Back to blogAI Governance

    71% Started, 9% Arrived: What Happens in Between

    71% of large Italian companies have active AI projects, only 9% have structured governance (Osservatorio PoliMi, February 2026). Why the gap opens, what closes it, and what's at stake for whoever stays in the middle.

    ZeroFive.AI August 28, 2026 5 min

    71% of large Italian companies have active AI projects, only 9% have reached structured governance (Osservatorio Artificial Intelligence, Politecnico di Milano, February 2026). The gap between those two numbers doesn't describe companies running late. It describes companies that started, in many cases started well, and stalled somewhere in the middle, where AI produces activity without yet producing a system.

    Italy's national statistics office tells the same story from another angle: in 2024, 8.2% of Italian enterprises had adopted AI technologies, against a European average of 13.5%. This isn't a problem of curiosity or available budget, Italy invests, experiments, launches pilots across every sector. It's a problem of what happens after the first project, when the enthusiasm of getting started meets the absence of a method for governing what comes next.

    Employee AI arrives before the policies meant to cover it

    An analysis published in May describes a pattern we see with striking regularity in our own assessments: the AI tools employees use every day move faster than the policies meant to govern them. People looking for a faster way to write a report, summarize a contract, or prepare a deck find it in a tool the company has never evaluated, often without the company even knowing.

    The case cited most often is still Samsung in 2023: employees, trying to speed up their own work, uploaded proprietary source code into a public chatbot, with no intention of causing harm, simply because the tool worked and nobody had said no. Three years later the scenario has multiplied rather than shrunk, more tools available, more employees used to working outside the corporate perimeter, and a gap between informal adoption and formal governance that in many organizations looks exactly the same as before.

    The 71% measures initiative, the 9% measures control

    The two Osservatorio numbers aren't in tension, they measure different things. The 71% counts anyone who has started something, a pilot, a project in one department, an agreement with a vendor. The 9% counts those who know, with verifiable evidence rather than the feeling of having done it, where those systems are in use, who owns them, what risks they carry and how often they get checked.

    In our AI Rating this distance almost always maps to a precise pattern: strong scores on Readiness and Confidence, because the company is eager to innovate and management believes in it, and a weak score on Risk, the dimension that measures compliance, risk management, and the existence of a register of AI systems in use. It's a critical gate, non-compensable, technical excellence elsewhere doesn't offset it. A company that innovates with enthusiasm but can't list its own AI systems stays stuck in class C, regardless of how advanced it looks on paper.

    What separates the companies that close the gap

    Organizations that move from the 71% to the 9%, that turn scattered initiative into real governance, share one specific move: they stop treating every AI project as a case of its own and build a single register, one place where every system in use gets mapped with the same level of detail, who activated it, what data it touches, what risk level it carries under the AI Act's classification, who is accountable if something goes wrong.

    This step doesn't necessarily require more budget. It requires an organizational decision, often taken at board level, that AI stops being managed department by department and becomes a single chapter of corporate governance, with a named owner and a periodic review process. Companies that get there earlier do so because they measured their actual situation instead of assuming it, and measurement, almost always, is the first step that's missing.

    The risk of staying in the middle

    Staying in the 71% without moving toward the 9% isn't a neutral position, it's a risk that compounds over time. Every month that passes without a register of AI systems in use adds to the number of unmapped tools, and with Italy's decree adding artificial intelligence to the predicate offenses under Legislative Decree 231/2001 nearing final publication, the distance between informal adoption and an adequate organizational model stops being a matter of efficiency and becomes a matter of legal exposure for the company itself.

    The question worth asking before the gap widens further is easy to phrase and uncomfortable to answer honestly: if a regulator, a board, or a court asked today for the complete list of AI systems in use, with risk level and owner attached, would that list already exist, or would it have to be built from scratch in a hurry.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI adoption#AI Governance#AI maturity#shadow AI#Osservatorio AI
    Share

    Keep reading