← Back to All Articles
AI Governance & Security

Falling Behind or Wasting the Spend? What CEOs Fear About AI, and Why Rules Can Speed You Up

A
ANG Associates
Life Sciences & AI Consulting
Sep 2026 7 min read

The Problem: The Fear Is Not Only a Leak, It Is Falling Behind While Paying for It

It is tempting to assume that CEOs lie awake worrying about a data leak. The survey evidence suggests a different first worry. In PwC's 29th Global CEO Survey (4,454 CEOs in 95 countries, fielded 30 September to 10 November 2025), the most-cited concern was the pace of AI-related transformation, at 42%, ahead of macroeconomic volatility (31%) and cyber risk (31%, up from 24% the year before). Only 30% of CEOs were confident about revenue growth over the next 12 months, the lowest in five years.

The same survey asked what AI has delivered so far. Only 12% report both cost and revenue benefits, 33% report gains in one of the two, and 56% report no significant financial benefit to date. This survey predates 2026, so the picture may have moved, but it captures the tension well: pressure to move fast, and unclear returns for the money already spent.

Grant Thornton's 2026 survey (950 leaders) adds a telling detail: 73% cite competitor pressure, rather than internal ROI analysis, as what drives their AI adoption. Gartner's May 2026 survey of 1,400 CIOs found that "operationalizing AI" has become the CIOs' top functional priority, overtaking cybersecurity, with 52% naming lack of skills as their main challenge. The mid-market picture is similar: Netrio (a vendor, surveying 401 US IT leaders) found 82% with AI in production or widespread use but only 26% reporting enterprise-wide scaling and governance. In Switzerland, EY's May 2026 survey of 604 companies found 89% use AI daily but only 9% see AI as transforming their business model.

The Solution: Governance That Speeds Decisions Up Instead of Slowing Them Down

PwC's data contains a finding that matters for anyone who assumes governance is a brake. Companies with strong AI foundations, including Responsible AI frameworks and enterprise integration, were about three times more likely to report meaningful returns. Grant Thornton similarly found that 58% of leaders with fully integrated AI report AI-driven revenue growth, against 15% of those still piloting. We want to be careful here: these are correlations. Firms that scale may simply be better resourced, and we cannot show from these surveys that governance causes the returns. What the data does support is a narrower and still useful point: the organizations getting value are not the ones without rules; they are the ones whose rules let them move.

The reason is practical. When every AI request goes through the same slow review, or when there is no review and each team improvises, the business either waits or takes risks nobody has priced. A risk-tiered approach fixes both: low-risk uses are pre-approved and start quickly, moderate-risk uses get a short structured review, and only the few high-risk uses go to senior committees.

Some sources also caution against expecting quick payback. Gallagher, an insurance broker, reports from its third annual AI survey that meaningful return on investment remains two to three years away, while Netrio's respondents were 96% confident of measurable ROI within 24 months. Those two views differ and neither is a benchmark; the safer stance is to define what success means before spending.

The Approach: A Safe Fast-Track in Four Moves

1. Tier the risk. Define three lanes by data sensitivity and impact on people or customers. A green lane for low-risk use of non-sensitive data, an amber lane for review, a red lane for high-stakes uses. Publish the criteria so teams can self-classify.

2. Pre-approve tools and patterns. Maintain a short catalogue of approved tools with the contract terms and security controls already checked, so a green-lane request is a same-week decision rather than a project.

3. Concentrate the spend. Pick a small number of use cases with an owner, a baseline and a target, and stop funding the long tail of pilots with no measure attached. Our earlier article on how pharma CIOs can split AI budget shows one way to do this.

4. Report to the board in one page. Which uses are live, what they cost, what they return, and what risks were accepted and by whom. This is also the evidence that answers the audit question.

Speed and control are not opposites. Unclear rules are what slow people down; clear ones let them move without asking permission every time.

How ANG Associates Can Help

ANG Associates designs a Safe Fast-Track for leadership teams that want to move on AI without creating unpriced risk. We work with your CEO, CIO and business leads to define the risk tiers and approval routes, identify which use cases deserve concentrated investment, set baselines and success measures, and prepare the one-page board view. We then support the first waves through the fast track so the process is proven on real requests, not just documented.

Our Life Sciences and IT delivery background helps where AI has to fit alongside validated systems, quality processes and regulatory expectations. We advise rather than sell software, so the recommendation on which tools to approve is not tied to a vendor. We cannot promise specific returns; what we can do is make sure you know what you expect, measure it, and can show the board how you got there.

This is one of six services in our ANG AI Trust Compass offering.

Sources

AI ROICEOCIOSafe AI AdoptionAI Governance

Interested in this topic?

Let's discuss how we can apply these approaches to your organization.

Contact Us