Senior business decision-makers, including CIOs, CISOs, and chief data officers, are now working 26% more hours on average to manage AI risk, according to a new survey released by AI governance platform vendor OneTrust. Four in five of these leaders are dedicating more of their day to handling AI risk as enterprise adoption accelerates. While growing attention to AI governance marks a positive shift from an unregulated approach toward risk-aware strategies, the survey reveals it's exacting a significant toll on those responsible, particularly as autonomous AI systems add new layers of complexity.

The data reveals a stark contrast in how AI affects different parts of the organization. A third of survey respondents reported employees using unauthorized AI tools because approved options weren't available fast enough. Eighty-six percent have encountered AI-related incidents, and more than a quarter have experienced two or more cases where AI systems executed unauthorized actions. Meanwhile, separate findings from Boston Consulting Group show that 42% of frontline workers who regularly use AI save nearly a full day of work weekly, with most receiving no direction on how to use that recovered time. The picture that emerges is one of widespread activity, unclear priorities, and substantial executive hours spent on monitoring and damage control.

Blake Brannon, chief innovation officer at OneTrust, told the publication that adoption volume plays a massive role in the workload increase. "You've got the sheer volume and adoption of AI in organizations," he said. "Whatever AI they were using at the beginning of the year, it's probably more than 2x what they're now looking at using inside the company, and that's a compounding thing." The report highlights that much of leaders' additional time stems from heightened awareness of AI risk and governance, but triage and reactive measures account for a significant portion as well. Viren Meghani, technical architect at Tata Consultancy Services, observed that the increase isn't driven by overseeing sanctioned tools but rather by tracking down unauthorized ones, noting that time spent investigating unapproved tools doesn't constitute genuine governance but merely fire suppression.

The report explains that several factors drive the governance burden beyond simple awareness. The rise of citizen development, where non-IT employees build their own AI-powered applications, creates exponential growth in what needs oversight. AI complicates risk management because of the velocity at which it can execute decisions and generate problems, a shift from historically governing humans who operated at human speed. Unsanctioned AI use emerges when employees can't wait for approved solutions and find their own tools, forcing governance teams to retrofit controls around technologies never properly evaluated. As autonomous agents gain the ability to create other agents and identify vulnerabilities at remarkable speed, Conal Gallagher, CIO and CISO at Flexera, notes that governance constantly plays catch-up to AI's evolution, with the risk surface expanding faster than management capacity.

Organizations that take AI governance seriously invest time in architectural planning before deployment, using techniques like data lineage, model versioning, escalation paths, and audit trails, according to the report. Anant Adya, executive vice president at Infosys, said the shift from experimentation to enterprise-scale adoption naturally requires additional attention, though his company is embedding it into their operating model rather than simply adding hours. The report warns that agentic AI will add another level of urgency as these systems gain greater autonomy to access sensitive data, interact with other systems, and take actions on behalf of organizations, requiring strong identity controls, continuous monitoring, and appropriate human oversight. CIOs facing an overwork problem from playing catch-up on AI governance are advised to enforce what matters before autonomous workflows compound the challenge. The underlying risk isn't just operational but strategic: organizations may rush to capture productivity gains while their control infrastructure remains fundamentally unprepared for the decisions they're delegating to machines. Leadership teams must decide whether the current pace of adoption serves the business or merely creates the illusion of progress while accumulating technical and reputational debt.