The share of organisations without responsible AI policies in place dropped from 24% in 2024 to 11% in 2025. AI-specific governance roles grew 17%. The board-level conversation about responsible AI is now operating at a substantially different baseline than it was twelve months ago, and the strategic AI plans built on the prior baseline need updating.
Impact of responsible AI policies in organisations, 2024 vs 2025:
The structural shift visible in the data, from McKinsey's 2025 State of AI survey, has three dimensions.
First, RAI policy adoption itself. The share of organisations reporting they have not implemented RAI policies dropped 13 percentage points in one year. That is not a marginal change. It is the difference between "RAI policies are present in roughly three-quarters of surveyed organisations" and "RAI policies are present in roughly nine in ten." For board-level strategic planning, the implication is that having no RAI policy in 2026 puts an organisation in the minority and, increasingly, outside what regulators, customers, and partners expect as baseline practice.
Second, ownership formalisation. In 2024, AI governance was often distributed across data and analytics teams without clear ownership. In 2025, dedicated AI-specific governance roles rose from 14 to 17% as primary owners. Information security held steady at 21%. The share of organisations with no designated AI governance owner dropped from 9 to 5%. The pattern: RAI ownership is consolidating into named roles rather than diffusing across general technology functions.
Business functions assigned primary responsibility for AI governance, 2024 vs 2025:
Third, investment commitment. Organisations are backing governance structures with budget. Among organisations with $30 billion or more in revenue, 41% expect to spend $25 million or more on operationalising RAI in 2025; 22% have budgeted $50 million or more. Smaller organisations under $1 billion revenue typically expect under $5 million. The picture: investment is meaningful for large enterprises and proportionate for smaller ones, but it is no longer rounding-error territory across the survey.
Investment in responsible AI by company revenue, 2025:
The outcomes data is the part that should change strategic AI planning. Organisations with RAI policies reported improved business operations (+4pp), customer trust (+4pp), business outcomes including revenue (+7pp), and a measurable drop in AI incidents (+8pp) compared to 2024. These are not soft signals. They are quantified year-over-year improvements that survived the McKinsey methodology's scrutiny.
For executives setting AI direction in 2026, three strategic implications follow.
The first: the strategic AI plan must include an explicit RAI workstream with named ownership, not an implicit RAI assumption distributed across data, security, and legal functions. The data shows that organisations with explicit governance ownership produce better outcomes on the dimensions executives care about: operational efficiency, customer trust, incident frequency, business outcomes. Plans that defer RAI workstream definition to "we will figure it out as we deploy more AI" are operating against a baseline that no longer matches what the data shows is producing results.
The second: AI governance investment should be sized to the AI deployment exposure, not to a conservative compliance baseline. The largest enterprises are spending $25M–$50M on operationalising RAI. That includes hiring (specialised governance, security, and risk professionals), tooling (RAI evaluation, monitoring, and audit infrastructure), and legal services (regulatory navigation across jurisdictions). For organisations deploying AI at meaningful scale, under-investing in this layer creates a structural mismatch between deployment surface and governance capacity that produces the incidents the McKinsey data shows organisations are experiencing more frequently.
The third: the RAI conversation has moved from "should we have a policy?" to "how mature is our policy?" The McKinsey RAI maturity scale (1 foundational, 2 integrating, 3 fully-in-place, 4 comprehensive and proactive) shows a global average of 2.3. Most organisations are still in the integration phase. The strategic plan should articulate which maturity level the organisation is targeting over the next 24 months, what would have to be true to reach it, and how the progression is measured.
The prescription: re-anchor the strategic AI plan around an explicit RAI workstream with named ownership, budgeted investment at the scale the McKinsey data shows is now baseline for the organisation's revenue tier, and a stated maturity-level target with measurable interim milestones. The 2024-era strategic plan that treated RAI as a compliance afterthought is now operating below the median in the surveyed population. Plans built for the 2026 baseline will produce better outcomes on the dimensions that matter to the board: operational efficiency, customer trust, incident frequency, and business performance.
There is a longer view worth being explicit about. The 13-percentage-point drop in organisations without RAI policies in one year is unusual for governance metrics. Most governance practices spread over multi-year timelines. The acceleration in 2025 was probably driven by a combination of regulatory pressure (the EU AI Act phasing in, ISO/IEC 42001 publication, NIST AI RMF gaining adoption), insurance and audit pressure, and customer/partner expectations. Those drivers will continue. By 2027, the defensible planning anchor is that RAI policy adoption will be near-universal among meaningful AI deployers, governance ownership will consolidate further into named roles, and investment will continue to grow as a share of AI deployment cost. Plans that build for that trajectory will be aligned with where the survey data is heading; plans that do not will lag.
Sources
- Primary: Stanford AI Index 2026, Chapter 3 (Responsible AI) 3.3 — hai.stanford.edu/ai-index/2026
- Survey data: McKinsey & Company "State of AI" Survey, 2025 — second consecutive year, year-over-year comparison (survey does not include China, limiting geographic scope)
- Regulatory drivers: EU AI Act; ISO/IEC 42001:2023; NIST AI Risk Management Framework
Discussion