CISOs Say They’re Managing AI Risk Without the Resources to Do It
Most security leaders did not get a bigger budget, a bigger team, or new expertise when generative AI landed on their desks. They got a bigger job. Strip away the headline concern number in Proofpoint’s newly released 2026 Voice of the CISO report and what is left underneath is the real story: a resourcing gap that nobody closed before handing CISOs the bill.
The report, based on a Censuswide survey of more than 1,600 CISOs across 16 countries conducted in May 2026, found that concern over generative AI as a security risk jumped 18 percentage points year over year. Seventy eight percent of CISOs now view GenAI as a security risk, and the same share say they are expected to manage AI related risk without a proportional increase in resources or expertise. Meanwhile, 79 percent now identify human risk, not malware or unpatched infrastructure, as their organization’s single biggest cyber vulnerability, up sharply from 66 percent a year earlier.
For a CISO or Chief Compliance Officer, these numbers describe a specific and familiar bind. The organization adopted generative AI tools faster than anyone built the controls, policies, or data governance infrastructure to keep pace. Employees are already using those tools with sensitive data, whether or not that use has been authorized, logged, or reviewed. And the person who owns the resulting risk on paper, the CISO, is being asked to answer for it with the same headcount and the same budget line they had before generative AI became a daily business tool.
Better AI literacy training will not resolve that on its own. It is a governance and evidence problem, and it points directly at the argument Kiteworks makes about AI data governance. The fastest way to close a resource gap that isn’t closing on its own is to stop trying to monitor every AI interaction after the fact and instead govern what sensitive data an AI tool can touch in the first place.
Key Takeaways
1. GenAI security concern rose 18 points in a single year.
Seventy eight percent of CISOs now view generative AI as a security risk, up from 60 percent in 2025, according to Proofpoint’s 2026 Voice of the CISO report.
2. CISOs are absorbing new AI risk without new resources.
Seventy eight percent say they are expected to manage AI related risk without a proportional increase in budget, staffing, or expertise, meaning accountability expanded faster than capability did.
3. Human risk overtook technical vulnerabilities as the top concern.
Seventy nine percent of CISOs now name human risk their organization’s biggest cyber vulnerability, up from 66 percent in 2025, and generative AI is a primary reason why.
4. UK CISOs see the exposure most clearly.
Sixty six percent of UK CISOs believe employees are likely to use AI in ways that could expose sensitive data, a direct description of shadow AI activity happening inside sanctioned business workflows.
5. Falling breach anxiety does not mean falling actual risk.
The share of CISOs who expect a material cyberattack in the next 12 months dropped to 61 percent from 76 percent, even as the underlying AI and human risk factors they described grew worse, a mismatch worth examining rather than taking at face value.
GenAI Security Concern Jumped 18 Points in a Single Year
An 18 point swing in one year is a large move for any risk category in a survey this size. Proofpoint’s Voice of the CISO series has tracked CISO sentiment across geographies and industries since 2022, and generative AI’s climb from 60 percent to 78 percent concern in twelve months outpaces the movement seen on more established risk categories like ransomware or supply chain compromise.
The timing explains part of the jump. Generative AI tools moved from experimental pilots to embedded, daily-use business software across nearly every function in the space of about two years. Sales teams use it to draft proposals. Legal teams use it to summarize contracts. Finance teams use it to model scenarios. Each of those workflows can involve pasting client data, contract terms, financial figures, or personal information from CRM and HR systems directly into a prompt window, often through a personal account outside any access controls the security team has visibility into.
That gap between usefulness and oversight is the practical definition of shadow AI, sanctioned business activity happening through unsanctioned or unmonitored AI channels. It does not require malicious intent. It requires only that generative AI got useful faster than governance got built, which is exactly what happened across 2025 and into 2026.
The concern jump also reflects a maturing understanding of what generative AI actually does with data. Early enterprise adoption treated GenAI largely as a productivity question, whether it saved time or improved output quality. The 2026 data suggests CISOs have moved past that framing and are now evaluating GenAI the way they would evaluate any other system that touches sensitive content, asking where the data goes, who can see it, how long it persists, and whether that handling satisfies the same regulatory obligations that apply to every other system in the environment. Under GDPR compliance obligations, under HIPAA, under sector specific rules, a regulator does not distinguish between a human employee mishandling protected data and an AI tool doing the same thing. The exposure is identical either way, and CISOs appear to be catching up to that reality faster than their budgets are.
You Trust Your Organization is Secure. But Can You Verify It?
CISOs Are Being Handed AI Risk Without the Resources to Manage It
The more consequential finding sits next to the concern statistic rather than inside it. Seventy eight percent of CISOs report being expected to manage AI related risk without a proportional increase in resources or expertise. Read plainly, that means the organization’s threat surface expanded, the CISO’s accountability for that surface expanded with it, and neither the budget nor the specialized skill set required to manage generative AI risk expanded to match.
This resourcing gap is not unique to Proofpoint’s findings. It echoes a broader pattern documented in the Kiteworks 2026 Data Security and Compliance Risk: Annual Forecast Report, which found that organizations are adopting AI capability on a much faster cycle than they are building the governance, staffing, and evidentiary infrastructure to manage what that capability touches. The result is a widening gap between what an organization can technically do with AI and what it can actually prove about how that AI handled sensitive data when a regulator, auditor, or opposing counsel asks.
That evidentiary gap is where the resourcing shortfall bites hardest. A CISO without additional headcount cannot manually review every prompt submitted to every generative AI tool across a workforce of any meaningful size. What that CISO can do, without hiring an AI specialist team, is change where the control sits. Rather than trying to monitor AI usage at the point of the interaction, which requires constant human oversight and scales linearly with headcount, the more sustainable model is to govern the data itself before it ever reaches an AI system, through policy enforcement built into Kiteworks Compliant AI. Content classification and access policy enforcement happen automatically at the moment data would flow into an AI workflow, which does not require the CISO to add analysts in proportion to AI adoption. It requires the CISO to move the control point.
This is also the argument that resonates most with the Chief Compliance Officer or Head of GRC reading alongside the CISO. Their problem is not detecting that an employee used an unauthorized AI tool after the fact. It is producing, on short notice, a defensible record showing what data an AI system was permitted to access, what policy governed that access, and what happened to the data afterward. An audit trail that already exists but was never built to evidentiary standard does not solve that problem when the regulator’s clock is already running.
Human Risk Overtakes Technical Vulnerabilities as the Top Concern
Seventy nine percent of CISOs now name human risk their organization’s biggest cyber vulnerability, up from 66 percent in 2025, a meaningful reordering of priorities. For years, CISO surveys tended to center technical vulnerabilities, unpatched systems, misconfigured cloud environments, aging infrastructure, as the dominant worry. Generative AI has shifted that center of gravity toward the person sitting at the keyboard, because generative AI is, structurally, a tool that turns a routine human action, typing a question or pasting a document, into a potential data exposure event.
Sixty six percent of UK CISOs specifically believe employees are likely to use AI in ways that could expose sensitive data. This is not a statement about a hypothetical future risk. It is a statement from security leaders about behavior they believe is already happening, today, inside their own organizations, through everyday workflows their teams rely on to get work done faster.
Traditional security awareness training was built to address a narrower category of human risk, recognizing a phishing email, avoiding a suspicious attachment, or choosing a strong password. Generative AI introduces a different kind of human risk, one where the unsafe action looks identical to the safe, productive, encouraged action. An employee pasting a customer contract into a GenAI tool to summarize it is doing exactly what the organization told them AI is for. The risk is not in the intent. It is in the absence of any technical control that distinguishes an approved AI destination from an unapproved one, or that enforces data classification before content ever leaves the corporate environment.
This distinction matters for where CISOs and compliance leaders invest next. Training reduces risk at the margins. It does not substitute for a technical control layer that can tell the difference between an authorized AI integration operating under governed ABAC policy and an employee’s personal account on a consumer AI tool, and that can enforce that difference automatically, at scale, without requiring a human reviewer to catch every instance.
Why Falling Breach Confidence Doesn’t Mean Falling Risk
One figure in the report cuts against the narrative of rising alarm. The share of CISOs who believe their organization is at risk of a material cyberattack in the next 12 months fell to 61 percent, down from 76 percent in 2025. Taken alone, that looks like good news, security postures improving, confidence rising.
Set beside the other findings, it reads differently. GenAI concern rose 18 points. Human risk concern rose 13 points. The specific worry about employees exposing sensitive data through AI use sits at 66 percent among UK CISOs. Against that backdrop, a 15 point drop in expected breach likelihood is not obviously a sign that risk actually declined. It may instead reflect a shift in what CISOs consider a breach worth worrying about, or fatigue with a threat that has become so pervasive it no longer registers as an acute, near term event the way a headline ransomware attack does.
There is a more troubling reading worth naming directly. Confidence and control are not the same thing, and a CISO can feel more settled about the traditional breach scenario, an external attacker exploiting a technical vulnerability, while remaining exposed to a newer category of risk that does not look like a breach at all. Sensitive data reaching an unauthorized AI system does not trip the same alarms as a ransomware payload or a credential stuffing attack. It can happen silently, through routine, well intentioned employee activity, with no external attacker involved and no obvious moment when someone would think to escalate it. A CISO’s overall risk posture can be simultaneously improving on paper and still expanding in a category their existing detection tools were never built to see.
Which argues for evaluating AI data exposure on its own terms rather than folding it into general breach likelihood. The controls that reduce classic breach risk, patching, endpoint detection, network segmentation, do very little to reduce the risk of an employee pasting protected health information into a public GenAI chat window. Different risk, different control set, and a resourcing conversation that treats the two as interchangeable will keep underfunding the one that is actually growing.
Closing the Gap by Governing AI Data Access Instead of Chasing Shadow AI
Across all five findings runs the same throughline, ownership of AI risk expanded well ahead of the tools, budget, and expertise available to manage it, and headcount growth alone will not close that mismatch. Security and compliance budgets are not going to scale linearly with the pace of enterprise AI adoption, and the survey data suggests most CISOs already know it.
The more durable answer is architectural. Instead of trying to monitor every prompt an employee submits to every generative AI tool, which requires resources most CISOs say they do not have, organizations can enforce policy at the point where sensitive data would flow into an AI system in the first place. Zero trust generative AI works on this model, verifying every request for data against policy before access is granted, regardless of whether the requester is a human employee or an AI agent acting on that employee’s behalf.
For organizations extending that governance to agentic AI and non-human identities specifically, the same principle applies through a Secure MCP Server, which lets an organization define exactly what data an AI agent can reach, under what conditions, and with what record kept of the interaction, rather than granting broad standing access and hoping monitoring catches misuse later. Governing the connection point instead of chasing every downstream interaction is what makes a flat security budget survive an expanding AI footprint.
It also solves the evidence problem the Chief Compliance Officer is living with. When policy enforcement happens automatically at the point of AI data access, the system generates a real time, granular record of what was permitted and why, rather than requiring someone to reconstruct that record after a regulator or auditor asks. An audit trail that merely exists is not the same as one that is evidence quality and ready to produce within the timeframe a regulatory inquiry demands, rather than the weeks it typically takes to assemble from scattered logs.
Nobody is going to hire their way out of this. The resourcing gap in Proofpoint’s data is not a staffing shortfall waiting on next year’s budget cycle, it is a design choice about where the control sits, and organizations can change that choice today by governing data access before an AI system ever sees it rather than watching for damage afterward.
To learn more about closing the AI governance gap without a proportional increase in headcount, schedule a custom demo today.
Frequently Asked Questions
The report, based on a Censuswide survey of more than 1,600 CISOs across 16 countries in May 2026, found that 78 percent of CISOs now view generative AI as a security risk, an 18 percentage point increase year over year. The same share, 78 percent, say they are expected to manage AI related risk without a proportional increase in resources or expertise, a gap that points directly to the case for automated AI data governance rather than manual oversight.
Generative AI adoption spread across enterprise workflows faster than most organizations built governance, staffing, or budget to match, so accountability for the resulting risk landed with the CISO by default rather than through a deliberate resourcing decision. Closing that gap without proportional headcount growth generally means shifting from monitoring AI usage after the fact to enforcing access controls at the point where sensitive data would reach an AI system.
Shadow AI refers to employees using generative AI tools, sanctioned or not, in ways that were never reviewed or governed by the security team, often by pasting sensitive data into a prompt outside any monitored channel. Sixty six percent of UK CISOs in the Proofpoint survey said they believe employees are likely to use AI in ways that could expose sensitive data, reflecting behavior they believe is already occurring rather than a hypothetical future risk, which is why enforcement needs to happen through policy and data classification rather than after-the-fact detection.
The share expecting a material cyberattack in the next 12 months fell to 61 percent from 76 percent, even as concern about generative AI and human risk both rose sharply. The likeliest explanation is that AI driven data exposure does not resemble a traditional breach and can occur through routine employee activity without tripping the detection tools built for external attacks, which is why organizations need AI data protection controls purpose built for AI data access rather than relying on general breach readiness metrics.
The most resource efficient approach is to govern data at the point it would flow into an AI system, rather than monitoring every individual AI interaction after the fact. Policy enforcement built into Kiteworks Compliant AI and a Secure MCP Server for agentic AI connections apply access rules automatically and generate an evidence quality audit trail as a byproduct, closing the resourcing gap Proofpoint’s CISOs describe without requiring a proportional increase in staff.
Additional Resources
- Blog Post
Zero‑Trust Strategies for Affordable AI Privacy Protection - Blog Post
How 77% of Organizations Are Failing at AI Data Security - eBook
AI Governance Gap: Why 91% of Small Companies Are Playing Russian Roulette with Data Security in 2025 - Blog Post
There’s No “–dangerously-skip-permissions” for Your Data - Blog Post
Regulators Are Done Asking Whether You Have an AI Policy. They Want Proof It Works.