Europe can’t hit the brakes on its own ai: 59% clueless on kill-switch timing
One minute after an algorithm starts leaking customer data, most European firms still stare at the screen. A 681-respondent flash poll by ISACA, previewed Monday in Madrid, exposes the continent’s dirty secret: AI is live, lucrative and essentially ungoverned inside boardrooms that have no idea how to unplug it.
Numbers that should freeze c-suites
ISACA’s AI Pulse Poll 2026 shows 59% of digital-trust professionals cannot estimate how long a shutdown would take. Another 20% admit “somewhere between 30 minutes and several hours.” Only 5% claim a one-minute kill-switch. Translation: in a ransomware scenario powered by generative models, the damage window stretches for hours while lawyers debate liability.
Pablo Ballarín, the ISACA cyber adviser who briefed reporters, called the sprint to adopt large-language tools “a forced march into fog.” His verdict: companies bolt chatbots onto CRMs overnight, then discover no one logged the training data, mapped the APIs or wrote an incident-playbook. The result is a governance vacuum masquerading as innovation.

Ownership is a guessing game
Ask who takes the fall when the model hallucinates a fraudulent invoice and the survey fractures: 38% would point to the board, 24% to a faceless “AI owner” and 15% simply shrug. Until regulators assign a legal persona to the silicon, the chain of blame ends nowhere, making insurance underwriters jittery and shareholders restless.
The irony? Humans remain the single point of failure. Respondents insist 71% of AI mishaps trace back to people feeding poisoned prompts or mis-labelled datasets. Yet only 17% work under mandatory disclosure rules; one in three firms never even ask staff to declare which cloud service they just wired to GPT-4. Shadow IT has evolved into shadow intelligence.

What happens on 5 may
The full report drops in ten days, but Brussels chatter already anticipates a delegated act tying the upcoming AI Act to mandatory kill-switch testing. Early drafts demand proof a model can be isolated inside fifteen minutes; the ISACA data shows four-fifths of organisations would flunk that test today.
Ballarín closed his slide deck with a line destined for investor calls: “AI can predict, decide and act—three verbs that turn a bug into a disaster faster than any classic IT outage.” Europe’s boards have until the next headline to turn those verbs into governance nouns: policy, ownership, evidence. Otherwise the first major AI breach will write its own post-mortem in real time, and no one will know whose job was supposed to end the story.
