Survey: AI ‘governance gap’ persists across industries as security incidents continue to rise

A recent Kiteworks report reveals that 80% of surveyed organizations experienced at least one incident in the past year and again shows a lack of industry-specific policies, rules, and oversight processes that guide AI.

What you'll learn:

  • More than 70% of organizations lack enforcement over sensitive data channels, according to the Kiteworks survey.
  • Few organizations have deployed AI-specific security controls.
  • Nearly two-thirds of organizations found employees using unapproved AI tools with sensitive data.

Data security was compromised at a large majority of organizations across many industries last year as companies continue to navigate adoption of AI, according to one recent report that also cites a lack of AI governance as a contributing factor in the surge of cyberattacks.  

The Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report, released in July, revealed that 80% of the organizations surveyed experienced at least one security or AI-related incident in the prior 12 months. 

See also: Older Kiteworks survey also showed ‘widespread governance failures’ in AI data security 

Kiteworks surveyed more than 450 security, compliance, risk and IT professionals across 10 industries and three global regions—the European Union/U.K., North America and the Middle East and Africa—during the second quarter of 2026. 

A widening maw in AI governance

According to Kiteworks, the gap in governance across companies is severe. For example, no AI containment control is deployed by more than 31% of organizations responding to the survey and 50% cannot produce a complete AI data access audit record within one business day; that’s a direct exposure under cybersecurity regulations in the E.U., for example—its DORA, its updated NIS2, and the E.U.'s AI Act.  

Over 70% of respondents to the Kiteworks survey have no technical enforcement over which channels employees can use for sensitive data, and only 27% have deployed AI-specific or data loss prevention, which is broadly understood as a cybersecurity strategy, set of tools, and processes designed to detect, monitor, and block the unauthorized access, sharing, or transfer of sensitive data.  

The survey also scored organizations based on AI governance maturity. Almost half of organizations were labeled as nascent in their maturity, and 23% were developing governance.  

About 20% had established governance maturity levels, while only 9% were classified as advanced. 

See also: The fiber bottleneck nobody priced into the AI boom 

In terms of industry-specific AI governance, energy and utilities were the most advanced, with manufacturing, financial services and health care following closely behind in scores. 

Defense contractors were found to have the least mature governance, followed closely by education and the federal government.  

The risks of ‘shadow AI’ 

Employee use of unapproved AI tools—or shadow AI—is also a major point of concern. According to Kiteworks, this issue is structural, as 65% of organizations discovered employees using unapproved AI tools with sensitive organizational data. 

Among those organizations, 36% found customer and client data flowing through them, 33% found IT credentials, and 31% found employee personal and HR data. 

Although roughly one-third reported no discovery, the report noted this is likely because of a lack of detection capabilities to see unapproved AI use. 

See also: Five requirements for navigating Europe’s cybersecurity compliance rules 

“AI risk is no longer a future problem. It is a present condition most organizations are still treating as a planning exercise,” said Patrick Spencer, senior vice president of Americas Marketing and Industry Research at Kiteworks. 

“Organizations still waiting to act are behind, not ahead. This research gives leaders defensible data grounded in deployed controls, not stated intentions, the foundation for moving investment toward architecture that governs people and agents under one standard.” 

See also: Podcast: Why is manufacturing such a huge target for cyberattacks? 

To mitigate risks of sensitive data exposure, Kiteworks encouraged organizations to prioritize enforcing sensitive data; deploy AI-specific DLP through a centralized policy engine; integrate MFT and AI infrastructure; implement and test an AI kill switch; build audit trails that meet regulatory production timelines; assign dedicated AI data governance ownership; and consolidate sensitive data exchange platforms.

About the Author

Sarah Mattalian

Staff Writer

Sarah Mattalian is a Chicago-based journalist writing for Smart Industry and Automation World, two brands of Endeavor Business Media, covering industry trends and manufacturing technology. In 2025, she graduated with a master's degree in journalism from Northwestern University's Medill School of Journalism, specializing in health, environment and science reporting. She does freelance work as well, covering public health and the environment in Chicagoland and in the Midwest. Her work has appeared in Inside Climate News, Inside Washington Publishers, NBC4 in Washington, D.C., The Durango Herald and North Jersey Daily News. She has a translation certificate in Spanish.

Sign up for our eNewsletters
Get the latest news and updates