A new McKinsey survey of roughly 500 organizations finds that responsible AI practices are struggling to keep pace with how quickly companies are deploying generative and agentic AI systems. The 2026 AI Trust Maturity Survey, conducted between December 2025 and January 2026, measured organizations across five dimensions: strategy, risk management, data and technology, governance, and a new agentic AI governance category.
The average responsible AI maturity score rose to 2.3 in 2026 from 2.0 the year before, but only about 30 percent of organizations reached a maturity level of three or higher in strategy, governance, and agentic AI controls specifically. That gap matters because nearly two-thirds of respondents cite security and risk concerns, not technical limits or regulation, as the top barrier keeping them from fully scaling agentic AI across their operations.
Risk awareness is not translating into action at the same pace. Seventy-four percent of respondents flagged inaccuracy and 72 percent flagged cybersecurity as highly relevant risks, yet the survey found a consistent gap between the risks organizations recognize and the ones they are actively mitigating, particularly around intellectual property and personal privacy.
Investment appears to make a measurable difference. Organizations that put $25 million or more into responsible AI initiatives reported significantly higher maturity scores and were far more likely to report an EBIT impact above 5 percent from their AI programs. Roughly 8 percent of organizations reported an AI-related incident in the past year, a figure that has held steady even as adoption accelerates.
Source: McKinsey and Company - https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era
