Research points to rising compliance pressures, shadow AI usage, and gaps in security and AI governance maturity.
Key Takeaways:
As organizations rush to embrace AI, 80% experienced either a cybersecurity breach or an AI-related incident in the past year. The findings suggest that many companies are deploying AI faster than they can secure it, which leaves sensitive data and compliance efforts increasingly vulnerable.
Kiteworks has just released its fifth annual Data Security and Compliance Risk survey. This report examined responses from 459 security, compliance, and IT professionals across multiple industries and regions. It analyzes how organizations are managing sensitive data, AI governance, cybersecurity, and regulatory compliance in 2026.
According to the Kiteworks survey, nearly two-thirds of organizations have implemented AI in production environments, but most have not established the controls needed to govern AI safely. Critical safeguards such as AI-specific data loss prevention, purpose-based access restrictions, audit trails, and emergency shutdown mechanisms remain uncommon.
Cybersecurity challenges continue to pose a significant threat to organizations worldwide. 74% of organizations experienced at least one security incident in the past year, while 64% of companies that use AI reported an AI-related security event.
Overall, four out of five organizations faced either a traditional cybersecurity incident or an AI-driven security issue during the same period. These findings suggest that many organizations are struggling to manage the risks introduced by expanding digital ecosystems and AI technologies.
Regulatory and compliance pressures are becoming increasingly difficult for organizations to navigate. The Kiteworks report found that 63% of respondents experienced a compliance-related consequence during the past year, including audit findings, mandatory remediation efforts, regulatory investigations, or contractual penalties. The findings also suggest that many organizations are finding it difficult to demonstrate adequate oversight of sensitive data and AI systems.
The survey found that 65% of organizations identified employees using unauthorized AI tools with company data. This creates additional exposure because sensitive information may be processed outside approved security and governance frameworks.
The report introduces two maturity measurements, including the Data Security Maturity Score (DSMS) and the AI Governance Maturity Score (AIGMS). This first one evaluates the implementation of core security controls such as encryption, secure file transfer, monitoring, and response capabilities. The average score was 39 out of 100, which indicates that many organizations have implemented fewer than half of the measured controls.
Meanwhile, the second score measures AI-related governance capabilities, including monitoring, auditability, and policy enforcement. The average score was 35 out of 100, which shows that AI governance programs are still in the early stages for most organizations.
The report combines these measures into a broader readiness index and concludes that organizations generally have insufficient alignment between their security programs and AI governance efforts. This shows that overall preparedness for AI-related security and compliance risks remains low.
To reduce growing security and compliance risks, organizations need to treat AI governance as a core business function. This report suggests that companies should implement stronger technical controls around AI systems, including monitoring tools, access restrictions, audit trails, and data protection mechanisms that prevent sensitive information from being misused or exposed. Moreover, security and governance efforts should evolve together, because investing in traditional cybersecurity alone is no longer enough to address the risks introduced by AI.
This Kiteworks report also emphasizes the importance of improving visibility into how data moves across the organization and ensuring employees use only approved AI applications. Businesses should establish clear governance policies, automate compliance processes where possible, and regularly assess their security maturity to identify gaps.