← Back to news
Archived · Published 14 August 2026
AI Governance Has Become a Budget Line, and It Is Growing Faster Than the Budget It Sits In
Enterprise AI budgets have grown steadily, with a large majority of enterprises reporting increases for 2026 and median year-over-year growth in the low twenties as a percentage. Inside that growing total, one component has grown considerably faster than the rest: the portion allocated to governance, compliance, security review and policy — estimated at 8-12% of AI budgets in 2026, against 3-5% two years earlier. Spending on the control layer is outpacing spending on the capability it controls.
The straightforward reading is regulatory, and it is partly right. Disclosure obligations, risk classification requirements and sector-specific rules have all arrived or firmed up, and each imposes documentation and assessment work that has to be staffed. But regulation alone does not explain the pattern, because the growth appears in organisations and jurisdictions where the binding requirements are still light. Something other than compliance deadlines is driving it.
That something is the transition from pilot to production. A pilot touching internal data with a handful of users is a contained experiment; a system taking actions against customer records at scale is an operational risk that has to be reviewed, monitored, logged and periodically re-examined. The governance cost is not really a tax on AI adoption — it is the cost of the systems being consequential enough to matter, and it appears at exactly the point in the deployment curve where the technology starts producing value. Organisations that pushed hardest into production are the ones reporting the largest governance shares, which is the opposite of what a pure compliance-burden story would predict.
The failure mode is a governance function measured by the volume of review it performs rather than the risk it prevents, which reliably produces a queue that every team learns to route around — approval theatre that delays the well-documented projects while the informal ones never enter the process at all. The organisations getting a return on this spending have generally moved the controls into the delivery path rather than alongside it: evaluation and logging requirements built into the deployment tooling, so that meeting the standard is the path of least resistance rather than a separate obligation competing with shipping.
Defici Editorial · Business
This article was generated by Defici's AI editorial system.