Stronger AI Governance Without More Case-by-Case Approval: What PwC's 2026 Study Suggests
Moving toward greater AI autonomy usually means reducing steps that require human sign-off. Does that mean governance must be loosened? PwC's study offers a useful lens for examining where controls should sit.
AI autonomy is often framed as a trade-off. Remove human approval steps, and governance appears to weaken; add more controls, and the work appears to slow down.
That framing is too narrow. Routing every decision through human review is not the same as governing AI.
Another model is to define the delegated scope in advance, implement standard controls, monitor production systems for anomalies, and escalate only high-risk cases or exceptions.
In PwC’s 2026 AI Performance Study, published in April 2026, companies with the strongest AI-driven results had a higher share of respondents reporting an increase in decisions made without human intervention. The same group also had higher shares reporting a documented Responsible AI framework and a cross-functional AI governance board.
A single survey cannot establish causation. It nevertheless provides a useful basis for asking whether autonomy and governance are truly an either-or choice.
Case-by-Case Approval Is Not the Same as Governance
Before going further, it is worth separating two things that are easily conflated.
Having a person approve every case is one form of control, and only one. Beyond case-by-case approval, AI governance can include:
- deciding in advance which use cases may run autonomously
- classifying prohibited and high-risk uses
- providing standard implementation templates
- enforcing access rights and operational limits within the system
- monitoring quality and detecting deviations in production
- escalating only high-risk cases and exceptions to a cross-functional governance body
- defining shutdown, recovery, and accountability procedures
Adding more case-by-case approval, on its own, does slow the work down. These other elements, though, are the foundation for deciding how far you are willing to delegate in the first place.
Governance and autonomy, in other words, do not necessarily move in opposite directions. How they move depends on where the controls sit.
What the PwC Study Measured and Who It Surveyed
Before interpreting the figures, it helps to clarify what the study actually measured, since isolated numbers are easy to misread.
By PwC’s account, the survey covered 1,217 senior executives, all at director level or above, primarily at publicly listed companies (91% of the sample) with US$1 billion or more in revenue (76% of the sample), across 25 sectors. Fieldwork was conducted in October and November 2025. The findings therefore primarily reflect the experience of large enterprises.
PwC also created a measure it calls “AI-driven performance,” based on the revenue gains and efficiency improvements or cost reductions that respondents attributed to AI, adjusted for differences across sectors. That makes it an analysis grounded in survey responses from senior executives, rather than a figure derived from audited financial statements alone.
The survey also covered 60 practice areas related to how companies manage and invest in AI. PwC grouped those practices into nine factors across two categories — AI use, and the AI foundations that support it — and says those categories make up its AI fitness index.
PwC’s materials use two different groupings. Companies with the strongest AI-driven financial performance are called AI leaders. Separately, PwC identifies the top 20% of companies on its AI fitness index and reports that this group achieved 7.2 times the AI-driven performance of all other companies. In what follows, the group PwC calls AI leaders — companies with the strongest AI-driven financial performance — is referred to as top performers.
Both Autonomy and Governance Appear More Often Among Top Performers
Start with the autonomy figures.
PwC asked respondents to what extent their company’s full AI portfolio had improved a set of outcomes. The published results report only the share answering “to a very large extent” or “to a large extent.” On the item covering an increased number of decisions made without human intervention, 56% of top performers gave one of those two answers, against 20% of other companies. The share among top performers was therefore 2.8 times as high as that among other companies.
Respondents were separately asked which of a set of options best described their organization’s most sophisticated use of AI. Among top performers, 31% selected “executes multiple tasks within guard rails,” compared with 17% of other companies. For “autonomous and self-optimising,” the figures were 15% and 8%.
The second of those deserves attention. Even among top performers, only 15% describe their most sophisticated use of AI as “autonomous and self-optimising.” The study does not show that full autonomy has become standard practice.
Now the governance figures. These come from a separate question asking to what extent each statement applied to the respondent’s organization. PwC again reports only the shares answering “to a large extent” or “to a very large extent.”
For the statement “a documented Responsible AI framework guides my organisation’s AI strategy, including use case selection, design, deployment, and ongoing monitoring,” 64% of top performers said the statement applied to their organization to a large or very large extent, compared with 39% of other companies. For the statement “a cross-functional AI governance board sets my organisation’s AI policy, regularly reviews high-risk use cases before deployment begins, and oversees live systems,” the figures were 63% and 43%.
These are shares of respondents describing their own organizations. They are not the result of a third party auditing how those arrangements actually run, or how well they work.
What the Study Supports and What It Does Not
The following analysis reflects MIF’s reading of the study.
What the published material shows is that among top performers, a higher share reported an increase in decisions made without human intervention, while a higher share also reported documented Responsible AI frameworks and cross-functional governance boards.
These are group comparisons, item by item. They are not a cross-tabulation showing how the two are combined within individual companies. The figures therefore cannot be read as evidence that stronger governance caused greater autonomy. The opposite explanation remains open: companies that already had the capital and the people may simply have been in a position to invest in governance and autonomy at the same time.
The narrower conclusion is that, among top performers, autonomy and governance do not appear to be a simple either-or choice.
One further caveat: the survey population is mainly large companies. Where this article goes on to suggest that something applies regardless of company size, that is a practical judgment rather than a finding of the study.
The Governance Model PwC Describes
The most useful part of the study may be not the numbers themselves, but the operating model PwC describes for top performers.
By PwC’s account, a governance board sets Responsible AI policies, and teams apply those policies in their day-to-day work through mechanisms such as standard build templates, quick checkpoints, and regular monitoring. Review by the cross-functional board is concentrated on the highest-risk work.
What stands out is that none of this reduces the total amount of control. Setting policy, using standardized implementation templates, introducing checkpoints, and monitoring production systems are all forms of control. What changes is where they sit.
Controls that had been concentrated in case-by-case review are distributed instead across policy set in advance, standards applied at build time, and monitoring in production, with board review reserved for high-risk cases. Under this model, routine use cases can move faster without eliminating governance.
The central question is what AI is authorized to do, and under what conditions. Where those conditions have been settled in advance and carried through into the implementation, there is less need for a person to weigh each individual case. Where those conditions have not been defined, organizations often fall back on inserting a person into the approval flow.
Placing Controls at Different Points
Here is one checklist for putting this into practice.
This is not a universal template, but one example of how the controls can be distributed. Each company must determine the appropriate level of detail and risk thresholds based on its sector, size, and applicable regulatory requirements.
| Control point | What to decide | Example that avoids unnecessary delay |
|---|---|---|
| Policy | Prohibited uses, high-risk uses, the conditions under which autonomous execution is allowed, and who is accountable | Approved low-risk use cases do not require case-by-case committee review |
| Build time | Access rights, limits, logging, evaluation criteria, and shutdown procedures | Encode these controls in reusable templates and shared components |
| Before deployment | Novelty, scope of impact, evaluation results, and residual risk | Use a brief check for routine cases and detailed review only for high-risk ones |
| In production | Quality degradation, anomalies, threshold breaches, and unintended use | Stop, notify, or hand over to a person only when a defined threshold is crossed |
| After deployment | Errors, exceptions, complaints, decision quality, and incidents | Update policies, thresholds, and templates based on operational evidence and incident records |
The number of human approval steps is not the only thing to check when moving toward autonomy. What matters is whether controls are distributed across upfront design, system-enforced constraints, production monitoring, and exception handling.
If every case runs through the same approval path, the problem may not be insufficient governance. It may be that all controls have been concentrated at a single point.
Conclusion
In PwC’s study, companies with the strongest AI-driven results had a higher share of respondents reporting an increase in decisions made without human intervention. The same group also had higher shares reporting a documented Responsible AI framework and a cross-functional AI governance board.
This does not establish that stronger governance causes greater autonomy. The study is based on responses from senior executives, primarily at large companies, and the published material does not show how autonomy and governance are combined within individual organizations.
Even so, among top performers, autonomy and governance do not appear to be a simple either-or choice.
The key takeaway is that governance should not be equated with case-by-case approval. Defining the delegated scope in advance, implementing standard controls, monitoring production behavior, and escalating only high-risk cases and exceptions offers a different operating model.
Moving toward autonomy does not necessarily require weaker governance. What deserves closer scrutiny is a design that routes every case through the same approval path.
When reviewing your organization’s use of AI, the question is not only how far human involvement can be reduced. It is also where upfront design, runtime controls, ongoing monitoring, and exception handling sit within the operating model.