Companies are moving quickly to bring AI into everyday operations, but new ISACA research points to a preparedness gap: only 8% regularly conduct AI-specific incident-response exercises, raising questions about whether governance is keeping pace with adoption.
Businesses have spent the past few years asking how quickly they can adopt artificial intelligence. A new study suggests another question deserves equal attention: what happens when something goes wrong?
Only 8% of organisations regularly conduct AI-specific incident-response exercises, according to new research from global technology professional association ISACA.
The finding highlights a widening gap between the speed at which AI is entering businesses and the systems organisations have in place to respond when AI-related problems emerge.
That matters because AI incidents can look different from conventional technology failures. They can involve inaccurate outputs, inappropriate data exposure, unexpected model behaviour or decisions that become difficult to explain once automated systems are embedded into business processes.
From Having a Plan to Testing It
The research suggests that simply having governance policies may not be enough.
Scenario exercises allow organisations to test what happens when an AI system produces an unexpected outcome: Who identifies the problem? Who has authority to intervene? When should a system be suspended? How are customers or employees informed?
Running those exercises before an incident occurs can expose unclear responsibilities and gaps in escalation processes.
ISACA’s research also found that organisations face challenges around AI skills and governance, reinforcing the need for technical teams, risk functions and business leadership to work more closely as AI adoption expands.
For executives, this shifts AI preparedness beyond the IT department.
AI is increasingly being used across customer service, cybersecurity, finance, HR, marketing and decision-making. An incident in one of those systems can therefore become an operational, reputational or governance issue rather than simply a technical one.
AI Readiness Enters Its Next Phase
The 8% figure does not suggest businesses should slow useful AI adoption. Instead, it highlights an opportunity to bring preparedness closer to the pace of implementation.
Companies already run cybersecurity simulations, disaster-recovery tests and business-continuity exercises. As AI becomes another layer of critical enterprise infrastructure, AI-specific scenarios could increasingly join that list.
The first stage of enterprise AI was about experimentation. The next could be about building the processes, skills and accountability required to use it reliably at scale — including knowing exactly what to do when the technology does not behave as expected.
Sources: ISACA; Business Wire.