IT Brief US - Technology news for CIOs & IT decision-makers
United States
CISOs say AI risk falls with stronger security programmes

CISOs say AI risk falls with stronger security programmes

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

IANS and Artico Search have published a report on how Chief Information Security Officers view AI risk, based on a survey of 113 CISOs.

Respondents with more mature AI security programmes rated current AI risk at 3.7 out of 10 on average, compared with 7.8 among those with low AI security maturity.

The findings suggest security maturity is most closely linked to how exposed organisations feel now. But they also draw a distinction between current risk perception and confidence in managing AI risk over the next 24 months.

Longer-term confidence was tied more closely to organisational readiness than to security controls alone. Leadership understanding of AI risk, clear ownership of AI governance, control of AI security budgets and staffing levels were all stronger markers of confidence among the more optimistic CISOs.

Among CISOs who were optimistic about managing AI risk over the next 24 months, 80% said senior leadership had a fair or good understanding of AI risk. That compared with 48% of pessimistic respondents, a gap of 32 percentage points.

Differences also emerged in governance and budget. Some 74% of optimistic CISOs said AI governance ownership was clearly defined at their companies, compared with 40% of pessimistic respondents. Meanwhile, 81% of optimistic CISOs said they controlled the AI security budget, against 50% of those in the pessimistic camp.

The survey also pointed to a divide in how security teams are equipped to respond. Among optimistic CISOs, 70% said their security teams used AI effectively, compared with 38% of pessimistic respondents.

Staffing levels were another dividing line. Some 41% of optimistic CISOs reported having a fully staffed security team, compared with 9% of pessimistic CISOs, also a gap of 32 percentage points.

Present risk

The results indicate that CISOs distinguish between the risks they face now and their expectations for managing them in the near future. More developed AI security programmes appear to reduce concern about immediate exposure, but they do not on their own explain which leaders feel prepared for the next phase of AI adoption.

This distinction matters as companies bring more AI tools and systems into everyday operations. As the use of external models, application programming interfaces and third-party plug-ins expands, security leaders are under pressure to put oversight and accountability in place rather than rely solely on technical controls.

An earlier benchmark study from IANS and Artico Search found that 74% of AI environments already pull data from external sources through APIs, Model Context Protocol servers or third-party plug-ins. Yet only 29% of organisations had carried out adversarial testing.

Those figures point to a widening gap between enterprise AI adoption and the measures used to test and secure those environments. The latest report argues that preparedness depends not only on security programmes being in place, but also on whether the wider organisation understands and supports the work needed to manage AI-related threats.

Executive view

Steve Martano commented on the findings.

"Most AI risk data is based on vendor feedback, so it inevitably reflects the supply side of the equation," said Steve Martano, IANS Faculty and Partner, Artico Search.

"This report is different: it's grounded entirely in the perspectives of the executives who advise companies on AI risk decisions. What you're seeing here is the demand side from CISO practitioners speaking for themselves," Martano said.

Nick Kakolowski said one notable finding was the weak relationship between current anxiety about AI risk and confidence in managing it over time.

"One of the biggest surprises in our data is that how organizations feel about AI risk today has little bearing on how confident they are about managing it tomorrow," said Nick Kakolowski, Senior Research Director, IANS.

"AI security risk isn't an unsolvable problem - organizations that invest in stronger programs rate their risk far lower than those that don't. But long-term confidence comes from somewhere else: leadership that understands what is at stake, clear accountability for governance, and a security team with the capacity and budget to act," Kakolowski said.

Methodology

The findings were drawn from responses to the 2026 IANS AI Security Survey, conducted with Artico Search between April and May 2026. Respondents came from organisations across a range of industries, revenue bands and company types.

The report adds to a growing body of research examining whether businesses are putting governance structures around AI in place as quickly as they are adopting the technology. Its central conclusion is that stronger technical programmes may lower perceived risk now, but confidence in managing AI over the next two years is shaped more by leadership understanding, accountability and team readiness.

Among optimistic CISOs, 74% reported clearly defined AI governance ownership, 81% controlled the AI security budget and 70% said their security team used AI effectively.