annex IV mandate exhaustive 'design history file' documentation (architecture, data provenance, evaluation results, monitoring). Non-compliance: €35M or 7% global revenue. Creates immediate examination-readiness driver.

— Framework synthesis across 4 operational layers (binding regulation, management systems, risk models, threat taxonomies). Cites HFS/Infosys: only 12% of enterprises have mature governance despite 40% of apps will include agents by 2026. Establishes governance infrastructure gap.

— German court decisions (May 2026) establish AI operators liable for system outputs; EU AI Act requires documented AI inventory, usage policies, and human oversight as legal mandates—translating governance documentation requirements into binding legal obligations.

HISTORY

  • 2023-H1: Research datasets (DumSum) and vendor tooling (ChatGPT-based) both demonstrate technical feasibility of automated minuting. Skepticism about accuracy and context-handling identified as the primary adoption barrier for regulated organizations.
  • 2023-H2: Named production deployment at Pennsylvania Chamber of Business and Industry validates real-world adoption. Practitioner concerns about legal liability, context understanding, and privacy risks documented—adoption slowed by risk tolerance, not technical capability.
  • 2024-Q1: Major governance platforms (BoardEffect/Diligent, Govrn) ship AI-powered summarization and minute generation as core features. Board-level surveys reveal persistent adoption barriers: 73% cite security concerns, 65% report integration challenges with legacy systems. Frameworks for audit-ready AI systems emerge, emphasizing validation and documentation traceability as prerequisites for regulated deployment.
  • 2024-Q2: Diligent expands AI suite with Minutes AI Assistant, regulatory mapping, and strategic insight capabilities; market research quantifies 28–35% efficiency gains in transcription and minutes automation. Education sector adopts at scale. Law firm analysis documents specific legal risks (litigation discovery, privilege violations, bias) reinforcing cautious deployment patterns in regulated sectors.
  • 2024-Q3: Forrester TEI study quantifies Diligent Boards deployment outcomes: 50–60% time savings for paralegals, $167k IT cost reduction, $22k risk mitigation. However, adoption barriers remain structural: law firm analysis identifies accuracy and privilege risks; TDWI survey shows governance readiness critically low (only 20% have solid programs); Gartner predicts 30% of GenAI projects abandoned by end of 2025; 90% of AI initiatives fail to deliver ROI. Adoption ceiling determined by organizational maturity and risk tolerance, not vendor capability.
  • 2024-Q4: Niche products reach GA (AGB OnBoard Automated Minutes for higher ed). Independent consulting firm (INVENSITY) validates Copilot in Teams: 98% transcription accuracy, 70-90% time savings. Governance profession adoption remains cautious (~30% use AI tools, 55% no plans). Critical risk analysis (Our Cat Herder) documents specific legal and operational blockers (speaker ID failures, discovery vulnerabilities, privilege loss). Adoption consolidating in early-adopter segments (education, smaller boards) while regulated sectors remain hesitant due to legal liability concerns.
  • 2025-Q1: Vendor platform consolidation accelerates: Diligent reaches 58% of Fortune 1000 and 75% of Fortune 500 with AI-enabled board meeting automation. However, adoption barriers persist: UK survey of 70 leading companies shows 92% had not adopted AI for minutes; law firm guidance emphasizes legal liability risks under Business Judgment Rule and privilege exposure. W3C standards body debates AI for meeting minutes, citing accuracy and privacy concerns. Market remains bifurcated: early-adopter segments (education, smaller boards) scaling, while regulated sectors hesitate due to liability and governance maturity gaps.
  • 2025-Q2: Vendor metrics mature further: Diligent reports 1,800 hours saved in board materials compilation and 80% reduction in meeting prep time with $187K ROI; Govrn continues platform expansion. Critical legal analysis from top law firms (Debevoise & Plimpton, Australian joint guidance from AICD/Governance Institute) documents persistent risks: accuracy failures, privilege erosion, dual-record legal exposure, and audit complications. Adoption barriers remain structural; practitioner analysis reinforces that AI over-documentation creates legal liability constraining board discussion. Market bifurcation continues: education and smaller boards advancing, regulated sectors held back by legal liability concerns and governance readiness gaps.
  • 2025-Q3: Diligent announces incremental feature expansion: Smart Builder for AI-driven document creation with multilingual templates, Smart Risk Scanner for automated risk identification in board materials. Law firm guidance (Institute of Directors New Zealand, Bennett Jones LLP) reiterates legal risks of AI notetaking: confidentiality, privilege exposure, data governance concerns, and accuracy limitations. Adoption patterns unchanged: early-adopter segments (education, smaller boards) advancing with production deployments and efficiency gains (1,800+ hours saved, 70-90% time savings); regulated sectors remain hesitant due to legal liability concerns and governance maturity gaps. Technology is proven; adoption barriers are organizational and legal, not technical.
  • 2025-Q4: New entrants in governance automation: FairNow platform for ISO 42001 compliance evidence collection (named customers Dayforce, Cielo); aigovernancetoolkit.com productizing board-ready governance documentation for Fortune 500 clients. Vendor ecosystem expansion with 25,000+ Diligent customers (third-party review, December 2025) confirms sustained adoption. However, regulatory barriers harden: Birmingham, Michigan city government explicitly rejects AI for official meeting minutes (December 2025) due to Open Meetings Act and Robert's Rules of Order compliance concerns—signals real-world regulatory rejection, not just cautious hesitation. Governance maturity data shows persistent adoption ceiling: 78% of orgs use AI but only 25% have implemented governance programs; 60-75% have policies but only 2% meet gold-standard maturity. Bifurcation accelerates: early-adopter segments (education, smaller boards) scaling with proven ROI (80% time savings, $187K over 3 years); regulated sectors face mounting legal liability, regulatory, and governance readiness barriers.
  • 2026-Jan: Global AI regulation enters enforcement phase: OneTrust reports AI regulation moved from planning to enforcement, requiring organizations to produce inventories, impact assessments, and regulatory evidence—governance documentation demand accelerates. However, governance maturity crisis persists: Deloitte survey of 3,200+ leaders shows only 21% have mature governance models; GhostDrift research identifies the Documentation Paradox where excessive documentation obscures accountability. Vendor platform evolution continues: Diligent announces AI Request Agent for Internal Audit (automating evidence collection) and enhanced Smart Minutes for examination readiness. Market bifurcation unchanged: governance documentation commodified for early adopters; regulated sectors constrained by legal liability and governance maturity gaps.
  • 2026-Feb: Regulatory examination focus sharpens: SEC 2026 priorities elevate AI oversight to all examinations; FINRA designates generative AI as formal supervisory priority. Named production deployments expand (Board Intelligence, ON Semiconductor using AI for financial filing drafts, HPE piloting LLM for SEC documents). Vendor ecosystem continues maturity trajectory (Diligent updates, BoardBreeze affordability positioning). However, structural barriers persist: Global Board Institute survey reveals 66% of directors lack AI knowledge despite 76% citing AI as strategic priority—governance documentation maturity gap drives examination readiness challenges. Legal profession reinforces risks (discoverability, hallucination, privilege loss). Governance documentation has shifted from optional automation to mandatory examination evidence requirement, but knowledge and maturity gaps constrain deployment in regulated sectors.
  • 2026-Apr: Examination readiness documentation frameworks hardened into practitioner standards: regulator-tested checklists now map six core examination domains (board oversight, model inventory, pre-deployment review, monitoring, vendor oversight, consumer protection) with specific evidence requirements, and the SEC examination shift from "disclose" to "demonstrate" is now codified in practitioner guidance requiring organisations to reconstruct AI decision-making with auditable evidence. Bradesco's agentic governance case study (83% resolution rate, 100% audit trail, governance-as-code) and Unilever's OpenPages deployment (40% drift reduction) represent production reference architectures for examination-ready governance in regulated entities. Commercial tooling for examination preparation commodified further: OWASP-aligned CISO playbooks (cross-mapped to NIST, ISO 42001, EU AI Act, MITRE ATLAS) compress 30-question governance assessments and evidence collection runbooks into structured audit-preparation packages, while board governance platforms (Board Intelligence, Diligent Elevate) advanced minute-writing and risk documentation with human-in-the-loop controls—signalling that examination-ready governance documentation is moving from bespoke consulting to productised tooling.
  • 2026-May: Regulatory enforcement against governance documentation gaps entered active phase, with multiple converging signals. FINRA's 2026 baseline codifies pre-deployment assessment, governance framework documentation, testing records, and incident documentation as mandatory examination requirements; Caremark duty-of-oversight liability is now explicitly extended to AI documentation gaps by legal analysts. Sinch research (n=2,527) finds 74% enterprise rollback of live AI agents — 81% among mature-governance organizations — establishing governance documentation as operational evidence, not just regulatory overhead. A named 650-employee financial services firm completed EU AI Act conformity in six months via shadow audit of 47 AI tools and a 5-day fast-track approval process, providing a reference architecture for examination-ready governance at mid-market scale.
  • 2026-Jun: With the EU AI Act's August 2 enforcement deadline 60 days out, examination-readiness frameworks converged across jurisdictions: GPAI documentation requires 10-year retention; FS AI RMF specifies 230 control objectives with examiners demanding logs, audit trails, and test records rather than narrative policy. Oxford Law's TRACE Model articulated director examination liability across five documentation dimensions (transparency, risk, audit trail, competence, ethics), and Diligent's AI Board Member GA (immutable audit logs, agentic GRC workforce) further productised the infrastructure. The governance maturity gap remains the binding constraint: only 21% of enterprises using agentic AI are governance-ready despite 69% deployment, with KPMG data showing organizations capable of producing audit evidence efficiently achieve 3–6× better error reduction.
  • 2026-Jul: Fiduciary liability frameworks for AI governance documentation hardened further: Caremark legal consensus now quantifies the gap as 83% of S&P 500 disclosing AI as material risk versus only 2.7% of directors with disclosed AI expertise, and Delaware case law confirms that CEO chatbot strategy discussions are discoverable as evidence — establishing governance design failures as legal exposure before any tool failure. Examination-specific tooling continued to mature: Swept's Compliance Trust Report generates multi-framework evidence packages (ISO 42001, NIST AI RMF, EU AI Act) from governance activity, the SEC codified three specific examination artifact categories (AI policy, vendor oversight one-pagers, human-review logs) for RIAs, and the MFSA established mandatory board-level AI mapping and gap-closure as supervisory expectations. Diligent's production deployment metrics (1M+ hours saved, 21K documents summarized in under a year) confirm enterprise-scale governance documentation infrastructure is operational. Late-month evidence sharpened the legal-liability dimension of AI-generated governance records: German court decisions established AI-operator liability for system outputs, and Columbia Law identified a documentation paradox where AI-generated board materials create privilege-waiver and discoverability exposure even as they satisfy record-keeping duties. A Grant Thornton survey of 950 C-suite leaders found 78% could not pass an AI governance audit within 90 days, and auditors increasingly expect continuous, time-stamped monitoring evidence rather than assembled documentation — reinforcing the maturity gap between regulatory expectation and organizational readiness.
  • 2026-Aug: Ahead of the EU AI Act's August 2 enforcement deadline for high-risk systems (design-history-file documentation, €35M/7% revenue penalties), multiple surveys sharpened the perception-reality governance gap: Schellman's 525-leader survey found 74% believe they could pass an AI audit today versus only 27% with genuinely mature governance, and Qapitol's 50-bank study found only 31% report comprehensive frameworks (87% below optimized maturity, 38% median EU AI Act readiness). FSB and industry analysis converged on decision-boundary documentation as the emerging blind spot — 84% of financial institutions have assigned an AI owner but 46% only partially understand what their systems are permitted to do — while framework synthesis found only 12% of enterprises have mature agentic-AI governance despite 40% of applications expected to include agents by year-end.