Evidence synthesis reveals widespread gaps between AI adoption and governance accountability across organisations, highlighting the structural limitations of compliance-first regulatory frameworks.
Organisations have absorbed AI faster than they have learned to be accountable for it. By late 2025, 88 per cent of organisations reported using AI in at least one business function, up from 78 per cent a year earlier. The average score on the sector's leading five-dimension AI trust maturity model stood at 2.3 out of 5, and the newest dimension, governance of agentic AI, lagged the rest. Nearly three-quarters of surveyed organisations are giving agentic AI systems access to their data and processes while only 20 per cent hold a tested AI incident response plan, and 78 per cent lack full confidence that they could pass an independent AI governance audit within 90 days. This paper argues that the gap between adoption and accountability is structural, not transitional. It reviews the accountability, algorithmic-auditing, documentation, agentic-governance, organisational-compliance, regulatory, and adjacent-domain governance literatures the argument draws on; distinguishes compliance-first from accountability-first governance, drawing on accountability theory; synthesises the 2025-2026 survey evidence; examines why agentic AI exposes material limitations in governance frameworks designed for request-response systems; and reviews the EU AI Act (as amended by the 2026 Digital Omnibus), ISO/IEC 42001, the NIST AI Risk Management Framework, and the UK's principles-based approach, finding that all four address compliance structure more fully than accountability practice. The paper then proposes an Accountability-First AI Governance Framework (A-FAGF) of seven protocol families, mapped onto existing regulatory obligations so that adoption is additive to compliance work already under way. It states the scope conditions under which meeting a family's documentary requirement actually delivers the accountability it is meant to deliver, including the assurance boundary and the risk of assurance laundering. The framework's completeness is qualified by these conditions and is not asserted on the seven families alone. Three practitioner case studies, disclosed as a conflict of interest, indicate that the framework is implementable at enterprise and SME scale with current tooling. We translate the framework into thirteen recommendations assigned by actor, of which only one requires a regulatory obligation that does not already apply. The framework therefore rests on three kinds of warrant: it is derived from a documented gap analysis, each family answers a deficiency the review of instruments evidences, and the case studies show it in operation. What it lacks is comparative effectiveness data, and none of the four instruments reviewed here meets that standard either.
No takes yet. Share an insight, caveat, or question.
Abu et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: