Respondents with a documented responsible-AI approach: 24% (Source: Strand Partners survey commissioned by AWS, cited in AWS Reimagine 2026, via Help Net Security)
Use has moved ahead of documented policy
AWS's Reimagine 2026 report draws on confidential interviews with 154 executives at 128 organizations across 23 industries, conducted over nine months. Its central argument is that governance has to be built into AI systems and that people must stay accountable for outcomes. Help Net Security covered the findings. The report leans on a Strand Partners survey of European businesses, paid for by AWS, in which a majority of small and mid-sized companies and large enterprises said they use AI.
The coverage does not say what base those percentages are drawn from, so treat them as directional. The survey and the executive interviews are separate sources and cannot be compared directly, but the gap between adoption and written policy points in the same direction as what several interviewees describe from inside their organizations.
Approval queues that outlast the experiment
Several organizations still run review processes designed for six-month IT programs against work that takes days. The report says that when a review cycle stretches to a month for an experiment that would take two weeks, some teams simply stop applying. The authors say policy is then "pushing it underground." One interviewed leader described CIOs who spent years on shadow IT now facing shadow AI at ten times the scale.
Boston University's CIO, Chris Sedore, offers a rough estimate that between two-fifths and half of the university's people turn to AI at least once a week. Some of that happens in sanctioned systems and some of it, in his words, is "going rogue." The report names leakage of proprietary data, customer personal information and business intelligence through third-party tools as a core concern. Such leakage can be invisible to the organization.
Adoption is not the same as results
The report warns that usage figures reveal little about value. Dr. Rashed Iqbal, CTO at RAK IDO, makes a related point about saved time: without a plan for the hours freed up, the company gains nothing. For a budget-holder, license counts and login rates are weak evidence of return.
Controls interviewees described
Bradesco's Rafael Cavalcanti built a decision tree that sorts each AI use case using three questions: does it involve personal data, does it run live or in batches, and must a person stay in the loop. The answers together place the project in a risk tier that carries its own set of controls.
On agents, the authors' guidance is to begin with a person approving actions, grant more independence once the agent proves dependable, and retain the means to pull that independence back. They liken this to probation for a new hire. Security limits should sit outside the agent, they write, because agents "can misinterpret or work around embedded rules."
Where salary, HR or personal communications data is involved, some organizations redact it before processing. At Houston Methodist, staff needed about a year of experience before they trusted that the system looked at group-level patterns and left individuals out.
What the evidence can and cannot support
The findings are qualitative, drawn from interviews, and the survey behind the adoption figures was commissioned by AWS. The report also notes that jurisdictional differences complicate a single global policy. Standard Bank's Duncan Macdonald pointed to the difficulty of operating across 22 countries. None of the interviewed organizations claimed to have solved the junior-talent problem, where AI removes the repetitive work that once built judgment.
Questions to put to your team
1. Do we have a documented responsible-AI approach and a data governance strategy, and who owns each?
2. How long does a small AI experiment wait for approval, compared with how long it runs?
3. What do we know about AI tools staff use outside those we provide, and what data reaches them?
4. Do we classify use cases by personal data, live versus batch processing, and human oversight, with controls attached to each tier?
5. For any agent we run, which limits are enforced outside the agent, and how would we reduce its autonomy?
6. Do we measure outcomes from AI use, or only adoption?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.





