
Sixty-seven percent of middle market companies say they apply formal AI governance controls before moving a project into pilot or production, according to RSM's Middle Market AI Survey 2026. That means roughly one in three organizations already running AI in production has no formal control gate in place. For most workflows, that gap is a manageable risk. For agreements, contracts, and anything with a signature on it, it is not.
RSM surveyed 1,030 senior business leaders (827 in the United States and 203 in Canada) and published the results on July 21, 2026. The topline finding is that the middle market has moved past experimentation: 86% of organizations say they have partially or fully integrated AI into their operations, and 97% report satisfaction with their AI investments so far, per the RSM Middle Market AI Survey 2026 introduction. More than half, 54%, say their AI investments have already exceeded return-on-investment expectations, according to the same survey release.
The catch is governance. Only 67% of respondents say they establish AI governance controls before implementing pilots or production, per RSM's building-blocks-of-AI-adoption analysis. RSM frames the remaining third as "forging ahead without governance in place" - a segment that is running AI in real business processes without the controls that would catch a bad output before it does damage.
Trade press covering the release has largely repeated that 67% figure without connecting it to a specific workflow. That is the gap worth closing, because "governance" means something very different depending on what the AI is touching. An AI summarizing internal meeting notes with no formal review process is a minor risk. An AI agent that reads, redlines, or approves a contract with no formal review process is a different category of exposure entirely.
Most AI use cases in a mid-sized company are reversible. A bad marketing draft gets edited. A miscategorized support ticket gets reassigned. An agreement is different in three ways that make an ungoverned AI touch expensive:
This is exactly the scenario RSM's governance-gap finding describes in the abstract: a control gate that either exists before production or does not. For agreements specifically, "before production" means before the document leaves the building for signature, not after.
Governance is a vague word until it is tied to specific mechanics. Inside Docusign IAM, the governance gap RSM describes maps onto three concrete controls that already exist in the platform:
None of these three controls are new. What is new is the need to apply them to a workflow step where the "who" is an AI agent instead of a paralegal. Our complete Docusign IAM implementation guide covers how to wire approval routing and audit logging into a broader rollout; the governance layer for AI-touched agreements sits directly on top of that same foundation.
The specific control that closes the gap RSM describes is a pre-signature standards check, and Docusign built one into the platform. Docusign's Iris engine powers an AI contract review capability where agreements are automatically compared against company playbooks to flag terms that do not match policy, according to Docusign's own announcement. If a company does not already have a formal playbook, the same tooling can draft a starting one from an existing template or reference document.
That is the governance control RSM's survey is implicitly asking about, expressed as a workflow step rather than a policy statement. Instead of trusting that whoever drafted or negotiated an agreement remembered every internal standard, the check happens automatically before the document reaches an approver. Docusign's broader Iris AI agents are also built with integrated human-in-the-loop approvals and transparent audit trails as a design principle, not an add-on, per Docusign's Iris agents product page.
For a mid-sized company without a large in-house legal team, this matters more than it does for an enterprise with twenty contract reviewers. The playbook check is doing work that would otherwise depend entirely on which specific person happened to review that specific contract. We go deeper on how this actually reads and flags language in how Iris AI reads agreements: a technical deep dive, and on where it differs from a fully custom agent build in Iris AI vs custom Claude agents on Docusign agreements.
The question a compliance team, an auditor, or an acquirer's diligence lawyer will eventually ask is not "did you use AI on this contract." It is "show me exactly what it did, when, and who approved it." A governance program that cannot answer that in minutes is not a governance program, it is a policy document.
Inside Docusign IAM, that answer comes from the same audit infrastructure that already exists for human-driven agreement activity. Every envelope carries an audit trail documenting the sequence of actions taken on it, per Docusign's audit trail documentation, and Workflow Builder's step-by-step tracking extends that record to the pre-signature process itself, not just the signing event. When an Iris agent flags a clause against a playbook, that check is a logged step in the same workflow, sitting alongside the human approval that came before or after it.
Practically, this means the audit trail for an AI-touched agreement should show, at minimum: which playbook version the agreement was checked against, what was flagged, who reviewed the flag, and what changed as a result before the document went to signature. If a Docusign IAM workflow cannot produce that sequence for a given contract, the governance gap RSM measured is present in that specific workflow, regardless of what the company's AI policy says on paper.
RSM's data suggests most middle market companies have already turned AI on somewhere in the business. The checklist below is specifically for the point where AI touches an agreement, contract, or anything that will be signed:
Governance done this way is not a brake on AI adoption. It is what lets a mid-sized company keep moving at the pace RSM's survey shows the market is already moving, without discovering the gap during an audit or a dispute instead of before one.
What percentage of middle market companies have formal AI governance controls? Sixty-seven percent apply AI governance controls before moving a project into pilot or production, according to RSM's Middle Market AI Survey 2026. The remaining third are running AI in production without that control gate.
How many companies did RSM's Middle Market AI Survey include? The survey covered 1,030 senior business leaders, 827 from the United States and 203 from Canada, per RSM's survey overview.
Can Docusign IAM check an AI-drafted contract against company standards automatically? Yes. Docusign's Iris-powered contract review capability compares agreements against company playbooks and flags terms that do not match policy, according to Docusign's product announcement.
Does Docusign keep an audit trail when AI touches an agreement? Docusign automatically generates an audit trail for every envelope processed on the platform, per Docusign's audit trail documentation, and Workflow Builder extends step-by-step tracking to the agreement process leading up to signature.
RSM's governance gap is a market-wide finding, but the fix is specific to each workflow. For agreements, it is a matter of turning on controls that Docusign IAM already provides: approval routing in Workflow Builder, playbook checks through Iris, and an audit trail that covers the AI step, not just the signature. If you are rolling out agreement AI at a mid-sized company and want a second set of eyes on where your governance actually stands, talk to the fluidlabs team about a Docusign IAM working session built around your specific workflow.
Schedule a 30-minute strategy session. We'll identify the highest-value vertical solution for your organization, walk through the architecture, and map out a build plan — no commitment required.
Submit Your Project Details →or email us at hello@fluidlabs.com