Retool Survey: Only 8% of Tech Leaders Have Strong AI Governance

Close-up of a metal rack appliance faceplate

Senior technology and security leaders know they are losing the AI governance race, and the survey data shows exactly how. Retool’s 2026 AI Governance Report surveyed 307 CTOs, CIOs, and CISOs at companies from 50 to 1,000-plus employees. Just 8% describe their internal AI tool governance as strong. Meanwhile, 93% say they are at least somewhat worried about vibe-coded tools running in production environments their teams cannot fully see.

  • The gap between concern and control is structural: 95% of respondents lack complete visibility into what is running in production, yet only 8% have centralized controls in place.
  • The counterintuitive pressure point: 37% of CISOs report near-zero tolerance for friction from the business on AI enablement, higher even than the 29% of CTOs who say the same. The people most accountable for failures face the most pressure to move fast.
  • 55% of leaders say security and access controls should live in a centralized platform underneath the app. Policy documents and per-app configurations are not what the C-suite thinks will work.

Vibe Coding Turned Shadow IT into Shadow AI

Shadow IT used to mean rogue SaaS downloads and unapproved cloud storage. Retool’s survey identifies the 2026 version: AI-generated internal tools spun up in hours by employees who have never written production code, shipped without logging, review, or governance trail. One enterprise CISO in the survey described it plainly: “Tools get built in hours, sometimes minutes, and they don’t look like ‘systems’ to the people building them. So now you’ve got data moving through a prompt, an API call, a quick script someone pasted together at 10pm. It works. It ships. Nobody logs it anywhere.”

The visibility numbers support that account. Only 5% of senior tech and security leaders are very confident they have full visibility into what is running in production. Another 43% are not confident at all. The remaining 52% occupy an uncomfortable middle ground: they know roughly what is running but acknowledge gaps still exist. That middle group is the governance problem in a single data point. Leaders who are not sounding alarms feel mostly covered. One in five organizations has already had a production incident from an AI-generated internal tool in the past 12 months.

Vibe coding, a term coined by Andrej Karpathy in 2025, means prompting AI into building a working application without traditional software development steps. Non-technical employees are now generating internal tools that handle real company data. The popular vibe-coding platforms optimize for speed to prototype, not for the review, testing, and access-control layers that engineers treat as baseline requirements. The result is a class of production tools that bypasses the governance processes their builders did not know to worry about.

The AI Governance Confidence Gap Runs 24 Points Across the C-Suite

Retool’s data surfaces a role-specific fracture. When leaders were asked whether AI coding tools had a net positive impact on engineering productivity, 71% of CTOs agreed; only 47% of CISOs said the same. That 24-point gap reflects a fundamental difference in what each role measures. CTOs see output: more code shipped, more features deployed. CISOs see risk surface: more unreviewed code in production, more data flowing through tools that were never formally onboarded into the security program.

The code review data reinforces the split. Overall, 34% of leaders say review time has increased since AI coding tool adoption. But 45% of CTOs report increased review time, compared to 28% of CISOs. The CISO number is low not because the review burden is lighter, but because AI-generated tools often skip the code review step entirely. You cannot measure increased review time in tools that were never reviewed. As we covered earlier in our analysis of AI governance and incident depth, the gap between deployment velocity and oversight maturity predicts incident frequency.

The accountability picture is equally fragmented. About 32% of respondents say engineering leadership or the CTO holds accountability for AI-generated tool incidents. Another 34% say it depends on the situation. And 10% say accountability has not been defined yet. Taken together, 44% of technical leaders either lack a clear default or have not made a decision. Diffuse accountability is not a policy position. It is what happens when governance has not kept pace with the building speed.

Three Moves the Survey Data Points Toward

The Retool report’s recommendations align with what 55% of leaders already believe: governance must move to the platform layer, underneath individual apps, not inside them. That shift requires three specific operational moves.

Build an AI asset inventory before writing the next policy – Forty percent of respondents say their AI governance is mostly functional but requires significant manual effort to maintain. That manual effort is almost always inventory work: discovering what is running, who built it, and what data it touches. Only 24% of organizations currently govern at the environment level. The other 76% still rely on tool-by-tool oversight that cannot scale to the pace vibe-coded tools create.

Close the detection gap before treating the policy gap – The survey finds 51% of leaders cannot confirm whether an AI-generated internal tool has caused a production incident. That is not a statement about incident frequency. It is a statement about detection capability. The shift from AI governance to AI data governance requires monitoring that covers not just what tools exist, but what data they access. Only 19% of leaders have monitoring in place that lets them confirm no incident has occurred.

Assign accountability before the next incident, not after – Case-by-case accountability worked when shadow IT was an occasional exception. With vibe-coded tools potentially numbering in the dozens across any engineering team, it will not scale. One CISO in the survey captured it: “When anyone can ship a tool in an afternoon, nobody signs up to maintain it.” Fifty-five percent of leaders want a centralized AI governance platform as the answer. The specific question to resolve now is who owns that platform, not who owns each generated app.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display