Enterprise AI Application Expansion Drives Significant Growth in Risk Mitigation Budgets
As enterprise AI adoption rates rise, governance and risk mitigation have become priorities. A OneTrust survey of 1,250 IT leaders shows that nearly all enterprises plan to increase governance budgets, with an average increase of 24%; IT leaders spend about 37% more time managing AI risks. Experts emphasize that improving governance frameworks and risk mitigation strategies is crucial to avoiding financial losses.

At a Glance
- According to a September report by OneTrust (which surveyed 1,250 IT leaders), as AI risks become clearer, enterprises are allocating more resources to governance.
- 98% of enterprises plan to increase governance budgets in the next fiscal year, with an average expected increase of 24%. Among IT leaders with "advanced AI adoption," 86% say they have identified gaps in visibility, collaboration, and policy enforcement.
- Enterprises are also investing more time in risk mitigation. The survey shows IT leaders now spend about 37% more time managing AI risks this year. More than four-fifths of enterprises view AI risk as a key factor driving the modernization of governance practices.
Deep Dive
Despite the many potential benefits of AI, chief information officers (CIOs) cannot ignore its risks. Enterprises are refining their strategies around governance and safeguards.
"Like many other operational aspects within an organization, when protecting AI, you must establish first, second, and third lines of defense," Traci Gusher, EY Americas AI and Data Leader, told CIO Dive (a sister publication of CFO Dive). "This comprehensive set of policies, value systems, technical processes, control points, and the people involved is what truly constitutes robust, responsible AI management."
Enterprises already rely on multiple mechanisms to improve risk mitigation, such as human-in-the-loop oversight, data access restrictions, and using AI through trusted technology providers. Recommendations issued by the National Institute of Standards and Technology (NIST) last year have also helped enterprises make progress in the early stages.
Analysts note that as AI technology matures and enterprises analyze potential risks, refining governance will be an ongoing, iterative process.
Some CIOs are also taking a more deliberate approach to prioritizing AI projects.
"If you just approve everything... your chances of success are much lower," said Greg Macatee, senior analyst at S&P Global Market Intelligence's 451 Research.
Although some "dead-end" AI projects are inevitable, failing to mitigate risks comes at a cost. According to an Infosys report from August, nearly all senior executives said their enterprises experienced at least one "incident" due to enterprise AI use, primarily resulting in direct financial losses. On average, enterprises reported losses of $800,000 over a two-year period.
CIOs are under pressure to help enterprises navigate this rugged and uncharted territory. AI adoption has changed what and how technology leaders govern, but Blake Brannon, Chief Innovation Officer at OneTrust, says vigilance remains crucial as the need for further adjustments grows.
"While AI initiatives move at unprecedented speed, traditional governance processes still operate at yesterday's pace," Brannon said in a press release accompanying the report.