I regularly ask GRC leaders the same question: are you using AI yet, or are you still watching from the sidelines? For a while, most answers landed in the "watching" camp. That's changing now, and it’s happening faster than I expected.
To get even more insight into this area, we at MetricStream teamed up with Open Compliance and Ethics Group (OCEG) recently on a brief poll. We asked GRC professionals three things:
And finally – what would increase your confidence?
You’re correct – that’s four things! But on the fourth, we were looking for verbatim comments for added insight. And we got them!
More than 100 leaders responded. The results tell a clear story about where this industry stands today – a quickly changing picture.
Let's start with adoption.
Add the first two numbers together, and you get 76.4% of GRC professionals who've moved past ‘should we’ and into ‘how.’ This is no longer a niche trend. That's the majority.
Confidence tells a related but separate story.
60% of respondents feel at least somewhat confident in AI for GRC, split between 27.8% "very confident" and 32.2% "somewhat confident."
Only 11.1% land on the unconfident side.
The number that stood out to me the most, though, is that people already using AI are more than three times more likely to feel very confident in it (44.7%) than people still exploring (13.3%). This tells us that confidence isn’t gained from reading about AI. It comes from putting it into action.
Are you as struck by that finding as I was? Of course, the proof is in the pudding and all those cliches, but considering the fear we sometimes hear around AI, it’s encouraging to hear the reality is exceeding expectations.
So where is AI being applied?
Interesting, our poll didn't find a single runaway use case.
Regulatory compliance and emerging AI law led at 53.9%, followed closely by information summarization (50.6%), risk assessment and compliance risk management (both 49.4%), risk monitoring (47.2%), risk intelligence (41.6%), cyber risk management (40.4%), and third-party risk management (37.1%).
Every one of these sits within 17 points of the top spot. GRC professionals aren't picking a single AI use case and stopping there. They're spreading it across the whole function.
That tells me they are approaching AI as they do modern GRC – as a unified, connected discipline.
Finally, let’s get to those verbatim comments and insights. What would make people more confident in AI?
Six themes came back loud and clear:
One respondent put it much better than I ever could:
“AI should operate 'not as it wishes, but as I intend it to operate.”
That speaks volumes about the intersection of humans and AI, and the importance of GRC leaders directing our machine assistants.
If adoption keeps tracking the way this poll suggests, our explorers won't stay in exploration mode much longer.
A third of the market is already leaning in, and the data shows their confidence catches up fast once they start using the technology. I'd expect a good chunk of that 33.7% to move into the confident column within the next year, not because vendors convince them, but because hands-on use closes the confidence gap on its own.
The use case spread tells us something important too, AI in GRC isn't a point solution. It's becoming infrastructure.
Regulatory compliance leading the list makes sense against a live backdrop. The EU AI Act's general application and new transparency obligations took effect on August 2, 2026, even as some high-risk provisions were pushed back to December 2027. Regulatory compliance isn't a hypothetical use case here. It has a hard deadline attached to this year. And, that seven different use cases cluster within a tight 17-point range shows organizations weaving AI into how they manage risk across the board, rather than inside one workflow.
The confidence-builder list is what I’d pay closest attention to as a GRC leader building a business case. None of the six themes that emerged is about AI capability. They're about trust. Can I see how it reached this conclusion? How can I govern it? How can I rely on it being accurate? Does my team know how to use it? Is my data safe?
If you're in the 23.6% who haven't started with AI, the data suggests the risk of waiting is starting to outweigh the risk of moving. Your peers who are already using AI report meaningfully higher confidence because using the tool is what builds trust in it.
If you're in the exploring group, the six confidence-builder themes are your evaluation checklist. Ask any vendor how they handle explainability, how governance and human oversight work, and how they benchmark accuracy. If they can't answer clearly, that's your answer.
And if you're already using AI in GRC, the breadth of use cases here is your invitation to expand. If you started with information summarization, look at what compliance risk management or third-party risk management could add. The data show AI works best as a horizontal capability, not as a single tool bolted onto a single process.
The industry has answered the "should we" question. Now we're all working through the "how," together.
Where do you stand? I’d love to hear your views! Feel free to reach out to me at pmcparland@metricstream.com, and let us know if you’d like to learn more about how MetricStream is applying AI across our GRC platform.
Curious what Reimagining GRC with AI could look like for your organization? Request a personalized demo today.
Subscribe for Latest Updates
Subscribe Now