Your AI governance policy exists.
Your organization's behavior doesn't match it.
McKinsey just put a number on the gap.
Enterprise Responsible AI maturity averages 2.3 out of 4 in 2026, up from 2.0. But fewer than a third of organizations have reached level 3 in the dimensions that matter most: strategy, governance, and agentic AI controls.
Most executives think of "AI governance readiness" as binary: you either have it or you don't. That's the wrong frame.
Readiness is a ladder, and most organizations are standing on a lower rung than the board deck suggests.
The progression toward adaptive and accountable governance is particularly important. But accountability may raise another question: is knowing who is accountable enough to understand whether a decision was sound?
An autonomous action can have a named owner, follow established controls, and remain fully traceable, while still being influenced by weak assumptions, incomplete evidence, or biases embedded in the reasoning behind the decision.
As AI becomes more involved in consequential decisions, governance may need to examine not only who authorized an action and whether the rules were followed, but also the quality of the reasoning that led to it.
Perhaps maturity will increasingly depend on making that reasoning visible enough to challenge, review, and learn from.
The gap between policy and behavior is, perhaps, the more important governance measure.
An institution can have an excellent governance framework and still behave as though it has none.
The real test is what happens when the policy meets an actual decision: who has the authority to act, who owns the consequence, and whether the control is embedded in the workflow rather than left in a document.
In that sense, governance maturity is less about having more rules and more about making the right behavior increasingly institutional rather than dependent on individual vigilance.
AI simply makes that distinction much harder to hide.