Kiteworks Report Reveals 80% of Organizations Experienced Security or AI Incidents as AI Governance Readiness Remains Critically Low

CSI security ai detected

Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, has released its 2026 Data Security and Compliance Risk: Annual Survey Report, highlighting significant gaps in enterprise AI governance and data security readiness. Based on primary research involving security, compliance, risk, and IT professionals across 10 industries and three global regions, the fifth annual report found that 80% of organizations suffered at least one security or AI-related incident over the past year.

The report also found that these incidents frequently resulted in compliance repercussions. Nearly two-thirds (63%) of organizations reported outcomes such as audit findings, mandated remediation plans, board-level escalations, contractual penalties, or formal regulatory investigations. Additionally, 65% identified employees using unauthorized AI applications to process sensitive organizational data.

Unlike surveys that rely on participants’ perceptions or confidence levels, the report evaluates organizations based on security controls that are actively deployed and operational. The Data Security Maturity Score (DSMS) measures implementation of 11 binary security controls, including eight controls focused on traditional human-driven data access and three AI-specific safeguards. The AI Governance Maturity Score (AIGMS) assesses 19 AI and agent governance capabilities. Together, these metrics form the Data Security and Compliance Readiness Index (DSCRI).

The findings indicate an average DSMS of 39 out of 100, an average AIGMS of 35 out of 100, and a combined DSCRI of just 16.2 out of 100. Seventy percent of surveyed organizations fall within Tier 1 or Tier 2 maturity levels, demonstrating that many enterprises are still in the early stages of implementing effective governance for both human users and AI agents.

“Organizations have deployed AI far faster than they’ve built the governance infrastructure to manage it,” said Tim Freestone, Chief Strategy Officer at Kiteworks. “The incidents have already happened, and the compliance consequences are already being felt. The path forward is architectural. It requires a data policy engine that enforces controls at the data layer for every person and every agent alike, not behavioral policy people can route around. Organizations that reached Tier 4 maturity got there by deploying controls, not documenting intent.”

The research identifies significant shortcomings in AI governance implementation. No AI containment control included in the survey has been adopted by more than 31% of respondents. Half of organizations cannot generate a complete AI data access audit trail within one business day, creating potential compliance exposure under regulations including DORA, NIS2, and the EU AI Act. Meanwhile, 73% lack technical controls restricting the channels employees can use to transfer sensitive data, and only 27% have implemented AI-specific data loss prevention (DLP) capabilities.

The survey also highlights the growing challenge of shadow AI. Among organizations that detected employees using unauthorized AI services, 36% found customer or client data had been processed through those tools, 33% discovered IT credentials, and 31% identified employee personal or HR information. The report notes that the 35% of organizations reporting no discoveries may instead lack the monitoring capabilities required to detect such activity.

“AI risk is no longer a future problem. It is a present condition most organizations are still treating as a planning exercise,” said Patrick Spencer, SVP of Americas Marketing and Industry Research at Kiteworks. “Organizations still waiting to act are behind, not ahead. This research gives leaders defensible data grounded in deployed controls, not stated intentions, the foundation for moving investment toward architecture that governs people and agents under one standard.”

The report also reveals a substantial maturity divide between high-performing and low-performing organizations. The 19% of respondents classified within the Resilient quadrant—those achieving DSMS and AIGMS scores of at least 50—recorded an average DSCRI of 46. By comparison, the 66% categorized as Exposed, with both scores below 50, averaged a DSCRI of only 8 despite having similar industry representation and organizational sizes.

According to the research, AI governance controls are the primary differentiator. At the average DSMS score of 39, increasing the AIGMS from 35 to 60 improves the DSCRI by approximately 10 points, nearly twice the improvement achieved by implementing four additional security controls while AI governance remains unchanged.

To help organizations improve their security posture, the report recommends seven priorities:

  • Classify and enforce sensitive data
  • Deploy AI-specific DLP through a centralized policy engine
  • Integrate MFT and AI infrastructure with a SIEM
  • Implement and test an AI kill switch
  • Build audit trails that meet regulatory production timelines
  • Assign dedicated AI data governance ownership
  • Consolidate sensitive data exchange platforms

The full report provides additional analysis by industry, geographic region, and organization size, along with a Security Maturity Readiness Checklist designed to help organizations prioritize remediation investments.

Organizations can also benchmark their own AI governance maturity using the Kiteworks AI Data Governance Readiness Assessment, an online tool that evaluates security controls across the same dimensions measured in the report. Access it at [URL forthcoming].

Download the 2026 Data Security and Compliance Risk: Annual Survey Report at https://www.kiteworks.com/sites/default/files/resources/kiteworks-annual-report-2026.pdf

The research was conducted by Centiment on behalf of Kiteworks during the second quarter of 2026.

About Kiteworks

Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies.

Join our LinkedIn group Information Security Community!

No posts to display