The AI Risk Landscape: Governance Gaps, Liability Traps, and the $4.7 Trillion Question
95% of US enterprises use generative AI. Only 25% have documented governance policies. The EU AI Act carries penalties of 7% of global turnover. 53 shareholder class actions have been filed. The gap between adoption and governance is the defining risk of 2026. The artificial intelligence market is projected to reach $4.8 trillion by 2033, with hyperscaler capital expenditure alone reaching $443 billion in 2025 — a 73% increase from 2024. AI startup funding hit $202 billion in 2025, capturing 50% of all venture...
EXECUTIVE SUMMARY
95% of US enterprises use generative AI. Only 25% have documented governance policies. The EU AI Act carries penalties of 7% of global turnover. 53 shareholder class actions have been filed. The gap between adoption and governance is the defining risk of 2026. The artificial intelligence market is projected to reach $4.8 trillion by 2033, with hyperscaler capital expenditure alone reaching $443 billion in 2025 — a 73% increase from 2024. AI startup funding hit $202 billion in 2025, capturing 50% of all venture...
95% of US enterprises use generative AI.
The artificial intelligence market is projected to reach $4.8 trillion by 2033, with hyperscaler capital expenditure alone reaching $443 billion in 2025 — a 73% increase from 2024.
The scale of capital flowing into artificial intelligence has no historical parallel in technology investment.
The global AI regulatory landscape has fractured into three competing models, each reflecting fundamentally different approaches to the relationship between innovation and risk.
95% of US enterprises use generative AI.
Scale Without Precedent
The scale of capital flowing into artificial intelligence has no historical parallel in technology investment. The five largest hyperscalers — Amazon, Google, Microsoft, Meta, and Oracle — are projected to spend $443 billion in combined capital expenditure in 2025, rising to $660-690 billion in 2026. Amazon alone has an annualised run rate exceeding $118 billion; Google has raised its guidance to $85 billion; Meta is committing $64-72 billion. These figures represent a 4.3x increase from 2023 levels, driven almost entirely by AI infrastructure — data centres, GPU clusters, and custom silicon.
AI startup funding has experienced a parallel explosion. Total AI investment reached $202 billion in 2025 — double the $100 billion raised in 2024, which itself was 80% above 2023. AI now captures 50% of all global venture capital, up from 34% in 2024 and 19% in 2023. Foundation model companies attracted $80 billion alone, more than doubling from the prior year. The geographic concentration is extreme: 79% of AI funding ($159 billion) went to US-based companies.
Yet beneath the investment headline lies a troubling signal: 42% of companies abandoned most AI initiatives in 2025, up from 17% in 2024, and 70-85% of AI projects fail to meet expected outcomes. Enterprise AI adoption rates are high — 88% regular use, 92% of Fortune 500 companies using generative AI — but the gap between deployment and value realisation suggests a hype cycle that may be approaching its peak.
Three Competing Models
The global AI regulatory landscape has fractured into three competing models, each reflecting fundamentally different approaches to the relationship between innovation and risk. The EU AI Act represents the most comprehensive binding regulation, classifying AI systems into four risk categories — unacceptable, high, limited, and minimal — with compliance deadlines staggered from February 2025 through August 2027. Penalties are severe: up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for other breaches. The EU Product Liability Directive, effective December 9, 2026, extends strict liability to AI systems for the first time, explicitly defining software and AI as "products."
The United States has taken the opposite approach. Executive Orders in January and December 2025 emphasised removing regulatory barriers to AI innovation, establishing an AI Litigation Task Force, and pursuing federal preemption of state AI laws. The regulatory philosophy is explicit: American AI companies must be free to innovate without cumbersome regulation. This creates a permissive environment for development but transfers risk to downstream users and those affected by AI systems.
China has taken a third path — early and specific regulation of generative AI. The Generative AI Administrative Measures, effective August 2023, made China the first country with binding generative AI regulations. AI-Generated Content Labeling Measures, effective September 2025, impose standardised requirements for marking synthetic content. China's October 2025 Cybersecurity Law amendments incorporated AI provisions into national law for the first time. Japan enacted its AI Promotion Act in May 2025; South Korea's AI Basic Act — Asia-Pacific's first binding comprehensive AI law — took effect January 2026.
The Litigation Explosion
AI-related litigation has surged across five categories, with no sign of deceleration. Over 51 copyright lawsuits have been filed against AI companies as of October 2025, led by the New York Times v. OpenAI & Microsoft case seeking billions in damages. The copyright litigation wave is structurally different from prior technology disputes because it challenges the foundational training methodology of large language models — if courts rule that training on copyrighted content is not fair use, the economic model of the entire generative AI industry is at risk. No summary judgement decisions on fair use are expected before summer 2026.
Shareholder class actions represent the most immediate financial risk to companies deploying AI. Fifty-three AI-related shareholder class actions were filed between March 2020 and June 2025, making AI the largest category of event-driven shareholder litigation — surpassing crypto, COVID-19, cybersecurity, and SPACs. Average D&O settlements have risen to approximately $56 million, a 27% increase. The common thread in these actions is not that AI systems failed, but that boards failed to govern AI systems — an important distinction that shifts liability from technology failure to governance failure.
Healthcare AI litigation deserves particular attention. The UnitedHealth/naviHealth class action alleges that the nH Predict algorithm had a 90% error rate in denying care — a case that, if successful, could establish precedent for AI liability across the healthcare sector. Employment discrimination cases are rising as AI hiring tools face scrutiny; a federal judge allowed a collective action under the ADEA against Workday's AI screening tools in May 2025. The AI phishing threat compounds cybersecurity litigation risk: AI-generated phishing emails achieve a 54% click-through rate compared to 12% for traditional phishing.
Adoption Without Oversight
The most consequential finding in the AI risk landscape is the gap between adoption and governance. Eighty-eight percent of enterprises use AI regularly; 92% of Fortune 500 companies use generative AI products. Yet only 48% of Fortune 100 companies cite AI as a board oversight responsibility — up from 16% in 2024 but still below half. Only 25% have documented board-level AI policies. Only 31% of AI use cases have reached full production. Sixty-three percent of companies deploying AI operate without documented governance frameworks.
This governance deficit creates a liability trap that plaintiffs are already exploiting. Under the Caremark duty of care, boards must establish formal reporting systems for material risks. AI is indisputably a material risk for any company deploying it at scale. The absence of documented governance frameworks — risk assessments, monitoring protocols, incident response procedures, human oversight mechanisms — provides plaintiffs with a straightforward negligence claim. The question is not whether boards will face AI governance litigation, but when.
Strategic Implications for International Businesses
The AI risk landscape demands three immediate actions from international businesses. First, establish documented AI governance frameworks before deploying or expanding AI systems — not as a compliance exercise but as a litigation defence. The cost of governance implementation is trivial compared to the cost of a shareholder class action, and the absence of documentation is itself a liability. Second, build multi-jurisdictional compliance architectures that accommodate the EU's risk-based framework, US sector-specific requirements, and China's content labelling mandates simultaneously. Companies that treat these as separate compliance streams will discover — expensively — that they are interconnected. Third, prepare for the copyright resolution. If courts rule against fair use for AI training, the downstream effects on every company using third-party AI models will be immediate and material. Companies should audit their AI supply chain now — understanding which models they use, what training data underlies them, and what indemnification provisions their vendor contracts provide.
The $4.7 trillion AI market will create enormous value. But in 2026, the governance gap — not the technology — is where the risk lies.
This analysis draws on McKinsey State of AI 2025, Crunchbase venture funding data, EU AI Act official text, White House Executive Orders, CreditSights hyperscaler analysis, IAPP global regulatory tracker, McKool Smith AI litigation database, Corporate Compliance Insights board governance surveys, and Bain enterprise AI adoption research. All figures in US dollars unless otherwise noted.
This page preserves the original historical SRG article text and exhibits while reformatting the structure for the current Global Risk Watch deep-dive template.
Charts and source-register language are retained from the source article where available.
Historical deep-dive format normalized for Global Risk Watch; original charts and exhibits preserved.