Skip to content
iclock 7 Minutes - Read Now
idate

The Cobbler’s Children: What 134 E&C Leaders Told Us About Their Own AI Adoption

Ethics and compliance teams are living two AI stories at once, and only one of them gets much attention. In […]

Bill Coffin
Bill Coffin Editor-in-Chief, Ethisphere Magazine, Ethisphere
The Cobbler’s Children: What 134 E&C Leaders Told Us About Their Own AI Adoption

Ethics and compliance teams are living two AI stories at once, and only one of them gets much attention.

In the first story, E&C is the function every other department turns to when AI shows up on the agenda. Marketing wants a generative tool for customer copy. HR wants an AI layer in its screening process. Someone in the field wants to run contract language through a large language model. All of it eventually lands on E&C’s desk for a policy read, a risk read, a yes or a no. In this survey, 63% of E&C leaders describe a formal role in enterprise AI governance: reviewing tools, drafting guardrails, advising the teams that own the framework.

In the second story, that same E&C team is supposed to be modernizing its own function at the same pace as everyone else, using AI to triage disclosures, screen investigations, or draft the first pass on routine reviews. Far fewer people are living this story in any meaningful way, and the data now shows exactly how wide that gap has become.

Both stories come together in The Cobbler’s Children: The State of AI Adoption in Ethics & Compliance, a first-of-its-kind report that analyzes how E&C teams are using AI relative to how much they must govern that same technology. And what that effort discovered has been quite interesting.

From anecodote to data

Ethisphere partnered with Ethena to put real numbers behind something we had been hearing anecdotally for months. BELA members kept raising a version of the same question about AI, and it wasn’t really about whether to use it anymore. It was about which peers had already figured out where AI belongs inside a compliance program, and what those peers had learned along the way. Plenty had been written about AI governance. Almost nothing answered the second question: how ethics and compliance functions are using AI themselves, at a level of detail a program leader could actually act on. So we built the benchmark ourselves, surveying senior E&C leaders at 134 organizations in June 2026 on exactly that.

What we found has a name now: the Cobbler’s Children problem. The shoemaker outfits the whole town while his own kids go barefoot. E&C helped write the guardrails for enterprise AI, and in the process, put its own AI enablement last.

By the numbers

The numbers make the metaphor literal. 67% of organizations in this survey have reached broad or advanced AI adoption. Only 22% of their E&C functions can say the same. That’s a 45.5-point gap between how fast the enterprise is moving and how fast the function governing it is moving. It holds up across every cut of the data we ran.

There’s a twist buried in that gap, and it changes what the fix should look like. When we asked E&C leaders directly what’s holding their own adoption back, the answer wasn’t budget. It was trust. Accuracy and hallucination risk (53%) and data exposure (48%) topped the list, well ahead of every resourcing barrier combined. Budget itself ranked sixth, at 23.9%. The cobbler doesn’t fully trust the shoes. E&C spends its days finding exactly where AI fails for everyone else in the building. That knowledge appears to have made the function a notably cautious adopter of the technology itself, and closing the gap starts with resolving that trust deficit, not with more appetite or a bigger line item.

Centralization and ceiling

Four patterns in the data explain how the gap opened and why it hasn’t closed on its own.

The first is what we’re calling the Centralization Paradox. Centralized global E&C teams are the most common program structure in the survey, at 44%, and they show the lowest AI adoption of the three main structures: just 16.9% at broad or advanced, and 35.6% stuck at limited or no use at all. Hybrid programs, which pair central strategy with regional execution, do meaningfully better on both counts. The likely driver is capacity, not the org chart. Centralized teams carry global scope on a fixed headcount, which leaves less room to pilot anything new.

The second is the Large-Team Ceiling. You’d expect the biggest E&C functions to have the most room to experiment. Instead, teams of 100 or more cite integration friction as their top barrier at 50%, more than twice the overall rate, and none of them measure AI’s impact with defined metrics. Scale, in this data, does not translate into agility.

Mid-sized and advanced adoption

The third is the Mid-Size Anomaly, and it’s the sharpest version of the Cobbler’s Children story in the whole data set. E&C teams sized 16 to 30 sit inside the fastest-moving organizations in the survey: 79.2% of them work inside a broad- or advanced-AI enterprise. These same teams have the least operational discipline around their own AI use anywhere in the sample. 87.5% have no dedicated AI budget line. The appetite is there; the follow-through isn’t.

The fourth is the Advanced-Org Gap, and it’s the clearest proof that this problem doesn’t fix itself. Even inside the 14 organizations rated most AI-mature in the entire survey, only 14.3% of their E&C functions have reached that same level. Organizational AI maturity does pull E&C along with it, directionally, but it never fully closes the distance.

Compliance in the loop

We asked Roxanne Bras Petraeus, CEO and co-founder of Ethena, what closing that distance looks like in practice for teams just starting out. Her answer is the clearest articulation we’ve heard of how E&C should sequence its own AI adoption:

“The principle we build on at Ethena is compliance in the loop: the agent does things like recommend and prepare. It’s the compliance leader who makes every judgment call,” Roxanne says. “This is an especially important principle for compliance teams who are early on their AI adoption journey. Companies shouldn’t go from crawl to run; instead, logically following an AI maturity journey means starting with compliance in the loop on every decision. Only after extensive testing and trust building might it make sense to start having true agentic workflows.”

That sequencing is the case for why the trust deficit in our data is solvable. It’s also the case for solving it deliberately, one stage at a time, rather than trying to close a 45.5-point gap in a single quarter.

Benchmark for yourself

The full report of The Cobbler’s Children: The State of AI Adoption in Ethics & Compliance, lays out all four patterns in complete detail, the full list of barriers E&C leaders cited in their own words, and a sequenced action plan built around three horizons: the next 90 days, the following two quarters, and the rest of the year.

[Read the full report →]

The report also comes with a live benchmarking tool, which is something not usually found alongside a research piece. Answer six questions about your own program’s structure, team size, and adoption stage. The tool generates a customized dashboard filtered to your industry and revenue band, measured against the 134 organizations already in this data set. It also produces a board-ready slide you can drop straight into your next deck.

[Open the interactive benchmark →]

E&C spent the last two years writing the rules for how the rest of the enterprise uses AI. Nobody is better positioned to apply those same rules to itself, and the benchmark now exists to show exactly how. This report, and the tool behind it, is a starting point for finally doing that.