Drata released new research examining the State of GRC (Governance, Risk, and Compliance) in the Age of AI. The study reveals a widening gap between rapid AI adoption across enterprises and the governance, visibility, and accountability mechanisms needed to manage it effectively.
What is GRC in the Age of AI for those who don’t know? GRC refers to the integrated processes, policies, and technologies organizations use to manage governance, risk, and compliance. In the context of AI, it involves establishing oversight, risk assessment, auditability, and accountability for AI systems to ensure they operate within legal, ethical, and organizational boundaries.
The findings show that while AI has moved quickly into production environments, most GRC professionals lack full confidence in their ability to see, control, and govern these systems. Only 13% report complete confidence in AI visibility, highlighting a critical challenge as organizations scale AI initiatives. The report emphasizes that accountability has become the central demand from GRC teams navigating the AI era.
This research comes at a pivotal moment when AI is reshaping business operations faster than traditional GRC frameworks can adapt. Drata’s study provides insights into current pain points, maturity levels, and the growing need for purpose-built tools and processes to bring AI under effective governance. It positions accountability as the key requirement for GRC teams seeking to balance innovation with risk management in the age of AI.
Key Findings
Drata’s State of GRC in the Age of AI research reveals a significant visibility gap, with only 13% of GRC professionals expressing full confidence in their organization’s ability to see and control AI systems and initiatives.
AI adoption is accelerating rapidly across enterprises, but governance, risk, and compliance practices have not kept pace, creating growing challenges around accountability and oversight.
Most GRC teams report limited visibility into where AI is being used, what data it accesses, and how decisions are being made, increasing potential risk exposure.
Accountability has emerged as the top priority for GRC professionals navigating the AI era, with many demanding clearer ownership, auditability, and control mechanisms for AI systems.
The report highlights that traditional GRC frameworks and tools are struggling to adapt to the dynamic, fast-evolving nature of AI technologies and agentic workflows.
Organizations with stronger AI governance practices are better positioned to manage risks, demonstrate compliance, and build stakeholder trust in their AI initiatives.
GRC teams are actively seeking better tools, processes, and platforms specifically designed to provide visibility, risk assessment, and governance capabilities for AI.
The research underscores that effective AI governance requires close collaboration between GRC, security, legal, and technology teams rather than siloed efforts.
Many organizations are still in early stages of developing formal AI governance policies, risk frameworks, and compliance controls despite high levels of AI deployment.
The findings point to a critical need for purpose-built GRC solutions that can keep up with the speed and complexity of AI adoption while maintaining appropriate oversight and accountability.
What the Report Covers
Drata’s State of GRC in the Age of AI research report examines how governance, risk, and compliance (GRC) professionals are responding to the rapid adoption of AI across enterprises. Drawing on survey data from GRC leaders and practitioners, the report highlights the current state of AI visibility, governance maturity, risk management practices, and accountability challenges in the AI era.
The report covers several key areas:
AI Adoption and Visibility Gaps — It details the pace of AI deployment and the surprisingly low confidence levels among GRC professionals, with only 13% fully confident in their organization’s AI visibility and control.
Governance and Accountability Challenges — The research explores the growing demand for clear ownership, auditability, and structured oversight of AI systems, as traditional GRC frameworks struggle to keep pace with AI’s speed and complexity.
Risk Management in the AI Era — It examines how organizations are assessing and mitigating AI-related risks, including data privacy, compliance, security vulnerabilities, and ethical concerns.
Maturity of AI Governance Programs — The report analyzes the current state of formal AI governance policies, cross-functional collaboration, and the tools GRC teams are using or seeking to improve oversight.
Future Outlook and Priorities — It discusses what GRC professionals see as the most important investments and changes needed to build effective AI governance capabilities moving forward.
Throughout the report, Drata emphasizes that accountability has become the central requirement for GRC teams as AI becomes deeply embedded in business operations. The document combines quantitative survey insights with practical observations to help GRC, risk, and compliance leaders understand current realities and identify steps toward stronger AI governance.
Overall, the report serves as both a benchmark of the current state of GRC in the AI age and a call to action for organizations to close the gap between AI innovation and responsible governance.
What AI Governance Looks Like Now
With the rapid adoption of AI across enterprises, AI governance is evolving from an emerging priority into a core focus for GRC teams, though it remains a work in progress for most organizations. GRC professionals are increasingly implementing structured oversight mechanisms, risk assessment processes, and accountability frameworks specifically tailored to AI systems. Many teams have begun developing formal AI governance policies, establishing cross-functional working groups, and deploying tools designed to improve visibility into AI usage, data flows, and decision-making processes.
Current practices often include AI risk registers, model inventories, and regular compliance reviews, with growing emphasis on auditability and explainability of AI outcomes. Some organizations are integrating AI-specific controls into existing GRC platforms, while others are adopting purpose-built solutions to address the unique challenges of agentic AI and automated decision systems. There is also a noticeable push toward better collaboration between GRC, security, legal, and technology teams to create more cohesive governance strategies.
However, significant gaps persist. Most GRC professionals still report limited confidence in their overall AI visibility and control, with only 13% feeling fully confident. Many organizations are still in the early stages of building comprehensive AI governance programs, struggling with incomplete inventories, inconsistent policies, and tools that were not designed for the speed and complexity of modern AI deployments. The report shows that while awareness and intent are high, execution and maturity vary widely across industries and company sizes.
Overall, AI governance today is characterized by growing investment and recognition of its importance, but also by the reality that governance is still catching up to the pace of AI innovation. The teams making the most progress are those treating accountability as a foundational requirement rather than an afterthought.
Our Take
AI Governance Take
Drata’s State of GRC in the Age of AI report delivers a clear message: AI has arrived faster than the governance structures needed to manage it responsibly. With only 13% of GRC professionals fully confident in their AI visibility and control, the research highlights a critical gap between innovation speed and governance maturity that organizations must address urgently.
The findings reinforce that effective AI governance is no longer a nice-to-have — it is foundational to sustainable AI adoption. As AI systems become deeply embedded in business operations, GRC teams are demanding greater accountability, auditability, and structured oversight. The report shows that organizations treating AI governance as a strategic priority — rather than a compliance checkbox — are better positioned to manage risks, demonstrate regulatory compliance, and build stakeholder trust.
For governance, risk, and compliance leaders, the key takeaway is the need to move beyond reactive approaches toward proactive, integrated AI governance frameworks. This includes building comprehensive AI inventories, establishing clear policies and ownership, implementing effective monitoring and audit capabilities, and fostering closer collaboration across GRC, security, legal, and technology teams. The research also underscores the importance of purpose-built tools that can keep pace with the dynamic nature of AI deployments.
Ultimately, the report positions accountability as the central requirement in the age of AI. Organizations that invest in strong governance practices today will gain a competitive advantage through reduced risk, faster compliance, and greater confidence in their AI initiatives. Those that continue to let governance lag behind deployment risk regulatory issues, reputational damage, and missed opportunities to build trustworthy AI systems.
The State of GRC in the Age of AI serves as both a benchmark and a call to action: the future belongs to organizations that can govern AI as effectively as they innovate with it.