Summary
- FTI surveyed 1,600 senior decision-makers and found 60% said their company had slowed, paused, or pulled back a planned AI deployment during the previous year.
- Cybersecurity was cited among the biggest AI risks by 60%, while 54% identified employee use of unapproved AI tools as a major concern for 2027.
- Governance remains relatively young, with 41% saying their framework was established within the previous year and only 17% reporting one more than two years old.
Large companies are slowing some artificial-intelligence deployments as cybersecurity, regulation, and trust catch up with the pace of experimentation, according to new research from FTI Consulting across the UK, continental Europe, Ireland, and the United States.
The survey of 1,600 senior business decision-makers found 60% said their organisation had slowed, paused, or pulled back a planned AI deployment during the previous year because of reputational, regulatory, or trust concerns. The result does not show companies abandoning the technology, but it does suggest that the path from pilot to routine production is encountering controls that were easier to ignore during the earlier phase of experimentation.
Cybersecurity was among the largest AI-related risks identified by 60% of respondents, while 54% said employee use of unapproved AI systems — commonly described as shadow AI — was a major concern for 2027. Regulatory uncertainty was also widespread, with 81% saying unclear AI rules had created material issues for their organisation.
The research covers senior respondents working at large companies in the UK, France, Spain, Germany, Belgium, Ireland, and the US, with average annual company turnover reported at £1.5 billion. It was conducted online between 5 and 11 August, so its findings describe the perceptions of executives at large organisations rather than the entire business population.
AI controls are younger than AI ambitions
One of the more revealing findings concerns how recently many companies built their governance structures. FTI reports that 41% of respondents’ organisations established their AI governance frameworks less than a year ago, while only 17% had frameworks more than two years old.
That means many businesses are trying to govern production technology with processes created after adoption had already begun. Teams may have started with public generative-AI tools, software vendors then added copilots to existing products, and departments introduced specialist models before a central organisation decided how systems should be approved, monitored, or retired.
Governance therefore has to catch an estate that is already moving. Inventories of approved systems can become outdated, while model providers change capabilities, employees discover new tools, and applications gain access to more corporate data or the ability to take actions through connected software.
Techopia examined that operational shift last week when LatticeFlow turned continuous AI assessment into a managed governance service. The growth of that supplier category reflects the same underlying pressure captured in FTI’s survey: organisations need continuing controls around live systems rather than policies written once during procurement.
Shadow AI exposes an adoption contradiction
Employee use of unapproved tools illustrates why simply slowing official deployments does not necessarily reduce exposure. Staff can adopt public AI services independently when sanctioned alternatives arrive slowly or do not meet a particular need, creating data-handling and security risks outside the visibility of technology and compliance teams.
Blocking every external tool is difficult, particularly where AI functionality is being added to ordinary search, productivity, design, coding, browser, and communications products. Organisations therefore need controls that distinguish acceptable use from activity involving confidential data, regulated information, customer records, software repositories, or credentials.
Cybersecurity concerns extend beyond employees pasting sensitive information into chatbots. Agentic software can connect models to email, codebases, customer systems, databases, cloud services, and other applications, which means identity and permissions become part of AI governance once the system can take action rather than merely generate text.
Those controls create friction by design. An AI pilot can look productive when a small team is allowed to experiment freely, whereas production deployment brings identity management, data classification, legal review, testing, monitoring, audit logs, incident handling, procurement, employee training, and change management into the programme.
Europe adds regulatory variation
FTI’s survey also captures the difficulty of operating across different regulatory environments. The EU AI Act applies requirements according to the type of system and role of the organisation, while privacy law, employment rules, sector regulation, cybersecurity obligations, and national guidance can create additional controls around a deployment.
Respondents in different European markets emphasised different remedies. FTI reports that greater investment in AI safety and skills attracted particular support among Spanish respondents, while mandatory AI-risk disclosure ranked strongly in Ireland and Belgium, and respondents in France placed comparatively greater emphasis on clear liability rules when AI fails.
Those differences should not be treated as national consensus because the market samples are limited to 250 respondents in most countries and 100 in Ireland. They are more useful as evidence that organisations are wrestling with several categories of uncertainty at once rather than confronting one uniform barrier called regulation.
The broad result is consistent with an enterprise market moving from experimentation into operating discipline. The first wave of generative AI could be funded as innovation, while production systems have to justify access to data, fit inside cyber controls, survive procurement, produce measurable benefits, and establish who is accountable when an output or action is wrong.
Slower deployment can therefore indicate failure, but it can also indicate that an organisation has begun applying the same scrutiny to AI that it applies to other systems capable of affecting customers, money, data, or operations. The distinction depends on whether projects are being paused because the technology lacks value or because the surrounding controls are finally becoming real.
FTI’s findings cannot establish which explanation applies to every organisation in the sample, and the research was published by a consultancy with a commercial interest in risk and communications work. Even with that limitation, the numbers describe a market in which enthusiasm has encountered the less glamorous machinery of implementation.












