Findings

What the published work shows

Four findings drawn from the papers published between March and August 2026. Each states what the evidence supports, what it rests on, and where it stops. The complete archive sits at all papers.

14published papers
50companies in the annual-report study
1,019coded statements and documents
140model outputs in controlled tests

Organisations govern AI as a technology control and require its use, while no board framework asks who wrote the instruction that shapes its answers.

The Classification Study

15 listed organisations · published governance material · June 2026

  • Placed AI under technology, security, product, risk, conduct or compliance governance15 of 15
  • Used the mechanisms applied to professional advice0 of 15

Every organisation governed AI as a system to be secured and controlled rather than as a source of advice to be checked.

The Mandate Study

19 organisations · public record 2025 to 2026 · July 2026

  • Recurring mechanisms formalising AI use5
  • Documented reversal after employee resistance1

Leadership directives, performance review, incentives, training and board expectation carry AI use from available to required, across law, retail, banking, consulting and manufacturing.

The Unread Instruction

9 board and audit frameworks · 3 questions each · July 2026

  • Frameworks requiring anyone to know who wrote the system prompt, when it changed, or how it performs across versions0 of 27
  • Documents in which the phrase "system prompt" appears0 of 20

General duties covering inventories, ownership, testing and monitoring appear throughout. The instruction the organisation itself writes goes unnamed.

An organisation can hold a complete inventory of its AI systems, satisfy every framework it has adopted, and still have nobody accountable for the text that decides what those systems will say. Governing AI as infrastructure produces controls over access, security and procurement. It produces no control over content.

The gap is a definitional one rather than a failure of diligence. Frameworks written for software ask who owns the system. The question that matters here is who wrote the instruction, and it has no place to sit.

Interpretation published elsewhereHas the Board Read the System Prompt? at fosterfletcher.com

Responsibility for AI output rests with the customer, while the controls that shaped that output are described in a different clause.

The Liability Transfer

7 enterprise AI services · 37 public documents · July 2026

  • Terms making the customer responsible for output7 of 7
  • Same terms describing controls that shape output7 of 7
  • Responsibility clauses mentioning those controls0 of 7

Filters, system instructions, safety features, retrieval rules, data masking and classifiers are all disclosed. The wording that assigns responsibility leaves every one of them out.

The Awareness Trap

EU AI Act Articles 14 and 26 · automation-bias research · March 2026

  • Oversight duties placed on the designated person5

The law requires a named individual to understand limitations, stay alert to over-reliance, detect anomalies, interpret output and intervene. The research finds that awareness of automation bias does not reliably prevent it.

The contracts and the regulation converge on the same person. Public terms assign the consequences of output to whoever used the system, and European law appoints someone to catch the errors. Neither gives that person any visibility of the controls that shaped what appeared on screen.

Where the two studies pull against each other is worth noting. The Awareness Trap finds the psychological literature unconvinced that a designated overseer catches what they are appointed to catch, which weakens the mechanism the law relies on and the contracts assume.

Interpretation published elsewhereBlamefall: Why mandated AI concentrates liability downward at fosterfletcher.com

Organisations report how much AI they have deployed. What it contributed, and how their own executives reach it, stay largely unreported.

Adoption Without Capability Reporting

22 listed organisations · 714 coded statements · June 2026

  • Statements about adoption and control404
  • Product or marketing claims308
  • Statements meeting the threshold for a capability statement2

Both qualifying statements came from a single company.

The Language of AI Deployment

9 organisations · 155 verified statements, 2022 to 2026 · July 2026

Expansion language dominates the record, and claims about replacing work are sometimes followed by later qualification.

The First Annual Reports of the LLM Era

150 SEC Form 10-K filings · 50 companies · 2019 to 2024 · Published March 2026 · Revised August 2026

The directional scoring produced a 24.5 per cent higher annual aggregate rate in the later interval. The median company difference was zero, the bootstrap interval spanned zero, and no timing convention gave either interval a majority of companies. The study does not establish a population trend or attribute the result to AI.

The Executive Access Study

Fortune 500 and FTSE 100 · public record to April 2026 · July 2026

  • Named executives publicly described running AI on personal hardware0
  • Documented executive-only AI environments1

This study reports an absence rather than a pattern. Survey evidence shows directors using AI well ahead of their organisations, while the public record says almost nothing about how. The single documented executive environment runs under tighter governance rather than looser.

Disclosure follows what is easy to count. Seats, spend, tools deployed and pilots launched all produce figures. Whether the work improved does not, so the reporting record describes the size of a programme and rarely its result.

Two of the 714 coded statements met the threshold for measured contribution, and both came from one company. That is a statement about what organisations choose to publish, and it does not establish that internal measurement is equally thin.

The written instruction added at deployment decides whether the AI will recommend anything, and executive rank has no documented way to reach it.

The Subtraction Study

40 outputs · one model held fixed · one governance instruction added · June 2026

Model identity stayed constant. Only the governance prompt varied.

The Separation Study

20 outputs per condition · 4 instruction conditions · August 2026

  • Clear recommendations, no added instruction18 of 20
  • Clear recommendations, full governance instruction8 of 20
  • Clear recommendations, two narrow conditions19 · 20
  • Prohibited-action requests answered with a permitted course55 of 56

The narrow conditions refused every full override and still supplied a lawful route. What suppresses recommendation-making is separable from what enforces the boundary.

The Override Rank Cannot Reach

7 enterprise deployments · 74 documentation and legal entries · July 2026

  • Deployments allowing an identity or group to vary safety controls during use2 of 7
  • Deployments documenting an exception keyed to executive rank0 of 7

This study expected none of seven and found two, then narrowed its own claim. Where variation exists it is provisioned in advance by an administrator, through group, identity, function or scope. The administrative model contains no object for rank.

The governance instruction and the safety boundary are usually written as one document and treated as one decision. The Separation Study separates them. Narrow instructions held the boundary in 55 of 56 prohibited-action requests while leaving recommendation-making almost untouched, which means the loss of usable output is a property of how the instruction was drafted rather than a cost of governing at all.

Whatever an organisation decides about that drafting is settled before anyone types a question. Both mechanisms found in the documentation are administrative provisions, so seniority operates through a request to whoever administers the tenant, expressed in the terms that model recognises.

Interpretation published elsewhereThe System Prompt Effect on AI Recommendations at fosterfletcher.com

Read together

The four findings describe one sequence rather than four separate results. Organisations place AI among their technology controls and then require people to use it. What it will say is decided by an instruction written during deployment, which no board framework requires anyone to read, test or version. Responsibility for whatever the system produces is assigned to the person who typed the prompt, in wording that never mentions the controls that shaped the answer. Rank supplies no route back to the instruction, because the administrative model holds no object for it.

The instruction is therefore the most consequential document in an enterprise AI deployment and the least governed. It determines the output, it sits outside every framework examined, and the people carrying responsibility for what it produces have no documented way to see it.

This reading goes beyond any single paper. Each finding above stands on its own evidence and its own stated limit, while the sequence between them is drawn rather than measured.

Terms used in the papers

System prompt
A written instruction supplied before the user's request, setting how the AI should respond. In the controlled studies, the tested instruction was written for the deploying organisation.
Capability statement
A published statement attributing a measured business outcome directly to AI reasoning or synthesis.
Clear recommendation
An output that chooses a course or position the reader can act upon. Acknowledging uncertainty leaves the recommendation clear when the choice remains operative.
Ablation
Removing one part of an instruction while keeping the rest of the test unchanged, so the effect of that part can be measured.

Where this work sits

Three properties carry different parts of the work, and they are kept apart so the research record stays independent of what is argued from it.

  • mkai.orgThe research archive. Papers, methods, evidence bases and stated limits, each at a permanent address for citation.
  • fosterfletcher.comEssays reading the evidence for what it means inside an organisation, published by Richard Foster-Fletcher, who authored the papers here.
  • realityandreason.orgGovernance instruments and definitions built on this work, for teams applying it in practice.