Round One Results · August 2026

The AI Governance Benchmark

What ten investment management firms actually have in place for AI governance, measured against a five-point maturity scale. Reported in aggregate; no firm is identified.

Join Round Two

Method and cohort

Round One closed at ten firms. Each completed the same self-assessment, which scores twelve practices on a five-point scale, averages them, and returns a maturity level from Initial to Optimized along with the three highest-return actions for that firm.

The cohort was made up of hedge funds, private equity firms, private markets managers, an advisory practice and a family office. Responses were self-initiated, so the cohort skews toward firms already working on the problem. Read the findings as a first cut rather than an industry standard.

2.62Average score out of 5.0. Median 2.50.
0 of 10Firms that reached Level 4, Managed, or above.
50%Whose largest gap was no approval path for new AI tools.
80%Told to build a complete AI inventory as a top-three action.

Where the sample landed

Number of firms at each maturity level, out of ten.

Level 1 · Initial0
Level 2 · Aware5
Level 3 · Defined5
Level 4 · Managed0
Level 5 · Optimized0

Scores ran from 2.00 to 3.33. The entire sample sits inside the middle two levels: firms that have policy but cannot enforce it, and firms whose policy is written but not automated. Nobody was below a written standard, and nobody was above a manual one.

Where firms lose points

  • No formal request or approval path for new AI tools5 firms. Staff adopt tools without a security review. Firms here typically run several times more AI tools than they can name.
  • AI vendor data handling unknown3 firms. Sensitive data may reach model training or unreviewed processing with no record the firm accepted that risk.
  • Uneven maturity across areas2 firms. Real controls in some areas and nothing in others — governance grew up around one team, not the firm.

The actions recommended most

Share of the ten firms receiving each action in their top three.

Build a full AI inventory80%
Monitor AI usage80%
Deploy a prompt firewall70%
Data loss prevention for AI20%
Automated compliance checks20%
Require an AI-SBOM from vendors20%
Continuous AI discovery10%

The recommendations cluster far more tightly than the scores. A firm at 2.00 and a firm at 3.33 received the same two instructions at the top of their list: find out what AI is actually in use, then watch it.

The five levels

  • Level 1 · Initial · Ad hoc. No consistent approach. Decisions are made tool by tool.
  • Level 2 · Aware · Reactive. Policy is written and largely unchecked. Enforcement is limited.
  • Level 3 · Defined · Operational. Policies defined but not automated. Evidence assembled by hand.
  • Level 4 · Managed · Measured. Controls run automatically and are reported continuously.
  • Level 5 · Optimized · Continuous. Evidence is a by-product; governance adapts as the estate changes.

How far the gap actually is

Every assessment attaches an effort estimate to each recommended action. Adding up the top three per firm, totals ranged from seven to sixteen weeks, and eight of ten fell between eight and thirteen. For most firms in this sample, the distance between Aware and Managed is one focused quarter.

The three highest scorers were not the firms with the most policy. Their weakest link had already moved past discovery to vendor questions — AI-SBOMs, model provenance, training data. Every firm below the median was flagged for the same absence: no structured way to request a tool and get an answer.

Take the six-minute assessment

Round Two is open. The assessment returns your own benchmarked score alongside the full cohort results before publication. Questions: hello@clarier.ai