Is AI Use Outpacing Policy? What Our Exclusive Surveys Tell Us About the Governance Gap

AI has gone from an emerging technology to an everyday workplace tool fast. 

Across web design, development, marketing and content, professionals are using AI to generate ideas, write copy, analyse data, create images and increasingly, write code. 

 But adoption is moving faster than the rules around it. 

Our two recent surveys point to the same emerging problem. In our exclusive survey into the impact of AI on the web industry we found that 84% believe AI should be subject to government regulation.  

Meanwhile, our Vibe Coding Survey found that among non-developers already using AI to write code, only 26% work at organisations with a formal policy governing the practice. 

Taken together, the findings suggest something important. 

The people embracing AI aren’t necessarily calling for fewer restrictions. Many are using it regularly, impressed by what it can do and, at the same time, seeing reasons why stronger safeguards are needed. 

AI adoption is already running ahead of governance 

We found that 89% of web professionals use AI tools in their work, with 39% using AI daily. 

Usage spans the industry. Web designers were the most frequent users in our survey, with 51% using AI daily, while developers, marketers and copywriters were also incorporating it into their workflows. 

And most users are impressed with the results. 92% said they were either somewhat or extremely impressed by AI tools. 

Yet enthusiasm for the technology sits alongside strong support for oversight. 

84% of web professionals told us AI should be regulated by government, including: 

  • 83% of web designers 
  • 84% of web developers 
  • 83% of digital marketers 
  • 88% of copywriters 

 Nearly a third wanted AI to be heavily regulated. 

That makes the finding more interesting than a simple divide between people who support AI and people who fear it. The same industry that has incorporated AI into everyday work is also asking for stronger rules around how it is used. 

And our more recent research gives an indication of why. 

The closer AI gets to critical work, the more oversight matters 

Using AI to brainstorm a headline is one thing. Using it to create software that interacts with customers, company systems or sensitive data raises very different questions. 

Our vibe coding survey looked at 600 U.S. employees in non-development roles who use AI to generate code. 

More than half, 51.1%, had very limited or no coding knowledge before starting to use AI tools. 

Yet respondents were now using AI to create scripts, automate workflows, fix bugs, write database queries and build API integrations. Around one in six had even used AI to create an entire website. 

This is one of AI’s biggest opportunities:  tasks that previously required specialist technical knowledge are becoming accessible to many more people.  

But it also helps explain why concern about oversight is growing. 

Only 26% of the AI-assisted coders we surveyed said their organisation has a formal policy governing the practice. 

A further: 

➡️ 34.2% rely on informal guidance 

➡️ 31.7% say there is no policy 

➡️ 8.2% don’t know whether one exists 

In other words, 65.9% are using AI to write code either without a formal policy or with informal guidance alone. 

While our two surveys questioned different groups, the contrast is striking: 84% of web professionals want government regulation of AI, while formal governance can still be absent inside the workplaces where the technology is already being used. 

Concern isn’t theoretical 

Our survey of 500+ web designers, developers, marketers and copywriters also asked what worried them about the technology. 

56% cited ethical misuse, while a similar proportion were concerned about over-reliance on AI. 

The vibe-coding results put a more practical dimension on those concerns. 

83.8% of respondents had encountered problems with AI-generated code. 

And 20.5% said AI-generated code had contributed to a security breach at their organisation. 

That breach figure is self-reported rather than an independently verified breach rate, but it illustrates the potential consequences when AI-produced work moves beyond experimentation and into real systems. 

The review process can also be limited. 

Although 61% said they test AI-generated code themselves, just 31.5% have it reviewed by a professional developer. 

Others rely on another AI tool or a non-developer colleague, while 9.3% told us they don’t perform any checks at all. 

That creates a contradiction which runs through both studies. 

AI makes it possible to produce more work, more quickly, and allows people to tackle tasks that might previously have been beyond their technical skills.

Yet greater capability doesn’t automatically bring the expertise required to assess everything that capability produces. 

Subscribe for the latest 20i news

Get the latest product launches, new features alerts, platform upgrades and exclusive content, all delivered instantly to your inbox.

AI is lowering the barrier to creation, but not to responsibility 

That distinction becomes particularly important with coding. 

AI can give someone with little development experience the ability to create a working application surprisingly quickly. 

But making something work is only part of software development. 

Security, maintainability, data handling, dependencies, access controls, testing and ongoing maintenance all still matter. 

The vibe coding survey suggests that AI has reduced the technical barrier to creating software faster than many businesses have developed processes for governing that software. 

And that provides useful context for the 84% calling for wider AI regulation. 

The demand for safeguards isn’t necessarily resistance to AI. It can also be read as a response to how quickly AI is extending what people are able to do. 

The more consequential the task, the greater the potential impact when something goes wrong. 

The governance gap exists at more than one level 

Government regulation often dominates discussions around AI governance, but legislation is only one layer. 

Businesses also must establish their own rules. 

Our research suggests that gap currently exists at both levels. 

Web professionals overwhelmingly support wider regulation, while inside organisations, AI-assisted coding can still happen without formal policies, mandatory review or clearly defined limits. 

That can create a form of ‘shadow AI’, similar to the longstanding problem of shadow IT. 

An employee may use AI to build a useful internal script or application without going through a conventional development process. 

➡️ But does the organisation know it exists?

➡️ Does it know what data the tool can access, which APIs it connects to, where it is hosted or who is responsible for maintaining it?

➡️ Has anyone with the appropriate expertise reviewed the code? 

AI hasn’t created these governance questions, but it has dramatically increased the number of people capable of creating software that raises them. 

Oversight needs to reflect the level of risk 

The answer isn’t necessarily to subject every use of AI to the same process. 

Using AI to suggest alternative wording for a paragraph doesn’t carry the same risk as using it to create an application that processes customer data. 

Businesses can instead define clearer thresholds for when additional oversight becomes necessary. 

A small internal script may require basic testing. A customer-facing application, payment system or tool that handles sensitive information should justify substantially more scrutiny and professional review. 

The same principle applies more broadly. 

 As AI becomes embedded into everyday work, policies need to distinguish between low-risk assistance and uses where errors, security weaknesses or poor decisions can have significant consequences. 

That allows businesses to retain the productivity benefits of AI without assuming that every output is trustworthy simply because it appears to work. 

The people using AI are already asking for guardrails 

Perhaps the most interesting conclusion from the two surveys is that enthusiasm and caution aren’t opposites. 

  • 89% of web professionals use AI. 
  • 92% are impressed by what it can do. 
  • 84% still believe it should be regulated. 

And when AI is used for something as consequential as writing software, 65.9% of users say their workplace has either no formal policy or only informal guidance governing the practice. 

Those findings describe the same shift from two different directions. 

AI has become useful enough that people are adopting it before governments and organisations have fully decided how it should be governed. 

The challenge now isn’t simply encouraging adoption or restricting it. It’s making sure the safeguards surrounding AI develop as quickly as its capabilities do. 

AI has lowered the barrier to creating things enormously. The next challenge is making sure it doesn’t also lower the barrier to creating risks nobody is properly overseeing. 

Previous Article

Get 20i Updates as Soon as We Publish!

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *