Metricstream Logo
×
Blogs

AI in GRC: Results of Our OCEG/MetricStream GRC Practitioner Poll 2026

AI in GRC- Results of Our OCEG
5 min read

Introduction

I regularly ask GRC leaders the same question: are you using AI yet, or are you still watching from the sidelines? For a while, most answers landed in the "watching" camp. That's changing now, and it’s happening faster than I expected.

To get even more insight into this area, we at MetricStream teamed up with Open Compliance and Ethics Group (OCEG) recently on a brief poll. We asked GRC professionals three things:

  • Are you using AI? 
  • How confident are you in it? 
  • Where are you applying it?

And finally – what would increase your confidence?

You’re correct – that’s four things! But on the fourth, we were looking for verbatim comments for added insight. And we got them!

More than 100 leaders responded. The results tell a clear story about where this industry stands today – a quickly changing picture.

infographic

What the Data Shows

Let's start with adoption.

  • 42.7% of respondents are actively using AI in their GRC program today.
  • Another 33.7% are exploring or evaluating it.
  • Only 23.6% haven't started.

Add the first two numbers together, and you get 76.4% of GRC professionals who've moved past ‘should we’ and into ‘how.’ This is no longer a niche trend. That's the majority.

Confidence tells a related but separate story.

60% of respondents feel at least somewhat confident in AI for GRC, split between 27.8% "very confident" and 32.2% "somewhat confident."

Only 11.1% land on the unconfident side.

The number that stood out to me the most, though, is that people already using AI are more than three times more likely to feel very confident in it (44.7%) than people still exploring (13.3%). This tells us that confidence isn’t gained from reading about AI. It comes from putting it into action.

Are you as struck by that finding as I was? Of course, the proof is in the pudding and all those cliches, but considering the fear we sometimes hear around AI, it’s encouraging to hear the reality is exceeding expectations.

So where is AI being applied?

Interesting, our poll didn't find a single runaway use case.

Regulatory compliance and emerging AI law led at 53.9%, followed closely by information summarization (50.6%), risk assessment and compliance risk management (both 49.4%), risk monitoring (47.2%), risk intelligence (41.6%), cyber risk management (40.4%), and third-party risk management (37.1%).

Every one of these sits within 17 points of the top spot. GRC professionals aren't picking a single AI use case and stopping there. They're spreading it across the whole function.

That tells me they are approaching AI as they do modern GRC – as a unified, connected discipline.

Finally, let’s get to those verbatim comments and insights. What would make people more confident in AI?

Six themes came back loud and clear:

  • Transparency and explainability
  • Governance frameworks and regulatory clarity
  •  Accuracy and reliability
  • Training and practical guidance
  •  Human oversight and control
  •  Data security and confidentiality

One respondent put it much better than I ever could:

“AI should operate 'not as it wishes, but as I intend it to operate.”

That speaks volumes about the intersection of humans and AI, and the importance of GRC leaders directing our machine assistants.

Where We See This Heading

If adoption keeps tracking the way this poll suggests, our explorers won't stay in exploration mode much longer.

A third of the market is already leaning in, and the data shows their confidence catches up fast once they start using the technology. I'd expect a good chunk of that 33.7% to move into the confident column within the next year, not because vendors convince them, but because hands-on use closes the confidence gap on its own.

The use case spread tells us something important too, AI in GRC isn't a point solution. It's becoming infrastructure.

Regulatory compliance leading the list makes sense against a live backdrop. The EU AI Act's general application and new transparency obligations took effect on August 2, 2026, even as some high-risk provisions were pushed back to December 2027. Regulatory compliance isn't a hypothetical use case here. It has a hard deadline attached to this year. And, that seven different use cases cluster within a tight 17-point range shows organizations weaving AI into how they manage risk across the board, rather than inside one workflow.

The confidence-builder list is what I’d pay closest attention to as a GRC leader building a business case. None of the six themes that emerged is about AI capability. They're about trust. Can I see how it reached this conclusion? How can I govern it? How can I rely on it being accurate? Does my team know how to use it? Is my data safe?

What This Means for GRC Leaders

If you're in the 23.6% who haven't started with AI, the data suggests the risk of waiting is starting to outweigh the risk of moving. Your peers who are already using AI report meaningfully higher confidence because using the tool is what builds trust in it.

If you're in the exploring group, the six confidence-builder themes are your evaluation checklist. Ask any vendor how they handle explainability, how governance and human oversight work, and how they benchmark accuracy. If they can't answer clearly, that's your answer.

And if you're already using AI in GRC, the breadth of use cases here is your invitation to expand. If you started with information summarization, look at what compliance risk management or third-party risk management could add. The data show AI works best as a horizontal capability, not as a single tool bolted onto a single process.

The industry has answered the "should we" question. Now we're all working through the "how," together.

Where do you stand? I’d love to hear your views! Feel free to reach out to me at pmcparland@metricstream.com, and let us know if you’d like to learn more about how MetricStream is applying AI across our GRC platform.

Curious what Reimagining GRC with AI could look like for your organization? Request a personalized demo today.

Pat McParland

Patricia McParland VP – Marketing

Pat McParland is VP of Product Marketing at MetricStream. She is responsible for creating product messaging, product go-to-market plans, and analyzing market trends for MetricStream's cyber compliance and third party risk product lines. Pat has more than 25 years of financial data and technology marketing experience at Fortune 1000 brands as well as startups and has led product and marketing teams at Dow Jones and Dun & Bradstreet. She has a BA from the College of William and Mary and lives in Summit, New Jersey.