AI: where it stands, and what trusted adoption requires

Background for an exploratory discussion: the three waves of adoption, the five governance principles published for boards, the ten dimensions of trusted AI, and where the firm works across AI and technology.

Purpose: background for an introductory discussion on AI and technology: what is changing, what boards are being asked to oversee, and where KPMG works
Position as at: 12 August 2026
Scope: enterprise AI adoption and its governance. Sector examples are drawn from financial services. Regulatory references are illustrative and jurisdiction-specific
Status: illustrative working material for discussion. Not legal or regulatory advice

1. Where AI stands: three waves

Adoption has moved in three recognisable waves. The waves overlap and organisations sit across more than one of them at a time, so the question is not which wave an organisation has reached but where the weight of its investment currently sits.

WaveWhat it looks likeWhat the board was asked to do
One. Personal productivity Assistants and copilots in the hands of individuals. Research and drafting that took three or four days compressed into minutes. Value accrues to the person doing the work. Contain the downside. Keep organisational intellectual property from leaving through the tool, and limit the consequences if something went wrong.
Two. Process improvement AI inside a process rather than beside it. Automation in the back office, and prompts that support a service agent during a live interaction. Still human-led throughout. Make sure the opportunity is being taken, in a safe and controlled way. The emphasis moves from containment to capture.
Three. Agentic Systems that plan and act across other systems, with growing autonomy and several distinct types of agent. Most organisations are at the beginning of this. Decide what an agent may do without a person, and evidence that the limit holds.
Most organisations are still substantially in wave one, and that includes large professional firms. This is worth saying plainly because the gap between wave one spending and wave two or three language is common rather than exceptional. It is a shared starting position rather than a finding about any one organisation.

The language of containment from wave one persists, and it is still useful. The question asked then was how to limit the blast radius if something went wrong. In wave three that question returns with more force, because a system that acts can affect a record, a customer or a payment rather than only a draft.

2. What boards are being asked: the five principles

In April 2026 KPMG International and the INSEAD Corporate Governance Centre published a set of AI governance principles written for boards rather than for technologists. They are principles rather than rules, chosen deliberately because principles are more useful where situations are unclear and uncertain, and they are explicitly illustrative rather than mandatory standards or legally enforceable obligations.

The dilemmas fell into three perspectives. Principles 1 to 3 take the company view, principle 4 the ecosystem view, and principle 5 turns the board on itself.

1Strategic oversight for long-term value creationCompany view
What the principle says
The board oversees the development and execution of the AI strategy, and how it supports sustainable long-term value creation.
Its five sub-principles
  • 1.1 Sustainable long-term value creation with AI
  • 1.2 Responsible innovation
  • 1.3 Foundational investments
  • 1.4 Organisational flexibility and learning
  • 1.5 Transformation scope
What it means in a discussion
The dilemma named is capital allocation. Benefits require sizeable early investment in technology and data infrastructure, capability building and change management, at a point when returns are uncertain, against pressure to show short-term productivity gains. The source states that long-term value from AI will not derive solely from productivity gains, which is the sentence that reframes a licence budget as something other than a strategy.
Source: Principle 1 and sub-principles 1.1 to 1.5.
2Active technology and security oversightCompany view
What the principle says
The board actively oversees strategic AI technology choices and expects appropriate consideration of speed, cost, sovereignty, privacy, safety and security.
Its three sub-principles
  • 2.1 Deliberate AI capability ownership
  • 2.2 Well-managed vendor dependency
  • 2.3 AI safety and security
What it means in a discussion
Technology choices are not always board-level topics, but the source is direct that the setup of the stack, from data centres and cloud infrastructure to the choice of foundation models and proprietary or third-party data, has a major impact on cost, speed, quality and above all on the control an organisation has over its AI systems. Sovereignty is named as increasingly relevant, including whether an organisation can expect governmental support or restriction. Vendor dependency covers a vendor failing or being legally prevented from supplying, and several vendors on one project with no clear structure for liability if the AI fails. Sub-principle 2.3 names agentic misalignment alongside data poisoning, misinformation, privacy breach and cyber attack, and expects risk-based traceability and auditability including clear audit trails.
Source: Principle 2 and sub-principles 2.1 to 2.3.
3Workforce transformation and human accountabilityCompany view
What the principle says
The board expects management to develop clear guiding principles for AI adoption, and considers how the adoption strategy affects human capital, including the future role of humans relative to AI.
Its three sub-principles
  • 3.1 Defined and safeguarded quality of (human) decision-making
  • 3.2 Strategic workforce transformation and upskilling
  • 3.3 Appropriate long-term talent pipeline
What it means in a discussion
Sub-principle 3.1 is a control expectation carrying an HR label. Boards ask management to define which decisions must always involve meaningful human oversight, involvement or accountability, consistent with human-in-the-loop and human-on-the-loop concepts. On high-impact decisions, a higher degree of AI involvement is held to be appropriate only where outputs are explainable, auditable and aligned with risk appetite. It also expects the board to remain informed on where tools are being developed bottom up as well as top down. Sub-principle 3.3 reaches further than most expect, asking how entry-level roles and apprenticeships might evolve and what that means for the future labour market.
Source: Principle 3 and sub-principles 3.1 to 3.3.
4Building trustworthy AIWider stakeholders
What the principle says
The board expects management to proactively adopt standards for trustworthy AI reflecting the organisation's values and regulatory obligations, and to consider stakeholders and society at large.
Its five sub-principles
  • 4.1 Fair and inclusive AI solutions, processes and culture
  • 4.2 Safeguarded privacy, data usage and protection in AI solutions
  • 4.3 Impact on the physical environment
  • 4.4 Trustworthy AI
  • 4.5 Legally compliant AI
What it means in a discussion
Sub-principle 4.2 requires that data is legally obtained and its use permissioned and transparent, extending to suppliers, vendors, partners and regulators. Permissioned is the operative word, because retrieval tools inherit whatever access already exists. Sub-principle 4.4 asks for values to be translated into practice through technical design together with monitoring for learning practices, testing, output drift and incident management. Sub-principle 4.1 contemplates involving an objective external party where appropriate. Sub-principle 4.3 covers energy and water use, which matters where sustainability commitments and data centre decisions sit in the same organisation.
Source: Principle 4 and sub-principles 4.1 to 4.5.
5The work of the boardThe board itself
What the principle says
The board considers how AI affects its own governance practices, defines what effective AI oversight looks like, and adapts its structures and processes, particularly around oversight of risk management.
Its five sub-principles
  • 5.1 Appropriate oversight capabilities for AI and other emerging technologies
  • 5.2 Effective AI oversight processes
  • 5.3 AI tailored risk management
  • 5.4 Adherence to a globally diverse regulatory AI landscape
  • 5.5 Transparent and outcome-based reporting
What it means in a discussion
This is the only principle where the board acts rather than instructs, which makes it the most immediately actionable. The source observes that traditional linear ways of working may need adjustment, and that boards may revise structures and composition, committee mandates, review frequency, agenda time and the use of external expertise. Committee charters are named directly. Sub-principle 5.2 goes further and contemplates the board using AI itself, subject to clear guidelines on permissible use by directors and, where appropriate, a formal and legally vetted AI use policy for board members covering confidentiality and legal privilege.
Source: Principle 5 and sub-principles 5.1 to 5.5.
The evidence base. The principles drew on inputs from over 25 board members across the Americas, Europe and Asia, a steering committee of directors collectively serving on more than 25 boards, and an advisory council covering a further 22 organisations.

3. Trusted AI: the ten dimensions

The principles describe what a board should oversee. The Trusted AI framework describes the dimensions along which an AI system is judged trustworthy, and is applied across the KPMG network. It is the layer where a governance expectation becomes something that can be designed, tested and evidenced.

DimensionWhat it asks of a system
01AccountabilityA person remains answerable for the system at every stage of its life, and human oversight is designed in rather than assumed.
02TransparencyThose affected are told, appropriately, that AI is in use and what part it plays.
03ExplainabilityThe reasoning behind an output can be set out in terms the recipient can act on.
04FairnessBias against individuals or groups is looked for, measured and reduced.
05PrivacyPersonal data is used lawfully and no more widely than the purpose requires.
06ReliabilityPerformance holds at the accuracy claimed, consistently and over time.
07Data integrityThe data carries known quality, governance and provenance.
08SecurityThe system resists attack, manipulation and misuse.
09SafetyPeople and property are protected from harm the system could cause.
10SustainabilityEnvironmental cost is understood and contained.
How the two fit together. The principles are what the board asks for. Trusted AI is how management answers, because each dimension reduces to something that can be specified in a design, checked in a test and shown to an auditor. Several map directly: accountability and explainability to sub-principle 3.1, privacy and data integrity to 4.2, security and safety to 2.3, sustainability to 4.3.

4. What is seen in practice

Observations from adoption work rather than from a study. They are offered as a description of the common pattern, and no proportion is asserted for any of them.

What comes up repeatedlyWhy it happens
Wave one value is real and hard to evidence Time is released across many people in small amounts rather than removed from one process, so it does not appear in an operational number. Reported savings frequently turn out to have converted into prompting and small decisions.
The data foundation decides the outcome Unstructured, unclassified and inconsistent source material makes a pilot perform well on a prepared sample and poorly on live material. This is the least visible and most expensive part of the work, and it survives a change of model or vendor.
Permissions surface before anything else does Retrieval inherits existing access rights, so over-shared locations become searchable in plain language. The exposure pre-existed the tool and was simply harder to reach. It is checkable quickly, which is why it is usually the first thing to look at.
Ownership sits between functions Adoption falls between technology and the business, and a committee is appointed where an owner with budget authority is what the work needs.
Success was not defined before the pilot began Without a criterion set in advance, a pilot can neither fail nor graduate, and it continues being described as promising.
Agentic deployments are ahead of the controls Interest in agents is running well ahead of written limits on what an agent may do without a person, and ahead of the audit trail needed to show the limit held.

5. Where KPMG works

Grouped by the question being answered rather than by service line, and covering technology delivery as well as governance, since in practice the two arrive together. Nothing below is a proposal. Any engagement is scoped to the organisation's own position, and independence requirements are confirmed before scope is discussed where an audit relationship exists.

AKnowing where the organisation standsDiagnostic
What it covers
AI maturity and readiness assessment against a defined baseline; a use case portfolio scored for value, effort, risk and data readiness; an inventory of the AI systems, models and agents already in use, with owners and data reach.
Why organisations start here
The inventory is often the point at which the position becomes visible, because assembling it is more informative than the document that results. It also sets the baseline everything later is measured against.
Related principles: 1.1, 1.5, 5.5.
BGovernance, policy and riskFramework
What it covers
AI governance frameworks covering policy, standards, roles, risk appetite and approval gates; risk assessments for AI systems; extension of existing model risk management to generative and agentic systems; third-party and vendor AI assurance; data protection impact assessment; mapping to applicable regulatory requirements and, where a group has European exposure, forward mapping to the EU AI Act.
Why organisations start here
Extending an existing framework is usually faster and better adopted than building a parallel one, because the ownership and the reporting line already exist.
Related principles: 2.2, 4.5, 5.3, 5.4.
CAssurance over AI systemsEvidence
What it covers
Readiness for and support through ISO/IEC 42001 certification; pre-implementation review of a specific system before go-live; independent evaluation and adversarial testing of models and agents; monitoring for output drift and incident management; internal audit support where AI enters the audit plan.
Why organisations start here
Sub-principle 4.1 contemplates an objective external party where appropriate, and certification gives an external reference point that internal assurance cannot supply on its own.
Related principles: 4.1, 4.4, 2.3.
DThe foundation, and the peopleDelivery
What it covers
Data readiness: classification, lineage, quality, and remediation of permissions and over-sharing before retrieval is switched on. Alongside it, target operating model and centre of excellence design, role-based enablement, and board and executive education.
Why organisations start here
These are the foundational investments sub-principle 1.3 refers to. They are the least visible part of a programme and the part whose absence stops the rest from working.
Related principles: 1.3, 3.2, 5.1.
EBuilding and running the technologyDelivery
What it covers
Selection of platforms and models against cost, control and sovereignty requirements; design and delivery of the systems themselves, including agentic workflows; the cloud, data and integration work underneath them; and the cyber security of the resulting systems, which changes shape once systems begin acting rather than only answering.
Why it belongs in the same conversation
Sub-principle 2.1 treats the choice of stack as a board-level matter because it determines cost, speed, quality and the degree of control retained. Governance designed apart from the build tends to arrive after the decisions that mattered have been taken.
Related principles: 2.1, 2.2, 1.4.
A board session on the principles is the usual starting point. The principles were written to be worked through by a board rather than read, and a session on them carries no commitment and no prerequisite: it needs no access to systems, no data, and no prior assessment. Where a board wants to go further, the same material supports a review of committee mandates and a policy on directors' own use of AI, both of which sub-principle 5.2 contemplates directly.

6. Questions worth exploring

Openers rather than an agenda, and none of them expects a prepared answer. Each is a question worth thinking about aloud together, and several have no single right answer.

QuestionWhy it is worth the time
Position and ambition
Where does the weight of investment currently sit across the three waves, and where should it sit in twelve months? Separates the ambition from the spending. A gap between the two is common and is more useful named than left implicit.
Which single process would be worth taking properly into wave two? One process carried through produces an operational number. A portfolio of pilots usually does not.
Trust and control
Which decisions should always involve a person, and where is that written down? Sub-principle 3.1 asks the board to have this defined. It is a risk appetite question rather than a technical one.
Of the ten trusted AI dimensions, which two carry most weight in this sector, and how would they be evidenced today? Focuses a broad framework on the two that a regulator or customer would actually test.
What would a plain-language search across existing systems return that it should not? Quick to check, and it establishes whether the data and permissions foundation is sound before anything is built on it.
The board and its own work
Do committee mandates say who owns AI oversight? Principle 5 names charter revision directly, and it is a concrete step a board can take without waiting for anything else.
Is there a policy on directors' own use of AI, covering confidentiality and privilege? Sub-principle 5.2 contemplates one. Few organisations have it, and board papers are exactly the material where it matters.
What reporting would let the board see adoption, benefit and risk in one place? Sub-principle 5.5 expects systematic and transparent reporting, including explanations of major AI capital allocation decisions.

7. Sources and limitations

Sources

Known limitations