Governance is advancing, but confidence remains fragile
Governance is already a prominent consideration across the respondent base, but maturity varies. Twenty-one respondents reported that AI governance or policies were in place, 21 said they were in development and 14 said they were partly in place. Four said they were not in place and six did not know. At the same time, concerns around data protection, security, accuracy and trust remain widespread.
Respondents reported a broad range of governance controls already being used within their organisations. These included AI policies, data protection controls, approved tool lists or AI registries, secure AI environments, human oversight, training, risk assessments and AI usage monitoring. A small number also reported more formal controls including vendor risk assessments and model validation.
The findings show that governance is not limited to a single policy document. Respondents reported combinations of policy, oversight, training and technical controls intended to support responsible use alongside experimentation and innovation. Despite these developments, concerns about AI remain significant.
Hallucination and data protection concerns
Hallucinations or incorrect outputs were selected as a concern by 39 respondents, 59%, followed by data protection at 38, 58%, and security at 29, 44%. Bias was selected by 19 respondents, 29%. Respondents also referenced compliance, vendor lock-in, intellectual property, cost and the potential loss of tenant trust.
Biggest concerns about AI (top 5 selected)
Hallucinations / incorrect outputs
Data protection
Security
Skills
Bias
Hallucinations and incorrect outputs emerged as particularly common themes. Throughout the responses, participants highlighted concerns about the accuracy of AI-generated information and the potential consequences of relying on outputs that may be incomplete, misleading or wrong. These concerns often appeared alongside wider anxieties about poor-quality source data and the risk of generating unreliable insights from flawed information.
Governance concerns are also closely linked to culture and organisational confidence. Twenty-three respondents identified risk appetite or organisational culture as barriers to wider AI adoption, while 16 identified governance itself as a constraint on progress.
Together, these findings suggest many organisations are still working to determine how AI can be used safely, responsibly and in a way that aligns with organisational values and expectations.
Governance maturity
The survey shows that governance maturity varies considerably. Some organisations reported comprehensive approaches including policies, training, monitoring, risk assessments and approved tool lists. Others were still developing their approach or had implemented only a limited number of controls.
Twenty-seven respondents selected strengthening governance as a priority for the next 12 months, making it one of the most commonly identified areas for future focus. For Housemark, the prominence of governance among respondents’ priorities supports the view that proportionate governance can enable responsible adoption.
The findings indicate that responsible AI adoption requires more than access to technology. Organisations also need clear expectations, practical safeguards and confidence in how AI is being used. For Housemark, the challenge is not choosing between innovation and governance, but creating enough trust, oversight and clarity to support both.