For Part 3 of our multi-part series on our 2026 State of GRC in the Age of AI report, I'm excited to dig into the trust problem: what it takes to build AI for GRC that can stand up to high scrutiny. Part 1 discussed the current visibility problem in GRC, and Part 2 traced who answers when AI negatively impacts our audit outcomes. For this part, we’ll look at what respondents called out: GRC-focused AI tools don't measure up, and we’re hoping to understand more about what "enterprise-ready" actually should mean.
The report frames the expectations gap as three compounding failures: vendors oversold, buyers bought breadth, and governance never caught up. This post is about the first two, and the singular demand from respondents is to fix both. We’re seeing the GRC market having an abundance of AI, and it’s exciting. Many of our GRC platform providers today now ship purpose built agents, copilots, and assistants to aid us in our day-to-day GRC program functions.
Underneath the volume, however, the report surfaces a harder problem: too many of these tools can't yet stand up to the scrutiny and expectations enterprises are demanding. 86% of IT and security professionals agree: too many GRC-focused AI tools aren't yet enterprise-ready, citing the exact qualities every vendor pitched as table stakes: scalability, foundational security, and audit defensibility.
Our data tell the same story. Only 26% of professionals call their AI returns “very strong,” which leaves 74% feeling underwhelmed at feeling modest or lower returns. 90% admit at least some AI investments in GRC fell short. As customers, we’re feeling sold “transformation,” but for many of our teams, the results have landed closer to “incremental” at best.
The Filtering Problem
As we’re facing a crowded market, in theory, we should be able to easily filter out the tools that don’t measure up. In reality, the report shows how hard that filtering has become. When asked about the biggest challenges in identifying AI tools that meet enterprise GRC needs, professionals named:
- Security or compliance concerns: 49%
- Difficulty evaluating vendor claims and performance: 48%
- Lack of internal expertise to assess solutions: 45%
The list doesn't end there. Uncertain integration (43%), too many vendors offering similar solutions (40%), and difficulty distinguishing enterprise-ready tools from early-stage products (40%) round out the list.
These problems don’t live in isolation. At times, vendor claims are hard to wholesale verify at face value, and the risk of getting the call wrong could mean security and compliance exposure.
The Real Divide: Ownership vs Breadth
What actually separates a trustworthy tool from an unreliable one comes down to the reliability of the purpose-built agent coupled with ownership and accountability demonstrated by the provider. A purpose-built agent is built to yield reliable and expected outcomes end-to-end. Today, purpose-built AI agents are built to vet a vendor, draft a questionnaire response, collect evidence for a control, or monitor drift on a single framework, and we can measure the outcomes against what we expected to see. When it makes a mistake, we know exactly where that mistake lives.
A general-purpose AI agent usually approaches tasks with a broad-brush-stroke fashion, taking a different path. These usually offer broad capabilities and leave the orchestration to us to tune and bargain (sometimes endlessly) with to get it to do what we’re wanting it to do. So when something breaks, we can’t easily point to the root cause. Breadth with no owner becomes the problem, and as AI moves from experimental projects to work our controls actually depend on, that gap in ownership will widen with every task it receives.
Even so, buyers aren’t cutting AI budgets to manage the risk; we’re redirecting investments toward tools that can hold a measurable outcome. Favoring accountable, purpose-built agents over breadth is one of the more consequential shifts GRC AI procurement is making.
Three Questions to Ask Every AI Vendor
Alongside a shift in buyer behavior, the procurement question has also changed. We’ve gone from “what can this AI do?” to “what is this AI accountable for?”. Every vendor pitching to GRC decision makers should be able to answer three questions without hesitation:
- What specific outcome does this agent own end-to-end?
- How is that outcome measured, and what is the threshold for failure?
- Who is accountable when the outcome is not delivered?
A clear answer to all three points to an agent built to own a job or outcome. Hesitation indicates a more general-purpose capability described in agentic terms, which will inevitably end up leaving us feeling frustrated due to wasted time, effort, and needing to explain the failure to our customers, auditors, and leadership team members.
This shift is already taking place. 64% of buyers say a targeted agent that does a few things well fits their needs better than a broad, all-in-one system; among buyers focused on minimizing risk that figure rises to 70%. Even among the efficiency-minded, only a minority (41%) stay open to all-in-one systems.
This line of questioning doesn’t exclude Drata. We build agentic AI for GRC, so we stand ready to answer these same three questions (and more!) we’d expect you to ask all providers in this space. If we can't tell you what an agent owns and how it's measured, we haven't effectively earned your trust or your business.
Get Enterprise-Ready AI With Drata
The Drata Agentic Trust Management Platform is built for accountability: targeted agents that each own a specific outcome: from assessing third-party vendors to automating evidence collection and drafting questionnaire responses, backed by the security and audit defensibility enterprise programs require. See what enterprise-ready agentic AI looks like in practice: book a demo now.
Catch up on the previous posts in the series examining the visibility problem and the accountability problem. Stay tuned for the next post in the series: the governance problem—when AI adoption happens faster than the rulebook can be written.

