Benchmark 4.1
AI security balance
Survey question
How would you describe the balance between your organization’s AI adoption pace and its security and risk management capabilities?
- Audience
- Technical Decision Makers · n=252
- In depth
- Ch 7 — The Governance Gap
55%
say AI adoption is ahead of their security capabilities — only 13% say security leads AI adoption
Technical Leadership · n=252 · Wave 3
| AI significantly outpacing | AI somewhat ahead | Roughly in balance | Security somewhat ahead | Security significantly ahead | |
|---|---|---|---|---|---|
| Share of technical leaders | 17% | 38% | 30% | 9% | 4% |
Technical Leadership · n=252 · Wave 3
Benchmark 4.2
Agentic AI guardrails
Survey question
Which of the following guardrails has your organization implemented for agentic AI systems?
- Audience
- Technical Decision Makers · n=252
- In depth
- Ch 7 — The Governance Gap
46 pts
separate human approval gates (75%) from policy-as-code (29%) — the governance stack leans manual, a potential risk given AI production levels in R&D
Technical Leadership · n=252 · Wave 3
| Category | % implemented |
|---|---|
| Human approval gates | 75% |
| Sandboxed environments | 56% |
| Role-based constraints and permissions | 48% |
| Monitoring and audit logs | 46% |
| Safe-action lists / allowlists | 40% |
| Policy-as-code | 29% |
| No guardrails in place | 6% |
Technical Leadership · n=252 · Wave 3
Benchmark 4.4
Agentic security threats
Survey question
Which of the following agentic threat vectors are of greatest concern to your organization? Rank up to 3, where #1 is most important.
- Audience
- Technical Decision Makers · n=252
- In depth
- Ch 7 — The Governance Gap
60%
rank excessive agency (32%) or prompt injection (28%) as their #1 agentic security concern — two threats that together dominate the agentic security agenda
Technical Leadership · n=252 · Wave 3
| Category | % ranked #1 | % in top 3 |
|---|---|---|
| Excessive agency / over-permissioned agents | 32% | 55% |
| Prompt injection | 28% | 49% |
| Credential and secret exfiltration | 12% | 40% |
| MCP / agent-tools exploitation | 6% | 38% |
| Agent-to-agent trust exploitation | 6% | 30% |
| Log and audit-trail blind spots | 6% | 26% |
| Supply-chain compromise via AI-assisted code | 7% | 21% |
| Memory and context poisoning | 4% | 19% |
Technical Leadership · n=252 · Wave 3
Benchmark 4.5
AI security integration
Survey question
At what point in the development process is security or risk management integrated into agentic AI systems?
- Audience
- Technical Decision Makers · n=252
- In depth
- Ch 7 — The Governance Gap
64%
integrate security early — at the requirements/design phase (33%) or during development (32%) — but 31% still integrate late or never
Technical Leadership · n=252 · Wave 3
| Requirements / design | During development | Testing / pre-deploy | After deployment | Rarely or never | |
|---|---|---|---|---|---|
| Share of technical leaders | 33% | 32% | 20% | 6% | 5% |
Technical Leadership · n=252 · Wave 3
Benchmark 4.6
AI-enabled security tool penetration
Survey question
What types of AI-enabled security tools has your organization implemented? Select all that apply.
- Audience
- Technical Decision Makers · n=252
- In depth
- Ch 7 — The Governance Gap
64%
have deployed AI-enabled identity and access management — the most frequently deployed AI security tool and 10 points ahead of email security at 54%
Technical Leadership · n=252 · Wave 3
| Category | % implemented |
|---|---|
| Identity and access management (IAM) | 64% |
| Email security | 54% |
| Data security | 50% |
| Penetration testing / red teaming | 46% |
| Continuous threat exposure monitoring | 46% |
| Security operations centre (SOC) | 43% |
| Supply chain security | 17% |
| None of these | 10% |
Technical Leadership · n=252 · Wave 3
Benchmark 4.7
Risk mitigation after AI incidents
Survey question
Which mitigations did your organization put in place following these AI-related incidents? Select all that apply.
- Audience
- Technical Decision Makers who reported an incident · n=139
- In depth
- Ch 7 — The Governance Gap
60%
responded by introducing or expanding human review and approval steps — the top mitigation of the eight measured, while the responses that change the system itself are the least used
Technical Leadership who reported an incident · n=139 · Wave 3
| Category | % adopting |
|---|---|
| Introduced or expanded human review / approval steps | 60% |
| Tightened prompts, guardrails, or instructions | 58% |
| Restricted data access or changed data handling policies | 42% |
| Increased monitoring, logging, or alerting on AI behaviour | 42% |
| Updated or added policy-as-code / enforcement rules | 29% |
| Limited or disabled affected AI features or use cases | 27% |
| Retrained, fine-tuned, or replaced models | 25% |
| Engaged external experts or vendors for review | 12% |
Technical Leadership who reported an incident · n=139 · Wave 3
Benchmark 4.8
AI vibe coding vs AI cybersecurity adoption
Survey question
Thinking about the areas where your organization is currently using AI, which specific AI tools, platforms, or vendors are you using?
- Audience
- Technical Decision Makers · n=235 answered
- In depth
- Ch 7 — The Governance Gap
+31 pts
adoption gap between AI automated coding and debugging (93%) and AI cybersecurity (62%) among technical decision makers — offense is outrunning defense
Technical Leadership · n=235 answered · Runner n=61 / Jogger n=90 / Walker n=70 / Crawler n=14 · Wave 3
| Category | Total | Runner | Jogger | Walker | Crawler |
|---|---|---|---|---|---|
| Automated coding and debugging | 93% | 100% | 89% | 93% | 86% |
| Vibe coding solutions (low/no-code) | 78% | 85% | 79% | 76% | 50% |
| Cybersecurity and fraud detection | 62% | 77% | 67% | 53% | 14% |
Technical Leadership · n=235 answered · Runner n=61 / Jogger n=90 / Walker n=70 / Crawler n=14 · Wave 3