Two-thirds of the organisations in IBM’s 2026 breach study had no AI governance policy in place. The distribution shifted toward a middle state where a policy exists on a slide deck and not in a control. Five of six comparable governance controls declinedOf the six AI governance control types the study measured in both years, five lost adoption, as of the February 2026 close of the study window. The 32 per cent holding a finished policy, cited above, comes from a separate question and is not a seventh control in this set. Read the complete article at Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report.