Survey: AI ‘governance gap’ persists across industries as security incidents continue to rise
What you'll learn:
- More than 70% of organizations lack enforcement over sensitive data channels, according to the Kiteworks survey.
- Few organizations have deployed AI-specific security controls.
- Nearly two-thirds of organizations found employees using unapproved AI tools with sensitive data.
Data security was compromised at a large majority of organizations across many industries last year as companies continue to navigate adoption of AI, according to one recent report that also cites a lack of AI governance as a contributing factor in the surge of cyberattacks.
The Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report, released in July, revealed that 80% of the organizations surveyed experienced at least one security or AI-related incident in the prior 12 months.
See also: Older Kiteworks survey also showed ‘widespread governance failures’ in AI data security
Kiteworks surveyed more than 450 security, compliance, risk and IT professionals across 10 industries and three global regions—the European Union/U.K., North America and the Middle East and Africa—during the second quarter of 2026.
The whopping cost of data breaches
Autonomous AI agents attempted to create fake online identities, socially engineer maintainers into approving malicious code, and gain unauthorized access to external systems during cybersecurity testing, according to recent reports by two other organizations, OpenAI and Anthropic.
Also, IBM’s 2026 Cost of a Data Breach Report found AI-enabled attacks accounted for 25% of malicious breaches globally, costing organizations an average of $6 million per incident.
Additionally, the global average cost of a data breach climbed 12%, reaching nearly $5 million, largely driven by detection, escalation, and lost business costs, according to the IBM report.
These incidents show that AI agents are evolving from software tools into autonomous actors that enterprises should govern, according to the report.
IBM also found that attackers are not only using AI, they are targeting AI, finding that security incidents were less about model selection than model and environmental security.
The root causes of these incidents were often structural, according to IBM, and included a compromise of connected APIs, applications and cloud misconfigurations, indicating governance failures.
Security incidents, widespread and commonplace
The Kiteworks survey found that 74% of organizations experienced at least one general security incident. Among the 64% that have deployed AI, almost two-thirds experienced an AI-related incident. Across all respondents, 80% experienced at least one incident of either type.
Manufacturers and companies across industries have grappled with security concerns as they implement AI. Other reports are showing this to be true.
For example, the World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87% of cyber leaders identified AI-related vulnerabilities as the fastest growing cyber risk of 2025.
Last year, another Kiteworks survey also revealed that manufacturers are feeding a lot of sensitive data into AI systems while lacking basic protections, creating significant risk across all industries, including manufacturing, which already is the worldwide leader in ransomware attacks and has been for many quarters in a row.
That survey also revealed “widespread governance failures in AI data security” and that just 17% of organizations have implemented automated technical controls such as DLP scanning for AI data flows, to block access to public AI, while more than a quarter of the respondents reported high private data exposure.
See also: Podcast: 'Muddy waters' of implementing AI and how manufacturers can avoid them
The most recent survey also found that 63% of organizations experienced a compliance outcome, such as an audit finding, a required remediation plan, a board escalation, a contractual penalty or a formal regulatory investigation.
A widening maw in AI governance
According to Kiteworks, the gap in governance across companies is severe. For example, no AI containment control is deployed by more than 31% of organizations responding to the survey and 50% cannot produce a complete AI data access audit record within one business day; that’s a direct exposure under cybersecurity regulations in the E.U., for example—its DORA, its updated NIS2, and the E.U.'s AI Act.
Over 70% of respondents to the Kiteworks survey have no technical enforcement over which channels employees can use for sensitive data, and only 27% have deployed AI-specific or data loss prevention, which is broadly understood as a cybersecurity strategy, set of tools, and processes designed to detect, monitor, and block the unauthorized access, sharing, or transfer of sensitive data.
The survey also scored organizations based on AI governance maturity. Almost half of organizations were labeled as nascent in their maturity, and 23% were developing governance.
About 20% had established governance maturity levels, while only 9% were classified as advanced.
See also: The fiber bottleneck nobody priced into the AI boom
In terms of industry-specific AI governance, energy and utilities were the most advanced, with manufacturing, financial services and health care following closely behind in scores.
Defense contractors were found to have the least mature governance, followed closely by education and the federal government.
The risks of ‘shadow AI’
Employee use of unapproved AI tools—or shadow AI—is also a major point of concern. According to Kiteworks, this issue is structural, as 65% of organizations discovered employees using unapproved AI tools with sensitive organizational data.
Among those organizations, 36% found customer and client data flowing through them, 33% found IT credentials, and 31% found employee personal and HR data.
Although roughly one-third reported no discovery, the report noted this is likely because of a lack of detection capabilities to see unapproved AI use.
See also: Five requirements for navigating Europe’s cybersecurity compliance rules
“AI risk is no longer a future problem. It is a present condition most organizations are still treating as a planning exercise,” said Patrick Spencer, senior vice president of Americas Marketing and Industry Research at Kiteworks.
“Organizations still waiting to act are behind, not ahead. This research gives leaders defensible data grounded in deployed controls, not stated intentions, the foundation for moving investment toward architecture that governs people and agents under one standard.”
See also: Podcast: Why is manufacturing such a huge target for cyberattacks?
To mitigate risks of sensitive data exposure, Kiteworks encouraged organizations to prioritize enforcing sensitive data; deploy AI-specific DLP through a centralized policy engine; integrate MFT and AI infrastructure; implement and test an AI kill switch; build audit trails that meet regulatory production timelines; assign dedicated AI data governance ownership; and consolidate sensitive data exchange platforms.
About the Author
Sarah Mattalian
Staff Writer
Sarah Mattalian is a Chicago-based journalist writing for Smart Industry and Automation World, two brands of Endeavor Business Media, covering industry trends and manufacturing technology. In 2025, she graduated with a master's degree in journalism from Northwestern University's Medill School of Journalism, specializing in health, environment and science reporting. She does freelance work as well, covering public health and the environment in Chicagoland and in the Midwest. Her work has appeared in Inside Climate News, Inside Washington Publishers, NBC4 in Washington, D.C., The Durango Herald and North Jersey Daily News. She has a translation certificate in Spanish.

