2026 Benchmark Survey · AI in Ethics & Compliance
The Cobbler’s
Children
The State of AI Adoption in Ethics & Compliance
Why the function that governs AI is the last to benefit from it.
01 · Executive Summary
Executive Summary
Ethics and compliance functions have spent the past two years helping write the rules for how their organizations use artificial intelligence. In this survey, 63% of E&C leaders report a formal role in enterprise AI governance — reviewing tools, drafting guardrails, or advising the teams that own the framework. Most have done this without applying AI to their own function in any meaningful way.
That is the finding at the center of Ethisphere’s AI in Ethics and Compliance Survey of E&C leaders at 134 organizations. 67% of respondents say their organization has reached broad or advanced AI adoption. Only 22% say the same about their own E&C function, a 45.5-point gap in AI adoption maturity between the enterprise and the function governing it.
We call this the Cobbler’s Children problem: the shoemaker outfits the whole town while his own kids go barefoot. E&C helped write the guardrails for enterprise AI and, in the process, put its own AI enablement last.
And there is a twist: the cobbler doesn’t quite trust the shoes. Asked what holds their own adoption back, E&C leaders name accuracy and hallucination risk (53%) and data exposure (48%) first — the very risks the function spends its days governing for everyone else. Knowing exactly where AI fails appears to have made E&C a notably cautious adopter of it. Closing the gap starts with resolving that trust deficit, not with more appetite.
That risk is that a lean team’s limited bandwidth is going to low-impact activities, like reviewing repetitious conflicts of interest manually. A better approach is using AI to have compliance in the loop, and then free up compliance teams’ time to do far more impactful activities.
AI is also often better at spotting risks and trends than a human. Incorporating that perspective leads to a far more sophisticated, tailored, and defensible compliance program.
Four data-backed patterns explain how this gap opened, and why it hasn’t closed on its own:
This report walks through the full data behind each pattern, what is holding E&C back in its own words, and shares a sequenced set of actions for closing the gap over the next 12 months.
02 · Methodology
About This Research
Ethisphere partnered with Ethena to survey ethics and compliance leaders at 134 organizations in June 2026. What sets this benchmark apart is who answered it. Ninety-five percent of respondents work directly inside the ethics and compliance function, and a majority (55%) are Chief- or VP-level E&C leaders who set AI strategy and policy for their function.
This is not a survey of general AI adopters or IT teams. It is a direct read on how E&C itself is using the technology it is responsible for governing.
Fielded in partnershipRespondents represent large, complex organizations: 89% report more than $1 billion in annual revenue, ranging from under $500 million to more than $25 billion. A full breakdown of revenue, industry, program structure, and team size appears in the appendix.
Aside from the respondent-profile questions, every question in the survey was optional. Respondents could skip any question that did not apply to their function or where they had no view, so response counts vary by question. Engagement was nonetheless high: more than 80% of respondents answered at least 90% of the questions that applied to them, and the median respondent completed 97%. Where a percentage reflects only the respondents who answered a particular question rather than the full sample of 134, the base size (n) is noted alongside it.
These findings reflect ethics and compliance leaders primarily at large, established organizations — the population Ethisphere’s network reaches — and are best read as directional rather than representative of all companies.
03 · The Central Finding
The Cobbler’s Children
Every enterprise function is racing toward AI adoption, and E&C is expected to keep pace with all of them at once: reviewing use cases, writing policy, approving tools. Meanwhile, its own use of AI lags the enterprise.
Pull the distribution apart, and the gap widens further. Half of E&C teams describe themselves as having “some approved use cases,” the middle of the maturity curve, and more than a quarter remain at “limited experimentation.” Only 2% have reached advanced, governed use. On the organization side, two-thirds have already moved past that midpoint.
Two more numbers describe the state of the discipline. 84% of E&C teams that answered have no dedicated AI budget line, and just 4.5% measure AI’s impact with defined metrics. Neither number proves money is the constraint — teams can and do fund AI through enterprise licenses and general budgets; 86% of teams that answered use Microsoft Copilot or other enterprise copilots — but together they signal something more telling: AI inside E&C is still informal and experimental. It has not yet become a funded, measured discipline.
This is not a story about E&C falling behind through inattention. It is the predictable result of a sequencing problem. E&C was handed the mandate to govern AI use across the enterprise, writing policy, vetting tools, setting guardrails, before it had the chance to build its own AI capability. And when leaders name what is holding them back today, the answer is not money. It is trust in the technology itself.
Why This Gap Formed
Three forces explain how this gap opened, and why it has not closed on its own.
The requests have shifted from ‘should we use it’ to ‘where should we integrate this technology in our program and how do we govern it well’. BELA members asking for AI governance policies, risk-tiering frameworks, and introductions to peers who’ve already put AI into investigations or due diligence.
What that tells me is simple: the hardest part of responsible AI adoption isn’t the technology, it’s the judgment around it — and that judgment is being supported by the collective knowledge and lived-in experiences of the BELA community, one peer conversation at a time.
04 · Governance Maturity
Where Guardrails Stand Today
E&C has not been idle on governance, even where its own AI adoption lags. Across the full sample, formal guardrails for AI use are common. In other words, E&C helped write the rules, but it has not been resourced to follow them with the same tools it reviews and approves for everyone else.
These guardrails represent real institutional work, but what they don’t represent is capability. Writing a policy for how AI should be used is a different exercise than building the budget, tooling, and measurement discipline for E&C to use it well itself, and the data above shows the former is far more mature than the latter.
The survey results illustrate this starkly. Trying to mitigate risk by steering clear of AI isn’t going to work in the short or long term. It creates a gap between employees using and encountering AI every day and E&C teams steering clear of time-saving and responsive technology ‘in case’ a risk arises.
Start simple with creating and using role and risk tailored training, triaging the hotline and helping employees file a report, and sorting through the annual conflict of interest or other disclosure mountains of data to find what’s important. That can help free up staff time for human oversight and fine-tuning.
The end result will be more meaningful metrics and more impactful, employee-friendly and responsive E&C programs.
06 · The Analysis
Four Patterns in the Data
The aggregate gap explains where E&C stands today. Four patterns in the data explain why, and where the fastest-moving programs are already pulling ahead.
The Centralization Paradox
Centralized programs are the most common structure in this survey. 44% of respondents run a single global E&C team — and of the three main structures, they show the lowest broad-or-advanced adoption and the highest share at limited or no use.
Only 16.9% of centralized E&C teams have reached broad or advanced AI adoption, and 35.6% remain at limited experimentation or no use at all. Hybrid programs, which pair central strategy with regional execution, do meaningfully better on both counts: 25.6% broad or advanced, and just 15.4% limited or none. E&C teams that sit inside Legal (n=27) show adoption rates directionally between the two, though the sample is too small to draw firm conclusions — and because respondents selected a single structure, some of these teams may themselves be centralized in form. The remaining structures in the sample are included in the appendix for completeness.
Centralization is supposed to be an advantage for AI adoption: one team, one policy, one rollout. In practice, the model best positioned to move fast is the one moving slowest. The likely explanation is capacity, not structure. Centralized teams carry global scope on a fixed headcount, leaving less slack to pilot and staff new tools. Hybrid programs distribute that load across regions. Legal-embedded teams — the smallest in the survey, yet among the better adopters — may be borrowing capacity rather than building it, whether from Legal’s broader resources or, in some organizations, dedicated legal ops and AI teams. Illuminating dynamics like this is the point of this benchmark. Today’s constraint is not tomorrow’s, and how programs solve for capacity — distributing it, borrowing it, or funding it — will be one of the clearest signals to watch as the field matures.
Centralized programs aren’t slow to innovate around AI usage because they’re centralized — they’re slow because we ask one team to carry global scope on a fixed headcount, and then wonder why nobody has time to pilot anything. The programs that outperform here aren’t the ones with a different org chart; they’re the ones that found capacity and focused use cases.
Hybrid teams distribute the load regionally and find specific use cases that lend themselves to experimentation. Teams inside Legal are often borrowing capacity — from legal operations groups and enterprise AI teams that already exist next door — and those teams are already good at spotting potential use cases.
The lesson for a centralized CECO isn’t to restructure. It’s to stop treating AI adoption as one more unfunded mandate for the same headcount, and to go find the capacity your peers are already borrowing.
Team Size: The Full Picture
Patterns 2 and 3 both turn on team size. The full picture across every band shows why.
Two things stand out. Organizations with larger E&C teams are somewhat more likely to sit inside a fast-moving, AI-forward enterprise, largely a function of scale: bigger E&C teams tend to sit inside bigger, more AI-mature organizations. And integration friction is flat and low across small and mid-sized teams, then spikes hard at 100-plus (n=14), roughly doubling the next-highest band. The pattern isn’t gradual: rather than increasing steadily with team size, integration challenges appear to emerge differently at enterprise scale, becoming most pronounced among the largest E&C functions in this survey.
The Large-Team Ceiling
Bigger E&C teams should have more room to experiment with AI. In this survey, they do not.
One interpretation, consistent with the data but not directly measured by it: size does not translate into agility. Large E&C functions tend to run on more entrenched legacy systems, more layers of internal process, and more stakeholders who need to sign off before a new tool goes live. If that reading is right, the bureaucracy that comes with scale is exactly what slows AI integration down — and it would explain why the pattern shows up most clearly in the biggest teams in this survey.
The Mid-Size Anomaly
The sweet spot for AI adoption in this survey is not the biggest team or the best-funded one. It is the mid-sized team.
This is the sharpest version of the Cobbler’s Children pattern in the data. These teams sit closest to the AI opportunity, inside organizations already moving fast, yet run their own AI with the least operationalization anywhere in the survey: no dedicated budget line, little to no impact metrics. The appetite is clearly there: 96% of answering 16-30 person teams report their AI use rose in the past six months, against 91% sample-wide. The discipline around it has not caught up.
The Advanced-Org Gap
If organizational AI maturity closed the gap on its own, this pattern would not exist. It does not close on its own.
Among the 14 organizations in this survey rated “advanced, governed, and integrated” in their AI use, only 14.3% have an E&C function at that same strict level. Half have a formal process for approving new AI use cases, and 71.4% require human review of AI-generated work before it is used, both meaningfully higher guardrail rates than the sample overall (50.7% and 60.4%, respectively). That tracks: the more advanced the organization, the more it has had to build guardrails to match its own AI use.
Zooming out, at broad-or-advanced rather than strictly advanced, the picture is less bleak but tells the same story.
E&C adoption does track organizational maturity, it just never catches up to it. Inside the most AI-advanced organizations, 57.1% of E&C functions have reached broad or advanced adoption themselves, the best showing anywhere in the survey. But that is still closer to a coin flip than a guarantee, inside the very organizations where the case for E&C’s own AI adoption is easiest to make. Move one tier down, to organizations with broad adoption, and the rate falls by more than half, to 23.7%. The gap is not fixed. It widens as organizational AI maturity decreases — and even organizations that have made significant progress on enterprise AI adoption have not consistently translated that maturity into E&C capability.
As these organizations move from AI that assists toward AI that acts, blanket human-review requirements will need to become a more deliberate, risk-tiered policy. Otherwise, the guardrail built to manage risk becomes the single biggest bottleneck between advanced organizations and the actual promise of the technology they have adopted.
07 · The Next 12 Months
Looking Ahead: Agentic AI and the Review Bottleneck
The human-review tension inside the Advanced-Org Gap is not a footnote. In our view, it is the central governance question for E&C over the next 12 months.
Nearly three-quarters of the most AI-advanced organizations in this survey still require a human to check AI-generated work before it goes out the door. That is a sound guardrail for most AI use cases today. But it sits uneasily with agentic AI — systems built to take multi-step action without a human in the loop at every step.
71.4% of the most AI-advanced organizations in this survey require human review of AI-generated work before it is used, and 60.4% of the full sample does the same. That policy works cleanly for AI that drafts, summarizes, or recommends; a human stays in the loop by design. It breaks down for agentic AI: systems that plan multi-step tasks and execute them with only intermittent human input, if any. The survey did not ask about agentic AI directly, but the direction of travel is visible in what teams expect next: 56% of answering respondents rate workflow automation as a high-value AI use case for their function within the next 12 months — exactly the class of work that increasingly runs agentically.
E&C does not need to abandon human review. But it does need to make review risk-tiered rather than universal:
The functions that make this shift now will be positioned to use agentic AI as it matures. The functions that wait for a universal all-clear will find themselves, again, the last function to adopt the next wave of the technology they are responsible for governing.
When I talk to compliance leaders, I hear examples of them reviewing massive excel documents row by row. Their eyes become blurry as they review the 100th instance of an employee sharing a volunteer activity, and then having to pull up a stock approach, and email that back. It’s incredibly manual, error-prone, and isn’t making the best use of compliance’s human judgment.
When we built our Disclosure Agent, we designed to have AI do the heavy lifting of reviewing each employee disclosure, comparing it to your relevant policy, and making a recommendation of risk. That’s risk-tiered review in practice. Compliance remains in the loop, but can now spend their limited resources on the handful of cases that require extensive review.
This is AI elevating, versus eliminating, compliance’s role.
08 · The Playbook
What This Means for E&C Leaders
Closing E&C’s AI adoption gap starts with treating E&C’s own AI adoption as seriously as every other function’s. It doesn’t require solving everything immediately. Programs should sequence the fix the same way the gap itself was created: deliberately, not all at once.
E&C is well positioned to close this gap. With 63% of leaders reporting a formal role in enterprise AI governance, few teams understand the guardrails, the risk tolerance, or the governance model better than one that helped write them.
The Action Plan

One of the clearest takeaways from this research is that most E&C teams aren’t trying to do everything with AI, but they are trying to figure out what to do next. That’s why we built this worksheet: to help you identify your next 90 days, turn ideas into action, and measure your progress. A starting point beats a perfect plan every time.
09 · Summary Statistics
The Data, at a Glance
10 · Closing
Conclusion
Closing the 45.5-point gap starts with treating E&C’s own AI adoption as seriously as every other function’s. The data shows most programs have not done that yet. The programs that have, mid-sized, hybrid-structured, or those that treated AI as a funded, measured discipline from the start, are the ones already pulling ahead.
Ethisphere intends to track these four patterns going forward. If the gap narrows, mid-sized and hybrid-structured programs will likely lead the way. If it does not, the widening distance between organizational and E&C AI maturity will become one of the defining compliance risks of the next few years, not because E&C cannot be trusted with AI, but because it has not yet been given the same running start as everyone else.
About Ethisphere
Ethisphere is the global leader in defining and advancing the standards of ethical business practices. Ethisphere’s methodologies, including the World’s Most Ethical Companies® recognition program, empower organizations to improve profitability, sustainability, and trust by adopting next-generation governance, ethics, and compliance practices. Ethisphere convenes the largest global community of ethics and compliance professionals through the Business Ethics Leadership Alliance (BELA).
About Ethena
Ethena is a platform of AI compliance agents built for modern teams. Agents review disclosures, flag policy gaps, and build admin-friendly training from your real risk data. The tools ethics and compliance leaders count on, from employee reporting to case management, keep the rest of your program running. You’re in the loop for every judgment call. Ethena partnered with Ethisphere on this research to understand how E&C functions are adopting the AI they govern. Learn more at goethena.com.
Appendix: Full Sample Composition
For reference, the following tables show the complete demographic composition of the survey sample (n=134).
© 2026 Ethisphere · Good. Smart. Business. Profit.®