The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI that maintains organisational risk registers and scans for emerging risks across regulatory, operational, and market domains. Includes automated risk identification and impact assessment; distinct from compliance gap analysis which measures against known requirements rather than scanning for emerging risks.
AI-driven risk register maintenance and horizon scanning has crossed from experimental to leading-edge deployment — but only at forward-leaning organisations with the governance infrastructure in place. The practice applies AI to continuously identify emerging threats across regulatory, operational, and market domains, going beyond compliance gap analysis by scanning for novel risks rather than measuring against known requirements. Regulatory adoption is now binding: the US government (NIST AI Risk Management Framework v1.0, effective June 2026) and EU (AI Act Article 9, effective August 2026) have made risk register maintenance and lifecycle monitoring core compliance obligations with significant penalties (EUR 35M or 7% global turnover for non-compliance). Vendor platforms offer production-grade tooling: Origami Risk, SAI360, LogicGate, and others compete on AI-powered risk identification and continuous monitoring. Board-level attention continues to surge: 48% of S&P 500 companies cite AI risk oversight, triple the 2024 rate. Market adoption accelerates: 75% of enterprises plan GRC budget increases with AI governance as the top priority (43%); the market for AI governance software is growing at 32.8% CAGR. Regulated insurance markets show mainstream adoption: Lloyd's Market Association survey of 39 CROs (60%+ of stamp capacity) shows 93% have AI governance frameworks in place or development, up from 25% a year prior. The defining tension remains organisational execution. Despite high regulatory pressure, critical gaps persist: only 38% of organisations have formal comprehensive AI policies; only 45% treat AI risk as immediate priority; 90% deploy AI but lack systematic governance; 80% deploying agents lack basic controls (decision boundaries, real-time monitoring, audit trails). Regulatory deadlines and escalating AI-related liabilities are compressing the timeline, but governance maturity has not kept pace with vendor capability or regulatory requirements. The shadow AI blind spot persists: 91% of enterprises don't fully understand their AI dependencies; 59% admit ungoverned shadow AI operates within their organisations.
Regulatory frameworks are now prescriptive and binding. NIST's AI Risk Management Framework v1.0 (June 2026) formalizes risk register maintenance as core lifecycle practice, requiring documented risk prioritization, response plans, and regular tracking of negative risks throughout AI deployment. The EU AI Act (Article 9, effective August 2026) mandates documented risk registers with likelihood, mitigation, and review records for high-risk AI systems; non-compliance carries penalties up to EUR 35M or 7% global turnover. These frameworks have shifted risk register maintenance from optional governance tool to compliance imperative, compressing organizational timelines. Yet adoption rates reveal persistent implementation gaps: ISACA's July 2026 "Taking the Pulse of AI" survey (3,400+ respondents) finds 90% of organisations deploy AI but only 38% have formal comprehensive AI policy; only 45% treat AI risk as immediate priority; 56% lack clarity on incident halt procedures. Deloitte's June 2026 enterprise AI survey (3,235 leaders) documents the agent governance gap: 74% expect agentic AI adoption by 2027, yet only 21% have mature governance models; 80% lack decision boundaries, real-time monitoring, and audit trails essential for risk register maintenance at operational speed. Cloud Security Alliance analysis identifies a secondary but material horizon scanning requirement: 91% of enterprises admit they don't fully understand their AI vendor dependencies; 81% would suffer critical disruption from a 7-day vendor outage; 51 AI service disruptions occurred in Q1 2026 vs. 6 in Q1 2025—showing that vendor concentration has become a critical operational risk requiring systematic monitoring and documentation.
Market momentum is unmistakable in Q2 2026. Optro's Q2 governance investment survey shows 75% of enterprises planning GRC budget increases, with AI governance solutions as the top investment priority (43%). The enterprise AI governance software market itself is growing at 32.8% CAGR, indicating mainstream infrastructure investment. Vendor tooling has matured rapidly: SAI360 launched GRC Elevate 6.0 in May 2026 with Regulatory Change Management monitoring 100+ jurisdictions and 2,000 publishers, plus Enhanced Risk Detection surfacing emerging risks and correlations—capabilities that compress manual work from months to days. Oracle, AppStream, and other platforms now incorporate risk register as a standard, GA module. Origami Risk's Spring 2026 AI Risk and Control Explorer further compresses risk register population. These are production deployments, not proofs-of-concept, but they remain concentrated among early movers and regulated firms.
In regulated insurance markets, adoption has become mainstream. Lloyd's Market Association survey of 39 chief risk officers (representing 60%+ of market stamp capacity) finds 93% have AI governance frameworks in place or in active development—a dramatic shift from 25% adoption one year prior. This market-wide deployment signals that boards and regulators are no longer treating AI risk register maintenance as optional. Regulatory convergence is formalizing: FDIC, FRB, OCC, NCUA, and the Treasury Department formally adopted the Financial Services AI Risk Management Framework in February 2026, documenting regulatory alignment on AI governance requirements. MOL Group's unified ERM platform deployment across 30 countries, integrating risk, security, and compliance with predictive analytics and real-time monitoring, demonstrates that multi-national enterprises are operationalising the practice at scale.
Yet critical execution gaps persist. VDF AI synthesis of 17 governance and compliance problems identifies missing central AI inventories, inconsistent risk-tiering, fragmented data lineage, weak post-deployment monitoring, and unclear second-line ownership—barriers that prevent most organizations from operationalizing risk registers effectively. A meta-analysis of 7 major reports (KPMG, Deloitte, McKinsey, Accenture, Stanford HAI, EY) finds convergence: "Technology is no longer the bottleneck; organization and governance are." Only 5% of enterprises successfully move AI from pilot to sustained production. Stanford's AI Index 2026 survey identifies security/risk concerns as the #1 blocker (62% of respondents) to scaling agentic AI—a 24-point margin over the next factor—with governance and data-layer control gaps cited as critical adoption barriers. Critically, 30% of organisations have experienced AI security incidents despite claiming governance awareness; only 22% have automated risk monitoring; two-thirds require weeks to implement policy changes. This execution gap persists even as boards demand oversight and regulators tighten deadlines: EU AI Act classification guidelines (August 2026 enforcement), Data Act (September 2026), Product Liability Directive (December 2026), and California AI risk assessment requirement (December 2027) all compress the timeline for governance maturity. Organisations recognise that AI risk belongs on their registers, but most have not yet built the operational muscle to maintain them continuously, hampered by data sovereignty concerns, inadequate third-party risk oversight, and the endemic problem of static, ownership-less spreadsheet registers.
— Kiteworks survey of 300+ security/compliance professionals: 80% experienced AI/security incidents; 65% discovered shadow AI; 70% in early-stage governance maturity (Tier 1-2). Documents widespread governance gaps and real incident evidence driving risk register and monitoring investment.
— StackAI benchmarking guide emphasizing governance as primary operational constraint. Core risk register themes: audit trails and monitoring as prerequisites for production; human-in-the-loop approvals for high-impact actions; versioning and release gates as load-bearing controls.
— Pathlock analysis of customer deployments: 23% experienced AI incidents; 79% lack dedicated governance teams; 52% cannot verify AI actions; 48% cannot trace activity end-to-end. Independent vendor data showing real-world incidents and control failures in deployed AI systems.
— Schellman audit firm survey: only 27% fully mature in AI governance; 94% operate under regulatory requirements but low readiness (29% EU AI Act, 12% APRA). Documents audit readiness failures and governance maturity gaps in regulated sectors.
— Aon (NYSE: AON) launches enterprise AI Risk Diagnostic tool aligned to ISO, EU AI Act, and NIST AI RMF; provides maturity assessment, governance gap analysis, and risk exposure mapping. Major vendor productizing AI risk assessment signals industry-wide shift to formal AI governance and risk register practices.
— Kyndryl survey of 1,100 senior leaders: only 27% maintain 'a registry and monitoring capabilities for all their AI systems,' directly quantifying a critical governance infrastructure gap. On-domain metric for risk register and AI system tracking adoption.
— Solytics comparative analysis of 12 AI risk management platforms; regulatory context (EU AI Act enforcement Aug 2, 7% revenue fines); real-world failures (Apple Card NYDFS, Epic Sepsis Model). Vendor ecosystem maturity and board-level adoption signal.
— Continuum GRC case study across 127 FedRAMP/CMMC 2.0 deployments: 41% remediation cost reduction and 47-day advance warning via predictive control monitoring. Demonstrates AI-driven horizon scanning for control degradation enabling proactive risk management.
2023-H1: Risk management automation gaining practitioner advocacy; Origami Risk and similar platforms demonstrating sustained enterprise adoption; horizon scanning identified as priority automation target but implementation barriers remain.
2023-H2: Enterprise risk platforms continue scaling (1,000+ accounts); industry research identifies lack of standardized AI risk assessment methodologies and governance integration frameworks as key adoption barriers; practitioner focus remains on implementation challenges rather than deployment success stories.
2024-Q1: GenAI governance concerns drive risk management interest; law firms like DWF deploy AI-powered horizon scanning for regulatory monitoring at scale; organizational preparedness gap widens, with only 25% of leaders feeling prepared for GenAI risk governance.
2024-Q2: Origami Risk launches AI Risk Identifier and Audit Accelerator tools; regulatory horizon scanning accelerates (EU AI Act passage, US roadmap, Seoul summit); ORX and Immuta surveys document emerging AI and cybersecurity risks; deployment remains concentrated among early movers, but one-third of risk professionals actively planning GenAI implementation.
2024-Q3: Regulatory bodies formalizing horizon scanning (EU EMA AI Observatory report documents first annual horizon scan); IEEE-SA standards work identifies AI safeguards through systematic risk horizon scanning; however, surveys show persistent adoption barriers—Deloitte finds data and risk management remain key constraints to scaling GenAI across 2,770 executives globally; Gartner forecasts 30% GenAI project abandonment by 2025 due to inadequate risk controls, signaling significant execution gaps in risk governance implementation.
2024-Q4: Analyst validation accelerates—Gartner Magic Quadrant recognizes Origami Risk with 50 carrier go-lives and 100+ new customers since 2022; regulatory adoption formalizes as Canadian OSFI reports AI use in financial institutions grew to 50% (from 30% in 2019); large enterprises adopt risk registers for AI—S&P 500 analysis finds 60%+ cite material AI risks; IEEE-SA p3395 standards work advances to Part III on technology horizon scanning. However, critical gaps persist: ISACA survey finds 70% of CISOs report existing tooling cannot detect security breaches effectively, indicating implementation challenges despite growing adoption momentum.
2025-Q1: Market maturation accelerates with ecosystem consolidation—comparative analyses identify 10+ leading automated risk assessment platforms; SANS Institute publishes risk-based AI security framework with six control categories, signaling standardization efforts; academic research (AGENTICS 2025) validates LLM-based risk scenario generation with human-in-the-loop methodology. Negative signals on implementation: 25% of AI spending in 2024 resulted in 'regrettable investments' with deployment failures, and standardized methodologies for ROI measurement remain nascent barriers to mainstream adoption.
2025-Q2: Adoption-governance gap widens as priority issue—EY survey finds 72% of executives have integrated/scaled AI but only 33% have proper governance controls; IDC data shows governance/risk management remains top AI adoption barrier. Vendor innovation accelerates: 4CRisk.ai announces horizon scanning tools with 20-40x speed claims, and academic research demonstrates 62% manual effort reduction in healthcare horizon scans. However, real-world risk penalties escalate (Air Canada chatbot liability, GDPR/NIS2 fines reaching $1-10M), and 90% of healthcare organizations report cyberattacks with 70% disrupting operations, highlighting hidden evaluation and maintenance burdens in automated systems. Shift in perception: AI increasingly viewed as risk multiplier requiring sophisticated governance, not pure productivity enabler.
2025-Q3: Enterprise risk governance frameworks mature—AWS publishes enterprise risk management guidance integrating GenAI risks; White & Case survey of 265 compliance professionals documents actual AI deployment patterns across compliance functions. Vendor momentum continues: Origami Risk launches new AI tools for rapid risk register creation and assessment. Horizon scanning automation gains traction: EU foresight project (FUTURINNOV) formalizes AI-enhanced horizon scanning methodology at scale. However, critical assessment remains: practitioners highlight persistent AI weaknesses in horizon scanning (hallucinations, source validation, need for human oversight) and widespread risk register failures in organizations (vague risks, lack of ownership, static processes). Evidence base reinforces: governance, standardization, and human-in-the-loop validation remain prerequisites for mature adoption.
2025-Q4: Board-level escalation and analyst validation converge—Gartner 2025 Magic Quadrant recognizes Origami Risk with new AI Risk and Control Explorer tool; 48% of S&P 500 companies now cite board oversight of AI risk (triple 2024 rate). Governance teams report escalating workload: OneTrust survey shows 37% increased time on AI risk, 75% find legacy governance insufficient. Verdantix confirms vendor maturity. Yet organizational maturity remains stubbornly lagged: practitioner analyses document endemic risk register failures (vague ownership, static processes, spreadsheet-reliance), with minority of ERM teams leveraging AI. The critical tension: rising board demand and analyst-validated vendor capabilities meet persistent organizational execution gaps, where risk registers fail operationally as strategic governance tools despite architectural recognition of the need.
2026-Jan: Risk management adoption accelerates—Moody's survey shows 53% of compliance professionals actively using or trialing AI (up from 30% in 2023), yet moderate impact and expertise barriers persist. Allianz Risk Barometer elevates AI to #2 business risk globally, signaling widespread organizational recognition of need for horizon scanning. Regulatory drivers intensify with California December 2027 deadline for AI risk assessments and NIST AI RMF adoption, shifting risk management from operational tool to compliance imperative. Execution gaps widen: organizational awareness and adoption intent rising, but majority lack governance processes and systematic approaches to operationalize risk registers.
2026-Feb: Vendor innovation accelerates with Origami Risk launching AI Risk and Control Explorer (Spring 2026), enabling rapid risk register population and continuous validation. Lloyd's Market survey confirms AI risk at #2 on corporate registers across insurance sector. Horizon platform demonstrates operational deployment: 1,300 employee interviews for Mercado Libre in 4 days (90x faster than traditional consulting). Industry surveys document AI as permanent fixture on risk registers but highlight persistent governance challenges: data sovereignty, third-party oversight gaps, and most registers remain static artifacts despite vendor platform maturity.
2026-Apr: GRC investment momentum is confirmed: Optro survey shows 75% of enterprises planning budget increases with AI governance solutions as the top priority (43%), while ORX documents horizon scanning methodology adoption across 47 leading financial institutions. A critical governance blind spot surfaces from ArmorCode's survey of 650+ security leaders: 86% claim complete AI inventory visibility yet 59% admit ungoverned shadow AI within their organisations — directly contradicting the premise of effective risk register maintenance. KPMG's global survey of 2,500 executives finds 74% confirm AI business value but only 24% achieve ROI, pointing to inadequate risk identification frameworks; McKinsey research confirms that mature governance is directly linked to business outcomes, with agentic AI triggering a redesign of oversight models toward continuous dynamic risk identification. Lloyd's Market Association survey of 39 CROs (60%+ of stamp capacity) finds 93% have AI governance frameworks in place or in active development — up from 25% a year prior — signalling that regulated insurance markets have moved to mainstream adoption. SAI360's AI-Connected Risk Register with KRI trend surfacing and incident pattern analysis demonstrates operational platform maturity. Execution gaps persist across the wider market: 30% of organisations have experienced AI security incidents despite claiming governance awareness, only 22% have automated risk monitoring, and Stanford's AI Index 2026 finds security/risk concerns are the #1 blocker (62%, 24-point margin) to scaling agentic AI. The enterprise AI governance software market's 32.8% CAGR reflects accelerating investment to close this gap.
2026-May: Governance demand escalates while execution readiness remains constrained. Horizon Search Institute (Georgetown/Northwestern/NYU) publishes a purpose-built horizon scan identifying the critical gap: agentic AI deployment outpacing governance maturity with only 33% of organisations at level 3+ controls. AICPA & CIMA survey of 1,735 executives (8 regions, 8 industries) documents sharp increase in board-level AI risk focus among AI-Transformed entities: 69% classify AI as a Top 10 risk (vs. 46% overall), 65% have board-level oversight (vs. 30% overall), yet only 24-27% report adequate talent, IT readiness, or regulatory preparedness. VDF AI synthesises 17 recurring governance implementation gaps: missing central inventories, inconsistent risk-tiering, fragmented data lineage, weak post-deployment monitoring, and unclear second-line ownership. Meta-analysis of 7 major reports (KPMG, Deloitte, McKinsey, Accenture, Stanford HAI, EY) confirms convergence: governance (not technology) is the bottleneck; only 5% of enterprises sustain AI from pilot to production. Vendor innovation accelerates: SAI360 launches GRC Elevate 6.0 with Regulatory Change Management (100+ jurisdictions, 2,000 publishers) and Enhanced Risk Detection for emerging risk correlation surfacing; Oracle confirms risk register as a GA module across enterprise platforms. KPMG's global survey of 2,110 C-suite leaders across 20 countries documents the shift from isolated AI use cases to coordinated enterprise capability, with governance and trust confirmed as prerequisites for scaling—directly framing risk register maintenance as foundational infrastructure rather than optional tooling.
2026-Jun: Horizon scanning automation demonstrates production-grade deployment at scale: UK Defence Science and Technology Laboratory's ML/LLM pipeline processes 300k+ articles monthly and improved analyst signal hit rate from 1% to 40%, winning a 2025 government innovation award. Stanford AI Index 2026 reports 74% of companies now cite AI inaccuracy as their top emerging risk—overtaking cybersecurity—sharpening the organizational urgency for continuous AI risk monitoring. LogicGate was named a Leader in the Forrester Wave Q2 2026 Governance Platforms with perfect scores on Technology Risk Management, with its agentic AI reducing GRC implementations from 30-150 days to days via natural language configuration. A Check Point survey of 1,042 professionals found 54% have confirmed AI-related security incidents but only 26% have enforcement architecture in place, quantifying the execution gap that risk register automation must close.
2026-Jul: Risk register maintenance shifts from governance best practice to binding legal obligation. The EU AI Act Article 9 (effective August 2, 2026) mandates documented risk registers with likelihood, mitigation, and review records for high-risk AI systems, with penalties up to EUR 35M or 7% global turnover for non-compliance; NIST's AI Risk Management Framework v1.0 (June 2026) formalizes risk register maintenance as a core Manage function with prescribed documentation, lifecycle monitoring, and regular tracking throughout AI deployment. Against this regulatory backdrop, adoption surveys reveal a critical execution deficit: ISACA's July 2026 survey of 3,400+ respondents finds 90% deploy AI but only 38% have formal comprehensive AI policy, 45% treat AI risk as an immediate priority, and 56% lack clarity on incident halt procedures. Deloitte's enterprise AI survey of 3,235 leaders across 24 countries confirms the agent governance gap: 74% expect agentic AI adoption by 2027, yet only 21% have mature governance models and 80% lack decision boundaries, real-time monitoring, and audit trails. A Cloud Security Alliance analysis adds a new horizon scanning demand: 91% of enterprises don't fully understand their AI vendor dependencies, 81% would suffer severe disruption from a 7-day vendor outage, and AI service disruptions ran at 51 incidents in Q1 2026 versus 6 in Q1 2025—making provider concentration an emerging operational risk requiring systematic register tracking. Governance-maturity economics get quantified: Qapitol's State of AI Assurance benchmark finds only 2% of organisations at optimized maturity against 73% still ad hoc, correlating with $35.3B in aggregate incident losses and 7.9x higher incident rates at the lowest maturity tier. A growing practitioner critique argues traditional risk registers structurally fail to capture AI-specific exposures because registers assume risks are event-shaped, owner-assignable, and assessable at a point in time—properties AI risks violate. Vendor and domain-specific tooling matures in parallel: SAI360 ships Elevate 6.0 with regulatory mapping across 100+ jurisdictions and emerging-risk correlation, OECD reviews 129 international horizon-scanning initiatives documenting institutional foresight capacity, and specialized supplier-risk and M&A risk-register automation report 35-70% efficiency and early-detection gains.
2026-Aug: Regulatory enforcement commences and governance gap evidence accelerates. EU AI Act Article 9 enters force August 2; NIST AI Risk Management Framework v1.0 becomes operational baseline. Enterprise adoption surveys confirm persistent governance-execution misalignment: Kyndryl (1,100 leaders) finds only 27% maintain registry and monitoring for all AI systems; Kiteworks (300+ security/compliance professionals) reports 80% experienced AI or security incidents, with 65% discovering shadow AI and 70% still at early-stage (Tier 1-2) governance maturity; Pathlock customer data shows 23% with confirmed AI incidents, yet 79% lack dedicated governance teams, 52% cannot verify AI actions, and 48% cannot trace AI activity end-to-end. Negative signal on deployment reliability: Renascence reports AI agent rollbacks outpacing deployments due to error rates and opaque decision-making. Vendor momentum continues: Aon launches AI Risk Diagnostic (aligning to ISO, EU AI Act, NIST), and Solytics Partners' comparative review of 12 AI risk management platforms cites named real-world failures (Apple Card NYDFS, Epic Sepsis Model) alongside EU AI Act enforcement exposure (7% global-revenue fines) as the market driver. Audit readiness metrics lag: Schellman finds only 27% fully mature, with 94% under regulatory requirements yet just 29% EU AI Act ready and 12% APRA ready. Governance remains the binding constraint: StackAI benchmarking shows audit trails and monitoring as load-bearing prerequisites for production deployment; Continuum GRC case study demonstrates predictive control monitoring enabling 47-day advance warning and 41% cost reduction. The defining tension sharpens: board and regulator pressure, vendor platform maturity, and binding legal deadlines clash with widespread organizational inability to implement systematic risk registers and horizon scanning at operational scale.