Intelligence

Gartner Tells Chief Audit Executives What Their AI Governance Actually Lacks

Gartner's new practical guide for chief audit executives finds that most audit leaders now name AI governance a top priority for 2026, and that most of them do not feel ready to address it. The guide names limited visibility into deployed AI as the assurance risk underneath that gap, and recommends evidence generated during the work itself rather than reconstructed once someone asks for it.

Event analysed: . This analysis was published on 12 September 2026.

What does Gartner's Audit AI guide for chief audit executives establish about the gap between audit leaders naming AI governance a priority and feeling ready to address it?

Gartner published Audit AI: A Practical Guide for CAEs on 9 September 2026. The guide reports that 83 percent of audit leaders identify AI governance as a priority for 2026, while only 34 percent are confident they can actually address it. Gartner names limited visibility into deployed AI as a major assurance risk sitting underneath that confidence gap, and its recommended direction has four parts: build a current AI inventory, assess risk per deployment rather than generically, integrate controls into the workflows the AI actually runs in, and generate audit ready evidence during the work itself rather than reconstructing it afterward when an auditor asks. Gartner's own material, as supplied to this record, does not attach a named evidence taxonomy, such as provenance, evaluation, policy enforcement and secure orchestration, to these findings. Where that four part framing appears in secondary commentary, it is that commentator's own gloss, not a Gartner finding, and this record keeps the two separate rather than presenting one as the other.

Gartner's own numbers are the useful part of this guide, more than any individual recommendation. Eighty three percent of audit leaders already name AI governance a priority for 2026. Only thirty four percent believe they can actually address it. That is not a gap between interest and execution in the ordinary sense of a new initiative outrunning its budget. It is a gap between what audit functions have decided matters and what they currently believe they are equipped to assure.

What Gartner names as the risk underneath the gap

Gartner's guide, as supplied to this record, identifies limited visibility into deployed AI as a major assurance risk. That is worth reading precisely. The claim is not that AI systems are unsafe, or that controls are absent. It is narrower and, for an audit function, more immediate: the assurance function often cannot see what AI is actually running, where, and under whose ownership, and that absence of visibility is itself the exposure Gartner asks chief audit executives to treat as a priority.

A function cannot assure what it cannot see. Gartner's finding is not that deployed AI is failing its controls. It is that audit leaders frequently do not have a reliable view of what AI is deployed at all, which means the question of whether controls exist and hold cannot yet be answered with confidence.

The recommended direction

Gartner's recommended direction, as supplied to this record, has four parts. Build and maintain a current inventory of the AI actually in use. Assess risk per deployment rather than through one generic AI risk rating applied across every use case. Integrate controls into the workflows the AI runs in, rather than layering review on top of them afterward. And generate audit ready evidence during the work itself, rather than reconstructing it once an auditor or a regulator asks what happened.

That last point is the one this record finds most durable, because it names a distinction Moona Intelligence has tracked across a separate line of evidence this year: the difference between a record produced while something is happening and a record assembled afterward from whatever happens to survive. Gartner is making that same distinction from the audit profession's own side. Evidence reconstructed after the fact depends on whatever logs, tickets, and memories happen to still exist by the time someone goes looking. Evidence generated during the work does not have that dependency, because it was captured as the work occurred rather than recovered from it later.

What this record does not adopt

A secondary commentary circulating alongside this Gartner guide proposes its own four part evidence taxonomy: provenance, evaluation, policy enforcement, and secure orchestration. That taxonomy belongs to whoever wrote that commentary, not to Gartner. Gartner's own material, as supplied to this record, is not shown stating that taxonomy or endorsing it, and this record does not attribute it to Gartner or treat it as part of Gartner's findings. The distinction matters for the same reason every unverified attribution matters to this desk: a genuinely useful analytical frame from one source should never be allowed to borrow the authority of a different, better known source it happens to have been published alongside.

Why this strengthens, and also bounds, Moona's own thesis

Gartner's guide is real market evidence that the assurance function itself, not only security teams or engineering, has converged on the same underlying problem this record has tracked from the technical side: knowing what an autonomous system did requires evidence that exists because it was captured at the time, not evidence assembled afterward from whatever is left. That convergence is worth taking seriously. An internal audit function reaching the same conclusion as security researchers and standards drafters, from a completely different professional discipline and a completely different set of incentives, is a stronger signal than either voice alone.

It is also worth being precise about what Gartner's guide is evidence for, and what it is not. An inventory of deployed AI answers what AI exists. It does not, on its own, answer the question this record exists to keep separate: whether a specific consequential action, attempted by a specific agent, under a specific delegation, in a specific context, was actually authorized when it happened, and what evidence supports that it was. Gartner's own recommended direction, read carefully, points toward exactly that separation without collapsing it. An inventory and a deployment specific risk assessment are visibility work. Controls integrated into the workflow and evidence generated during execution are the beginning of the authority and evidence layer this record has argued for all year. Gartner's guide is strong practitioner side evidence that the second half of that pair is now recognized as necessary by the profession whose job is to assure it, not a reason to fold Moona's own scope into a general AI inventory or audit platform.

Connected Knowledge assessment

Intelligence: CREATE. This is new, verified market evidence that the internal audit profession has named limited visibility into deployed AI a major assurance risk, with a specific confidence gap (83 percent priority, 34 percent confident) and a four part recommended direction, distinct from and not previously held by this corpus.

Records: CONNECT and UPDATE. No equivalent canonical record exists for this specific audit profession survey. The canonical record for AI execution visibility and audit ready execution evidence already held by this corpus is agent-evidence-layer, which tracks the same evidence generated during execution versus evidence reconstructed afterward distinction from the security and standards side. This signal is connected there as a new, independently sourced data point corroborating that record's own thesis from the internal audit profession, and that record is updated accordingly rather than a second parallel record being created.

Risks: CONNECT. This signal is evidence backed corroboration for AEW-011, evidence after the fact mistaken for authorization before it, specifically its own stated authority gap that authorization is a decision made before an action while evidence is a record made after it. Gartner's own recommendation, evidence generated during work rather than reconstructed afterward, is independent practitioner evidence for that same corrective from a discipline outside security research. No new weakness is warranted: the pattern Gartner names is not materially distinct from the one AEW-011 already states.

Protocols: CONNECT. This signal supports the black-box-agentic-processes-arxiv-2609-04017 protocol record's own grc-audit-use-framed-as-post-hoc-not-preventive property, which frames blockchain anchored agent evidence as governance, risk and compliance and regulatory reporting readiness infrastructure rather than a preventive control. Gartner's guide is independent, non technical, practitioner side evidence that the audit profession itself already frames its own evidence need the same way: necessary for assurance, and not a substitute for a pre execution authorization decision.

Sources

This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.

[1]
Audit AI: A Practical Guide for CAEs
Gartner · 9 September 2026 · Research

Protocol evidence

This record does not assess these architectures. The connection runs through the Risk Registry requirement each one bears on, and these published authority architectures are what the evidence says about that requirement.

Protocol evidence related through AEW-011 Evidence after the fact mistaken for authorization before it

  • Supports requirement

    A Black Box for Agentic Processes

    Arslan Bromme (independent research, arXiv preprint)

    Requirement The paper's own evidence model separates temporal anchoring and artifact integrity from event ordering, capture authenticity, authorized anchoring and causal traceability

    This weakness's own authority gap states that evidence made after an action is not the authorization decision made before it. This paper's own evidence model draws a closely related separation from a different starting point, stating directly that digest verification establishes only that a retained artifact matches a prior commitment, not that the underlying event was captured completely or faithfully, occurred in the order a chain of anchors implies, was anchored by an authorized party, or is true. It supports the requirement that a Moona reasoning surface never let evidence integrity alone stand in for authorization or captured truth, rather than implementing an enforced version of that separation, since the paper itself proposes no mechanism that checks these properties against each other.

    View protocol evidence

  • Supports requirement

    A Black Box for Agentic Processes

    Arslan Bromme (independent research, arXiv preprint)

    Requirement Anchoring or timestamp order between two committed events is explicitly not treated as proof of causal or workflow order

    This weakness already treats a record made after an action as distinct from authorization of that action; this property extends the same discipline to a narrower claim this weakness's own known examples had not yet named directly, that the order in which two events are anchored or timestamped reflects anchoring and confirmation mechanics rather than the causal order of the underlying workflow. It supports requiring an explicit dependency link before an anchored or timestamped order is read as proof that one recorded action caused or authorized another.

    View protocol evidence

  • Supports requirement

    A Black Box for Agentic Processes

    Arslan Bromme (independent research, arXiv preprint)

    Requirement The paper frames its use for governance, risk and compliance evidence, incident reconstruction and regulatory reporting readiness, not as a preventive control

    This property frames blockchain anchored agent evidence as governance, risk and compliance and regulatory reporting readiness infrastructure, not a preventive control, the same record versus gate separation this weakness already states as its own authority gap. Gartner's Audit AI: A Practical Guide for CAEs, published 9 September 2026, is independent, non technical, practitioner side evidence that the internal audit profession names the identical need from its own side: it reports a gap between audit leaders who name AI governance a 2026 priority (83 percent) and those confident they can address it (34 percent), names limited visibility into deployed AI as the assurance risk underneath that gap, and recommends audit ready evidence generated during work rather than reconstructed afterward. That recommendation supports this property's own post hoc, not preventive framing without establishing that any specific construction satisfies it.

    This record is the cited evidence for this relationship.

    View protocol evidence

  • Supports requirement

    Agent Infrastructure Control Protocol (AICP)

    Tihan-Nico Paxton, Apollo Deploy (individual submission to the IETF)

    This weakness's own corrective principle keeps a decision record produced before execution separate from a log produced after it, and forbids treating prose as the control. AICP's own Section 5.5 states directly that a client must not treat prose as authorization, executable instructions, a replacement for a stable code, or a reason to violate a structured constraint, and Section 12.1 restates the same discipline for a Problem's own human readable detail member specifically, stating that a client bases retry and recovery decisions on the stable code and structured fields, not the prose. Section 11.3 extends the same separation to evidence itself: access to an Evidence Reference must be independently authorized and must not be granted merely because a client can read an Outcome. Recorded as design evidence for the requirement this weakness already states across its whole object model, not as a claim that any provider has implemented this draft's text.

    View protocol evidence

  • Supports requirement

    An Architecture for Auditing Agent Delegation and Interactions (audit-architecture)

    Mirja Kuehlewind (Ericsson) and Henk Birkholz (Fraunhofer SIT), individual submission to the IETF

    Requirement Auditability is built from four separate record classes rather than one undifferentiated log

    This weakness's own corrective principle requires a decision record produced before execution to be kept separate from a log produced after it, and treats audit evidence and authorization as separate obligations. The draft's own four record classes are exactly that separation made structural rather than left to convention: an Action Record documents that a tool or service call took effect, and an Authorization Transition Record, a distinct class with its own ordered previous-state/new-state sequence, is what actually tracks whether that effect was authorized. Recorded as design evidence for the weakness's own principle, not as a claim that any implementation of this record model exists outside the draft's own text.

    View protocol evidence

  • Supports requirement

    An Architecture for Auditing Agent Delegation and Interactions (audit-architecture)

    Mirja Kuehlewind (Ericsson) and Henk Birkholz (Fraunhofer SIT), individual submission to the IETF

    Requirement The draft states directly that this architecture is post-hoc auditing, not session management and not enforcement

    This weakness names the confusion between an audit record and a pre-execution control directly: presenting an after-the-fact record as if it governed the decision leaves the actual decision ungoverned. Revision 01 of the draft states, in its own words, that the architecture it describes is post-hoc and is not a session or context-management mechanism, a first-party statement of exactly this weakness's own boundary rather than an implicit assumption a reader has to supply.

    View protocol evidence

  • Supports requirement

    EP Authorization Receipts (EMILIA Protocol)

    Iman Schrock, EMILIA Protocol, Inc., individual submission to the IETF

    Requirement The draft states directly that a receipt is evidence, not authorization, and that it does not treat a local human interaction as an authorization decision

    EMILIA states directly that a receipt is evidence, not authorization, and that the decision remains with the authorization server. That is the exact line this weakness says products blur when they present an audit archive as a control.

    View protocol evidence

Related Intelligence

All Intelligence Records →