AI Governance Gap Continues Growing: Survey Results

The 2026 Annual Survey Report Is In: The AI Governance Gap Didn’t Close. It Widened.

An untested kill switch is not a control. It is an assumption, and this year’s data shows just how many organizations are operating on one.

We just closed data collection on the Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report, drawing on responses from 459 security, compliance, and technology professionals across North America, Europe, and the Middle East. The headline finding is not a new vulnerability or a new regulation. It is a structural one: the gap between what organizations believe about their AI governance and what they can actually demonstrate has widened over the past twelve months, not narrowed.

Late last year, our own forecasting projected that roughly 60% of organizations would still lack a tested AI kill switch by the time this survey closed. The measured number came in at 79%. We did not just miss the target. We watched the gap grow while AI adoption accelerated underneath it — 64% of organizations surveyed already have AI deployed in production environments. Adoption stopped being the open question a while ago. Containment is where the real exposure now sits.

This post walks through the findings that matter most from this year’s AI data governance research: what broke, why it broke in the specific way it did, and what separates the organizations closing the gap from the ones widening it. Kiteworks secure data exchange customers and prospects alike are asking the same underlying question this data answers: is my organization actually as governed as I believe it to be?

Key Takeaways

  1. The governance gap widened instead of closing. Our own forecast projected 60% of organizations would lack a tested AI kill switch by now; the measured figure came in at 79%, meaning the gap grew rather than shrank over the past year.
  2. Containment controls are the weakest link, not detection. Only 21% of organizations have deployed an AI kill switch, and 23% of those running AI in production have never tested their termination process end to end.
  3. Compliance consequences are already here, not projected. Sixty-three percent of organizations experienced a compliance consequence tied to an AI governance gap in the past 12 months, and half cannot produce a complete AI access record within one business day.
  4. Security maturity and AI governance maturity are multiplicative, not additive. Our new composite index, the Data Security and Compliance Readiness Index, averaged 16.2 out of 100 across 459 organizations, because strong general security cannot compensate for weak AI-specific controls.
  5. Budget does not predict maturity. Organizations with the largest security budgets in the survey had the lowest representation in the top maturity tier of any size band we measured, while mid-sized organizations with far smaller budgets outperformed them.

The Kill Switch Problem: Documented Procedures Are Not Tested Controls

Here is where most organizations get tripped up. When we asked about AI termination capability, a large share of respondents described something that sounds like a control but functions like a hope: a named owner, an escalation path, a runbook nobody has actually executed against a live system.

Only 21% of organizations have deployed a formal AI kill switch capability. Worse, 23% of organizations with AI already in production told us they had never tested their termination process end to end — not “tested it once, a while back.” Never. That distinction matters enormously the first time an incident forces the real test, because that is not the moment to discover the procedure does not perform the way its documentation claims.

The speed problem compounds this. The CrowdStrike 2026 Global Threat Report documented AI-enabled lateral movement in as little as 27 seconds in its fastest observed intrusions. Mandiant’s M-Trends 2026 report found the median time from initial access to a secondary threat group handoff fell to 22 seconds in 2025. A kill switch that depends on a person noticing an alert, escalating it, and manually pulling access controls was never built for a 27-second problem. That is not a criticism of any individual security team. It is a structural mismatch between how most containment plans are designed and how fast the thing they are supposed to contain actually moves. A SIEM platform ingesting real-time AI access telemetry — with behavioral alerts pre-configured to fire at the lateral movement signatures CrowdStrike and Mandiant documented — is the detection infrastructure that closes the gap between a 27-second attacker and a kill switch built for human-speed response.

Twenty-two percent of organizations with AI deployed have already had to revise, roll back, or restrict at least one AI deployment in the past 12 months over data security concerns. That is not a hypothetical risk. It is an operational cost organizations are already absorbing.

You Trust Your Organization is Secure. But Can You Verify It?

Read Now

Compliance Consequences Are a Current-State Finding, Not a Future Risk

Sixty-three percent of organizations reported at least one compliance consequence tied to an AI governance gap in the past year: an audit finding, a required remediation plan, a board escalation, a contractual penalty, or a formal regulatory investigation. That figure is not a projection about what might happen if governance does not improve. It is a reported outcome from organizations telling us what already happened to them.

Half of the organizations we surveyed could not produce a complete AI access record within one business day of a request. Only 33% have tamper-evident audit trails in place, meaning the majority cannot produce evidence that has not been modified after the fact — the specific kind of record investigators and auditors examine first. These two findings are connected: an organization that cannot retrieve its own access records quickly is, almost by definition, an organization that cannot answer a regulator’s question quickly either.

The regulatory backdrop makes this more urgent, not less. Under frameworks like GDPR and emerging AI-specific rules, an accountability principle already assumes organizations can demonstrate control over sensitive data on demand. A retrieval delay is not a technical inconvenience under that standard. It is evidence of inadequate governance, and it is treated that way by regulators and auditors alike. A confirmed data breach or compliance finding tied to AI governance — when the audit trail needed to scope it cannot be produced within one business day — compounds the regulatory exposure by demonstrating that the accountability infrastructure itself failed, not just the control that was breached.

Sixty-one percent of organizations now rank data sovereignty as their single biggest compliance challenge for the year ahead, yet only 29% use a technical mechanism to enforce it. Data sovereignty concern is nearly universal. Technical enforcement is not. That gap between stated priority and enforced control is where regulatory exposure actually lives, and it shows up again and again across this year’s data.

Why We Built a New Index: Security Maturity and AI Governance Maturity Multiply, They Do Not Add

For years, organizations have told us they were “secure enough” based on general security posture alone. This year’s data says that instinct is wrong, and we built a new composite measure specifically to make the point unmistakable.

The Data Security and Compliance Readiness Index, or DSCRI, combines the Data Security Maturity Score and the AI Governance Maturity Score using a multiplicative formula rather than an additive one. Across all 459 respondents, the survey mean landed at 16.2 out of 100. The mean Data Security Maturity Score alone was 39 out of 100; the mean AI Governance Maturity Score was 35 out of 100. Multiplied together, those two middling numbers produce a genuinely poor composite score, because a strong general security program cannot compensate for AI-specific governance gaps, and vice versa. One does not substitute for the other.

The clearest illustration of what that gap costs in practice is the incident-rate divide between our highest- and lowest-maturity organizations. Organizations that reached the top maturity tier reported AI incidents at a 34% rate. Organizations in the lowest maturity tier reported them at 91%. That is not a gradual slope between the two groups. It is a fork in the road, and which side an organization lands on has far less to do with overall spend than most executives assume. A formal risk assessment that evaluates both AI-specific governance controls and general security maturity simultaneously — rather than treating them as separate audit tracks — is what surfaces the multiplicative gap before a compliance event forces the calculation in the other direction.

Budget Does Not Predict Maturity — Architecture Does

This is the finding I keep returning to when I brief executives on this year’s results. When we plotted every organization in the survey across two axes — general security maturity and AI-specific governance maturity — the pattern that emerged was not about company size or spend.

Global enterprises, the organizations carrying the largest security budgets in our sample, had the lowest representation in the top maturity tier of any size band we measured. Mid-sized organizations, operating with a fraction of that budget, outperformed them. The same pattern held across industry: Defense Contractors and Federal Government respondents, the sectors handling some of the most sensitive data in the economy, showed zero representation in the top maturity tier. Energy and Utilities, a sector nobody names first when discussing AI governance leadership, produced some of the strongest individual scores in the entire dataset.

The regional breakdown tells a similar story. North American organizations were the only region with meaningful representation in the top maturity tier. Middle Eastern organizations were the most concentrated in the bottom tier of any region surveyed, and least represented at the top — a pattern that tracks with lower overall security maturity scores, not a lack of awareness. Every region we surveyed ranked data sovereignty among its top compliance concerns; very few had the zero trust architecture or technical enforcement layer to back that concern up in practice.

Budget buys a security program. It does not automatically buy the specific, AI-focused controls — ABAC enforcement, tested termination capability, centralized audit logging — that determine whether that program actually holds up when it is tested by a real incident. Data classification applied consistently across all AI-accessible content is a foundational prerequisite that budget alone cannot guarantee: organizations with large security programs frequently discover their classification infrastructure is incomplete or inconsistently enforced across channels, which is why enforcement gaps persist even where investment is substantial.

Third-Party AI Vendor Risk Is Compounding the Internal Gap

Internal governance gaps do not exist in isolation. Twenty-seven percent of organizations have not evaluated or technically verified whether the AI vendors they rely on use their data for model training, which means over a quarter of organizations are extending sensitive data into third-party systems on trust alone. The Black Kite 2026 Third-Party Breach Report documented 136 verified third-party breach events in 2025, with a median disclosure lag of 73 days between compromise and notification — meaning an organization can be exposed by a vendor’s failure for more than two months before it even learns a breach occurred.

Nineteen percent of organizations have never tested or exercised their own third-party access revocation capability, which mirrors the internal kill switch problem at the vendor layer. A vendor risk management program that has not confirmed it can actually cut a vendor’s access on demand is making the same kind of untested representation this report flags as risky when organizations make it about their own internal AI systems. Supply chain risk management disciplines that formally test third-party access revocation on a recurring schedule — rather than documenting the capability and assuming it works — are the organizational practice that closes the mirror gap between internal kill switch maturity and third-party revocation maturity.

Shadow AI and Fragmented Data Exchange Are Compounding the Gap

Sixty-five percent of organizations discovered shadow AI usage in the past 12 months — employees routing sensitive data through AI tools the organization never approved or provisioned. Only 43% have centralized their AI gateway into a single control point, which means most organizations are still trying to govern AI activity from five or six different vantage points simultaneously. You cannot enforce a consistent policy across a system you cannot see consistently.

That fragmentation is not limited to AI tools. Sixty-two percent of organizations operate fragmented sensitive data exchange environments across managed file transfer, secure email, file sharing, and web forms — creating inconsistent security policies and multiple points of exposure rather than one governed perimeter. Among organizations using MFT specifically, only 26% stream logs to SIEM in real time, and only 39% maintain tamper-evident audit trails for that channel. Fragmentation and audit gaps reinforce each other: the more scattered the infrastructure, the harder it becomes to produce a single, defensible record of what happened, when, and to whom. The CISO Dashboard provides the unified, real-time visibility across all content exchange channels — MFT, email, file sharing, AI agents — that makes a single defensible record possible without requiring organizations to manually aggregate logs from five disconnected systems.

Classification tells the same story from a different angle. Fifty-five percent of organizations have not achieved automated data governance and classification across all major systems, and only 39% can enforce tagging and classification consistently across channels. Classification that does not enforce downstream controls is not governance — it is a label on a folder. Data Security Posture Management closes part of this gap by providing continuous discovery as data moves across systems, channels, and AI pipelines, but discovery alone does not stop a misdirected file. It has to be paired with enforcement at the point of transmission, not just visibility after the fact. Data minimization applied at the AI data boundary — ensuring agents and models receive only the minimum content their designated task requires — further reduces the blast radius of any governance gap by constraining how much sensitive data can be exposed through any single ungoverned channel.

Governance ownership itself is part of the problem. Thirty-nine percent of organizations treat AI data governance as an add-on to an existing security or IT role rather than a dedicated responsibility, and only 24% have a dedicated team assigned to it. When accountability is a side project bolted onto someone’s existing job description, the controls that require sustained, ongoing attention are consistently the first ones to slip once budget season or a competing priority shows up.

What Separates the Organizations Getting This Right

Across every cut of this year’s data — industry, size, and region — the same three characteristics showed up consistently in the organizations that scored well:

  • A kill switch that has been tested on a recurring schedule, not documented once and left alone
  • Access scoped narrowly enough that revoking it does not require untangling a web of inherited permissions
  • Centralized, tamper-evident audit logging built for fast retrieval, not just long-term storage

None of these are expensive relative to a typical security budget. All three are architectural decisions rather than line-item purchases, which is exactly why spend alone does not predict which organizations have them. This is the core thesis behind Kiteworks Compliant AI: governing the data-to-AI boundary requires the same disciplined incident response planning, vendor risk management, and centralized visibility that mature data security programs have applied to every other channel for years. AI does not require a different governance philosophy. It requires the existing one, applied consistently, and enforced technically rather than attested to on paper. The data control pane delivers the unified governance environment — one policy engine, one audit trail across all content channels and AI workflows — that makes those three architectural decisions operational rather than aspirational.

What This Means Going Into 2027

We predicted this gap a year ago in our Forecast Report, and the honest surprise in this year’s data is not that the gap exists. It is that organizations widened it instead of closing it while AI deployment kept accelerating underneath. That is not a technology failure. It is a sequencing failure — deploying first and addressing containment later, when the two need to move together from the start.

If your organization is running AI in production right now, the single most useful question to ask this week is not whether you have a kill switch. It is when it was last tested, how long the test took, and what broke. If nobody in the room can answer that with specifics, the honest answer is that a kill switch does not exist yet. What exists is a plan to build one, and this year’s data says that plan is one incident away from being tested for the first time under the worst possible conditions.

The organizations that closed this gap in the past year did not do it by waiting for a bigger budget cycle. They did it by treating three things as operational requirements with owners and test schedules rather than as documentation exercises: a kill switch that gets exercised on a calendar, access that is scoped narrowly enough to revoke cleanly, and audit logging built to answer a regulator’s question in hours rather than days. That is a shorter list than most organizations expect, and it is exactly why the gap between the top and bottom maturity tiers is as wide as this year’s data shows it to be.

To learn more about closing the gap between your organization’s security posture and its AI-specific governance controls, schedule a custom demo today.

Frequently Asked Questions

It is Kiteworks’ annual primary research study, based on responses from 459 security, compliance, and technology professionals across North America, Europe, and the Middle East. The report measures organizations’ AI data governance maturity alongside their general data security posture, using two composite scores — the Data Security Maturity Score and the AI Governance Maturity Score — combined into a single Data Security and Compliance Readiness Index. Organizations subject to regulatory compliance obligations should treat the 16.2/100 DSCRI mean as a sector-wide baseline: it quantifies the governance gap that frameworks like HIPAA, GDPR, and CMMC will increasingly evaluate AI data access governance against, not just human user access governance.

Seventy-nine percent of organizations surveyed lack a tested kill switch for their AI systems, and only 21% have deployed one formally. Among organizations already running AI in production, 23% have never tested their termination process end to end, meaning even the minority with a kill switch often cannot confirm it works under real conditions. Kiteworks recommends scheduling recurring incident response drills against this specific control rather than treating it as a one-time deployment task. Organizations should also verify that their kill switch test covers AI agents operating under non-human identities — an agent credential that cannot be revoked cleanly is the same untested assumption at the machine identity layer that an untested human-initiated kill switch represents at the user layer.

The survey found that organizations with the largest security budgets, including global enterprises, had the lowest representation in the top maturity tier of any size band measured. Mid-sized organizations with far smaller budgets outperformed them, because the controls that matter most — tested kill switches, ABAC enforcement, centralized audit logging — are architectural decisions rather than purchases sized to budget. Larger organizations often carry more organizational complexity and legacy fragmentation, which can offset the advantage of a bigger security spend. Data classification infrastructure consistently enforced across all AI-accessible systems is the foundational prerequisite that budget alone cannot purchase: it requires architectural decisions about how content is labeled and how those labels propagate to access policy enforcement.

The DSCRI multiplies the Data Security Maturity Score by the AI Governance Maturity Score rather than adding them together, which means weak performance on either dimension pulls the combined score down significantly. The survey mean came in at 16.2 out of 100, reflecting mean component scores of 39 and 35 respectively. This design choice reflects a real operational finding: strong general security cannot substitute for AI-specific governance controls, and organizations need to invest in both simultaneously rather than assuming one covers the other. Supply chain risk management maturity is one of the AI Governance Score components that most frequently suppresses the composite — organizations with strong internal controls but unverified third-party AI vendor governance score poorly on the vendor risk dimension, which the multiplicative formula amplifies rather than smooths over.

Sixty-three percent of organizations reported at least one compliance consequence tied to an AI governance gap in the past 12 months, including audit findings, required remediation plans, board escalations, contractual penalties, and formal regulatory investigations. Half of surveyed organizations could not produce a complete AI access record within one business day of a request, a retrieval delay that functions as evidence of inadequate governance under frameworks like GDPR that assume on-demand accountability. Organizations should treat audit trail retrieval speed as a measurable control, not an afterthought. Data governance programs that maintain AI access logs in a queryable, tamper-evident format — integrated with a SIEM for real-time alerting rather than stored only for post-incident retrieval — are the ones that can meet a one-business-day audit record request without treating it as a crisis.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks