Internal audit has an AI say-do gap, and two 2026 surveys now put numbers on it: stated adoption has roughly doubled, but the share of functions actually embedding the technology, or ready for the fraud it enables, has not kept pace. Audit is talking about AI far faster than it is using it.
The numbers, from two 2026 surveys
Gartner's survey, published on 27 January 2026 and based on 119 chief audit executives polled in August 2025, found 83 per cent of audit functions are now piloting or using AI, with another 12 per cent planning to within the year. Set that against Gartner's March 2024 survey, where 41 per cent said they used or planned to use generative AI, and the trajectory is clear: adoption has roughly doubled in under two years. More than 70 per cent of chief audit executives now rate building a culture of innovation and better use of data analytics and generative AI as important or extremely important for 2026, and 80 per cent want to lift the impact of data analytics in their function.
That is the "say", and it is loud.
Where the doing lags
The same research names the gap. Despite the interest, Gartner reports that only a small number of chief audit executives are confident in their function's ability to effectively embed generative AI into audit workflows and methodologies, and about 70 per cent of those already using the tools say they need outside help. Gartner's benchmarking of how audit actually uses generative AI puts most functions in the early stages, still exploring or piloting individual use cases rather than running them as embedded, day-to-day practice. Progress is held back, it notes, by poor data quality, a shortage of technical development skills, and in some cases access to the technology itself.
The distance between "83 per cent piloting or using" and "a small number confident they can embed it" is the say-do gap in one line. A pilot is not an embedded practice, a licence is not a capability, and intent is not a completed audit that used AI in a defensible step.
The same gap, with stakes
A second survey shows what the gap costs when the pressure is real. The Internal Audit Foundation and AuditBoard, in a report released on 17 February 2026 based on more than 370 senior internal audit leaders in North America, found 85 per cent consider AI-enabled fraud a moderate-to-high risk, yet fewer than 40 per cent feel their function is adequately prepared to detect it. "While the awareness of AI-enabled fraud is high, the 'readiness gap' remains a significant vulnerability for most organisations," said Richard Chambers, senior advisor for risk and audit at AuditBoard.
The reasons auditors gave are practical, not philosophical: a lack of appropriate technology or tools (57 per cent), too few staff with the relevant skills (55 per cent), limited budget (46 per cent) and competing priorities (43 per cent). It is the same shape as the Gartner data at higher stakes. Awareness is not the bottleneck. Tools, skills and time are.
Why this is a benchmark, not just news
These are North American surveys, so treat the exact percentages as a mirror, not a local statistic. The value for an Australian function is the self-assessment: hold it against the same two questions. On adoption, are you in the 83 per cent that has at least piloted, or still deciding? On capability, are you in the small group confident it can embed AI in an actual audit, or is your "adoption" a stalled pilot and a subscription nobody has operationalised?
That distinction matters more than the raw figures, because internal audit is the third line of defence, and in APRA-regulated entities it carries named obligations under prudential standards on governance and the operational-risk expectations of CPS 230. A function that has "adopted AI" on paper but cannot evidence how it uses or governs that AI has a say-do gap its own board and regulator could one day ask about. The site's companion piece on what still counts as evidence covers the assurance half of that question; this is the adoption half.
Score your own function
A mid-sized Australian internal audit team of six runs one AI subscription, bought eight months ago after a board push to "use AI". Scored honestly against the surveys, it sits in the 83 per cent that has piloted and the majority that cannot yet embed. Two auditors use the tool to summarise documents and draft sections of reports; nobody uses it in testing, and there is no written standard for when AI output can support a finding. On the fraud question, the team rates AI-enabled fraud a high risk in its own audit universe but has run no procedure to detect a synthetic identity or a deepfaked approval.
The head of audit records the position as it is, with no real names, no live engagement references and no vendor account details, then sets three targets: a written AI-use standard within the quarter, one auditor trained to embed the tool inside a real audit, and one fraud-detection procedure piloted before year-end. The gap does not close by buying more tools. It closes by turning a subscription into practice.
Draft it with these prompts
Use these to run the self-assessment and build the plan, keeping inputs generic so nothing confidential leaves your environment.
Do this Monday
- List every AI tool your audit function holds and how it is actually used today, engagement by engagement, not subscription by subscription.
- Score the function against the two survey questions: have we piloted, and can we evidence AI used inside a completed audit. Be honest about pilots that stalled.
- Name your single biggest blocker from tools, skills, budget, time or governance, using the first prompt, and stop treating "we have a licence" as adoption.
- Draft or update a one-page standard for when AI output can support audit work and when a human must verify it, so adoption has a rule behind it.
- Pick one real, upcoming audit and commit to embedding AI in a defined, documented step of it, with a named auditor accountable.
- Add AI-enabled fraud to your audit universe and pilot one detection procedure this quarter, using the second prompt to sequence it.
- Record the whole assessment, dated, so your next review measures movement rather than restating intent.
A self-assessment checklist
Work down this list and mark each as present, partial or absent. Anything absent is your say-do gap, in order.
- Adoption that is embedded, not just licensed: at least one completed audit used AI in a defined, documented step.
- A written standard for when AI output can support a finding and when a human must verify it.
- At least one auditor skilled enough to embed the tool in testing, not only in drafting.
- AI-enabled fraud named in the audit universe, with at least one detection procedure piloted.
- A named owner for AI governance inside the function, and a date the position was last reviewed.
- Evidence you could show a board or regulator of how the function uses and controls its own AI, not just that it bought some.
Hype check
The percentages are North American and largely self-reported, and the headline adoption figure counts piloting, which flatters the intent side of the ledger. Do not import them as Australian facts. Equally, do not wave the gap away. Two independent 2026 surveys, one on general adoption and one on fraud readiness, describe the same shape: audit is aware and interested well ahead of being capable and ready. The measured reading is that the say-do gap is real, it is named by auditors themselves, and it closes with skills and standards rather than another subscription.
Bottom line
Internal audit's AI adoption has roughly doubled on paper, but confidence in actually embedding the technology, and readiness for the fraud it enables, has not followed. Gartner puts 83 per cent piloting or using AI while only a small number feel able to embed it. The IIA and AuditBoard put 85 per cent alert to AI-enabled fraud while fewer than 40 per cent feel prepared for it. For an Australian function, the numbers are a mirror: score yourself honestly, name the blocker, and turn intent into evidenced practice before your board asks you to.
Do this Monday:
- Score your function against two questions: have you piloted AI, and can you evidence it used inside a completed audit.
- Name your single biggest blocker, tools, skills, budget, time or governance, and stop counting a licence as adoption.
- Write a one-page standard for when AI may support a finding and when a human must verify it.
- Add AI-enabled fraud to your audit universe and pilot one detection procedure this quarter.
TheAICommand. Intelligence, At Your Command.



