AI Governance is Advancing While the Attack Surface Expands

August 25, 2026
AI governance is taking shape, but technical controls and visibility are still catching up. See where CISOs are making progress and where gaps remain.
IANS

Generative AI moved into the enterprise faster than most security teams expected. With competitive pressures accelerating adoption, you were expected to build governance policies and controls tools were deployed—which left security teams responsible for decisions they didn’t make. The question on your mind now: How do we build governance without slowing down innovation?   

New IANS and Artico Search data, based on a survey of 113 CISOs, shows that many security teams are laying the foundation for AI governance. Now CISOs and other security leaders must close the gaps between policy and enforcement, while supporting their current AI environment and preparing their future tech stack.  

 

AI adoption outpaced governance

 

Generative AI adoption moved quickly to keep pace with business opportunities and emerging trends. As a result, you’re playing catch-up, adding controls to existing tools and writing policies for technology already in use. Security teams didn’t simply fail to prepare for AI. The problem was that AI deployment came first, and governance had to follow. Despite a difficult starting point, CISOs are making progress: 

  • 66% of organizations have a dedicated, stand-alone AI policy
  • 61% are aligning to the NIST AI Risk Management Framework

Now the focus needs to shift from establishing AI governance to putting those governance policies into practice. “CISOs operating without a defined risk appetite are operating without strategic direction. This is the single most common governance gap we see,” said Jeff Brown, IANS Faculty. 

 

AI controls lag behind policy

 

Policies alone don’t control how AI will behave, how data moves through AI systems, or how those systems respond. The benchmark data shows an earlier stage of maturity, with technical enforcement still developing:  

  • 31% use prompt logging and monitoring 
  • 19% have implemented prompt-injection detection and defenses 
  • 16% use AI-specific red teaming and adversarial testing 
  • 15% have implemented output filtering or response guardrails 

Testing presents an even larger gap. About 71% of organizations have not yet conducted adversarial testing of their AI systems, and 37% say it isn’t currently a priority. 

This data displays the difficulty and relative immaturity of these capabilities designed to detect AI-native attacks, control model outputs, and continuously test AI systems for new vulnerabilities. For instance, prompt-based attacks can be difficult to detect, and model outputs require new forms of monitoring and filtering. AI-specific red teaming often requires customer testing that has yet to become a repeatable part of the development lifecycle. Many controls designed to address AI-native threats are still developing.  

IANS Faculty member Adrian Sanabria points toward what more mature testing may need to look like: 

“For internal generative AI efforts, there’s a lot of custom work that needs to be done to make GenAI red teaming useful internally, and it should be turned into an automated process that is used similarly to code tests on every deployment, complete with regression testing,” he explained. 

Having the AI policy sets the foundation. The next step: put the policies into practice with enforcement, monitoring, and testing.  


The AI attack surface is growing

As AI becomes more connected and sophisticated, your attack surface expands with it. 

Seventy-four percent of enterprise AI environments pull data from external sources through APIs, MCP servers, or third-party plug-ins, according to our data. All that connectivity creates more data, integrations, and identities for security teams to protect because it expands the attack surface.  

Organizations are building inventories, but the data shows a drop-off as they move from asset identification to governance: 

  • 60% maintain a formal register of approved AI tools 
  • 23% periodically audit or recertify their AI inventory 
  • 21% maintain a dedicated inventory of non-human identities (NHIs) 
  • 14% include NHIs in access reviews and recertification 
  • 13% have defined NHI lifecycle processes 

As AI becomes embedded across the enterprise, the security boundary extends beyond individual AI models to the data, identities, applications, and integrations around them. 

“Successful Copilot adoption requires securing the broader ecosystem—not just the model itself—ensuring appropriate data access, enforcing compliance, and embedding oversight into existing IT governance structures. The technical controls haven’t yet caught up with the AI risks,” said Wolfgang Goerlich, IANS Faculty. 

Shadow AI visibility follows a similar pattern. While 56% use CASB or web filtering to detect and block unauthorized AI sites and applications, only 29% regularly review endpoint or proxy logs for AI usage patterns, and 28% use DLP policies to flag AI-related data exfiltration. 

An AI tool census is just the beginning. Effective governance increasingly requires visibility into how those tools connect, what data they access, which identities interact with them, and how those relationships change over time. 

 

Operationalize AI security

 

Security organizations have made meaningful progress establishing AI policies, adopting governance frameworks, and creating asset inventories. But AI environments continue to evolve quickly, which introduces new integrations, identities, and risks. All of this requires security organizations to keep adapting. It’s a moving target, with no sign of slowing down. 

In the next phase of AI security, security leaders will have to turn their AI governance foundation into active, repeatable processes with stronger enforcement, monitoring, and testing. Most organizations have made important progress on AI risk, but landscape is constantly changing. As it changes, the challenge for security leaders is to strengthen their governance, controls, and visibility to stay ahead of the risk.  

Want to gauge where your AI security programs are making progress and determine where to focus next? Get the report: AI Security 1H 2026 Benchmark Report

Subscribe to IANS Blog

Receive a wealth of trending cyber tips and how-tos delivered directly weekly to your inbox.

Please provide a business email.