Written by 9:48 pm Blog

AI risk is not just a technology problem: New research shows why leadership matters more than controls

Artificial intelligence is rapidly becoming embedded across the modern enterprise. From customer se…
AI risk is not just a technology problem: New research shows why leadership matters more than controls

Artificial intelligence is rapidly becoming embedded across the modern enterprise. From customer service chatbots and software development assistants to decision-support systems and autonomous agents, businesses are deploying AI at a remarkable pace. Yet as adoption accelerates, so do concerns around governance, data security, compliance, and operational risk.

A new report from IANS and Artico Search suggests that many organizations may be focusing on the wrong issue. While technical security controls remain essential, the research indicates that long-term confidence in managing AI risk depends less on technology and more on organizational readiness. In particular, leadership understanding, governance ownership, staffing, and budget authority appear to play a decisive role in how chief information security officers (CISOs) view the future of AI security. The findings are based on responses from 113 CISOs surveyed between April and May 2026 as part of the CISO Perspectives on AI Risk study.

Security maturity reduces today’s risk

One of the clearest findings is that organizations with mature AI security programs feel significantly more secure today. CISOs overseeing AI security-mature environments rated their current AI risk at an average of 3.7 out of 10. By contrast, leaders in organizations with lower levels of AI security maturity rated their risk at 7.8 out of 10. Organisations that have implemented stronger governance frameworks, security testing, monitoring mechanisms, and protective controls generally have greater visibility into their risks and more confidence in mitigation measures. The finding reinforces a broader cybersecurity principle: maturity matters. Organizations that invest in understanding their AI environments are likely to experience fewer surprises than those deploying AI without adequate oversight. Yet the study uncovered a second, perhaps more significant, insight.

According to IANS researchers, perceptions of current AI risk have only a weak relationship with how confident CISOs feel about managing AI risks over the next two years.  An organization may have a robust AI security program today and still feel uncertain about future challenges. Conversely, some CISOs facing considerable current risks remain optimistic that their organizations possess the structures needed to improve.

Nick Kakolowski, Senior Research Director at IANS, described this as one of the most surprising findings in the report. The research suggests that confidence comes not merely from existing controls, but from whether the organization is positioned to adapt as AI technologies continue to evolve. This is a crucial point because AI is not a static technology. New models, capabilities, vulnerabilities, regulations, and threat vectors emerge continuously. Security programs cannot simply achieve compliance and remain unchanged. They must evolve.

Leadership understanding drives confidence

Perhaps the strongest differentiator between optimistic and pessimistic CISOs was leadership awareness. Among CISOs who were optimistic about managing AI risk over the next 24 months, 80% said senior leadership possessed a fair or good understanding of AI risk. Among pessimistic CISOs, only 48% reported the same level of executive understanding.  The 32-point gap exceeded differences related to technical maturity.

This finding highlights a challenge that extends beyond cybersecurity teams. AI strategy is increasingly becoming a board-level issue. Decisions about data usage, intellectual property protection, third-party model adoption, regulatory compliance, workforce impacts, and ethical governance require executive engagement. Without informed leadership, security teams may struggle to obtain support for necessary controls, governance initiatives, training programs, and investments. In effect, cybersecurity professionals may understand the risks, but without executive alignment they may lack the authority to address them effectively.

The study also found significant differences in governance structures between optimistic and pessimistic CISOs. Among optimistic respondents, 74% reported clearly defined ownership for AI governance. Among pessimistic respondents, only 40% reported similar clarity.  This may be one of the most practical lessons from the report.

In many organizations, responsibility for AI remains fragmented. Multiple departments may become involved simultaneously, including information technology, cybersecurity, legal, compliance, risk management, human resources, and business operations. Without clear ownership, decision-making can become slow, inconsistent, or ineffective. Regulators worldwide are increasingly emphasizing accountability in AI governance. The European Union AI Act, emerging U.S. frameworks, and international standards initiatives all point toward the growing importance of defining clear responsibilities for AI oversight. Therefore, organizations that establish accountability early may be better positioned to manage future compliance obligations.

The report also highlights the importance of operational capacity. Among optimistic CISOs, 81% controlled their AI security budgets, compared with only 50% of pessimistic respondents. Similarly, security teams in the optimistic group reported higher levels of effective AI utilization.

Budget ownership may sound like an administrative detail, but it has significant implications. For instance, security leaders who control resources can respond more quickly to emerging threats, invest in needed capabilities, and implement governance programs without excessive bureaucracy. Those without budget authority may find themselves dependent on competing priorities elsewhere in the organization. The staffing findings tell a similar story. AI security requires specialist expertise, particularly as organizations deploy increasingly sophisticated systems. Confidence appears closely linked to having sufficient personnel and capability to manage changing risks.

The report arrives as AI adoption continues to outpace security preparation. A related IANS and Artico Search benchmark study found that 74% of AI environments already obtain information from external data sources through APIs, third-party plugins, or Model Context Protocol (MCP) servers. Yet only 29% of organizations have conducted adversarial testing of those environments.  This discrepancy highlights an emerging governance gap.

Organizations are deploying increasingly connected AI systems while many still lack the testing, monitoring, and governance structures needed to manage the resulting risks. Vulnerabilities such as prompt injection, data leakage, model manipulation, supply-chain compromise, and unauthorized access remain active concerns for security professionals.

Article Source

Close