Chapter 7

The Governance Gap

Deployment is outpacing governance — manual guardrails, trailing security, and incidents at scale.

Georgian + NewtonX AI, Applied Benchmarks, Wave 3 (n=252 Technical Decision Makers) · March–April 2026

AI production deployment — especially in R&D, with agent-based coding — appears to be moving faster than the IT governance structures needed to manage it. Securing AI products appears to be lagging behind AI adoption. While IT guardrails are often a blend of automated and manual controls, our data suggests a larger reliance on manual controls around AI products. As a result, we see AI-related security incidents happening at scale. This gap is not theoretical, and it appears to be widening.

Finding 1

Incidents are a production reality

The governance gap is not a risk on the horizon — it is a production reality. More than half of B2B software technical decision makers report experiencing an AI-related incident in the past year. The most common is hallucinations causing business errors, at 40% — statistically equal to the 44% who cite hallucinations as their top barrier to scaling agentic AI.

While the impact of some of these incidents is only internal, we believe the potential for external incidents such as data leakage, jailbreak attacks, and compliance exposure sits at levels unacceptable for the vast majority of technical decision makers.

Experienced at least one AI-related incident

Experienced at least one AI-related incident

55% of technical decision makers experienced at least one AI-related incident in the past 12 months — most commonly hallucinations causing business errors (40%).

0%

AI-related incidents in the past 12 months

“Which AI-related incidents has your organization experienced in the past 12 months?” Technical Decision Makers · n=252 · Wave 3. Causality between guardrails and incidents is not implied.

0%10%20%30%40%Hallucination causing business errorHallucination causing business error — % experienced: 40%40%Policy or compliance violationPolicy or compliance violation — % experienced: 21%21%Data leakage or unintended exposureData leakage or unintended exposure — % experienced: 17%17%Prompt injection or jailbreakPrompt injection or jailbreak — % experienced: 14%14%

“Which AI-related incidents has your organization experienced in the past 12 months?” Technical Decision Makers · n=252 · Wave 3. Causality between guardrails and incidents is not implied.

Finding 2

The Runner paradox

55% of all technical decision makers say AI adoption has moved ahead of their security capabilities — but the organizations furthest along in AI deployment are the most aware of the security lag their own velocity has created. We view this not as a comment on security at Runner-tier organizations, but as evidence that deployment speed has outpaced security program adaptation.

Runners saying AI adoption is ahead of security

Runners saying AI adoption is ahead of security

67% of Runners say their AI adoption has moved ahead of their security capabilities — the highest of any maturity tier, versus 55% across all technical decision makers.

0%

“AI adoption is ahead of our security,” by segment

“How would you describe the balance between AI adoption and AI security capabilities?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

0%20%40%60%80%RunnerRunner — % saying AI ahead of security: 67%67%CrawlerCrawler — % saying AI ahead of security: 65%65%Growth-stageGrowth-stage — % saying AI ahead of security: 58%58%JoggerJogger — % saying AI ahead of security: 52%52%EnterpriseEnterprise — % saying AI ahead of security: 52%52%WalkerWalker — % saying AI ahead of security: 45%45%

“How would you describe the balance between AI adoption and AI security capabilities?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

Finding 3

Guardrails lean manual

While the data shows most technical decision makers using around three AI guardrails on average, it also suggests a guardrail automation gap may exist between manual approaches and automated ones. Human approval gates are the most common single guardrail (75%), and the most formalized automated enforcement is the least adopted (policy-as-code, 29%) — suggesting teams lean on human review and lighter-weight automated controls rather than codified runtime policy.

The guardrail automation gap

The guardrail automation gap

75% rely on human approval gates while only 29% use policy-as-code enforcement — a 46-point gap between manual and automated guardrails.

+0pts
AI guardrails in place

“Which AI guardrails does your organization currently have in place?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

0%20%40%60%80%Human approval gatesHuman approval gates — % adopted: 75%75%Sandboxed environmentsSandboxed environments — % adopted: 56%56%Role-based constraintsRole-based constraints — % adopted: 48%48%Monitoring & audit logsMonitoring & audit logs — % adopted: 46%46%Safe-action / allow listsSafe-action / allow lists — % adopted: 40%40%Policy-as-code enforcementPolicy-as-code enforcement — % adopted: 29%29%No guardrails in placeNo guardrails in place — % adopted: 6%6%

“Which AI guardrails does your organization currently have in place?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

Finding 4

Two threats dominate the agentic landscape

The agentic threat landscape has a clear center of gravity among those surveyed. Excessive agency — over-permissioned agents with read, write, or deploy access that create a large blast radius when compromised — is ranked #1 by 32% of technical decision makers. Prompt injection — inputs that redirect agent behavior — is ranked #1 by 28%. Together they account for 60% of all #1 rankings; no other category reaches 15%. Both are characteristically agentic: they exist because agents take autonomous actions in response to inputs. These are new threat categories directly named as a result of AI.

As this benchmark series continues, we will track the evolution of cybersecurity and its ability to reduce AI threat-vector concerns and reduce incident rates.

Two threats account for most top-ranked concerns

Two threats account for most top-ranked concerns

Excessive agency (32%) and prompt injection (28%) together account for 60% of all #1-ranked agentic security concerns — no other threat category reaches 15%.

0%

Greatest agentic AI security concern (ranked #1)

“Which agentic AI security threat is your greatest concern?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

0%10%20%30%40%Excessive agency / over-permissioningExcessive agency / over-permissioning — % ranked #1: 32%32%Prompt injection attacksPrompt injection attacks — % ranked #1: 28%28%Credential or secret exfiltrationCredential or secret exfiltration — % ranked #1: 11%11%Supply-chain attacksSupply-chain attacks — % ranked #1: 7%7%MCP / agent-tool exploitsMCP / agent-tool exploits — % ranked #1: 6%6%Log & audit-trail blind spotsLog & audit-trail blind spots — % ranked #1: 6%6%Memory & context poisoningMemory & context poisoning — % ranked #1: 4%4%

“Which agentic AI security threat is your greatest concern?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

Finding 5

Security is shifting left, but not far enough

AI security appears to be entering into consideration earlier in the AI development lifecycle — 63% of technical decision makers now integrate security at the requirements or early-development phase, and Runners lead at 73% early integration versus 56% of Walkers. But 31% still integrate security late in development or only after deployment, and 5% report no formal AI security integration at all. Late-stage security integration may be linked to the higher AI incident rates noted in Finding 1.

Integrate AI security early or at requirements

Integrate AI security early or at requirements

63% of technical decision makers integrate AI security at the requirements or early-development phase — but 31% still integrate late or never.

0%

When AI security is integrated

“At what stage does your organization integrate AI security considerations?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

Stage of integration31%32%20%0%100%
At requirementsEarly in developmentLate in developmentOnly after deploymentNo formal integration

“At what stage does your organization integrate AI security considerations?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)

Finding 6

A governance gap in the org chart

The governance gap is not only a security-tooling story — it is reflected in organization design. Roughly a third of surveyed B2B companies have no formal AI governance structure at all, and the shortfall is not evenly distributed. Ad hoc is the single most common operating model on the go-to-market side (33%), while technical decision makers most often report a hybrid structure and are less likely to be operating with no structure at all (27%). The starkest contrast is the centralized Centre of Excellence: 25% among technical decision makers against 16% in GTM.

We believe this is a gap that needs to be filled quickly and adequately. It is not just a security risk; it is a general risk to your AI strategy overall, across all dimensions — productivity, ROI, and costs — along with security concerns. And on the evidence here, the commercial organization is roughly a maturity rung behind the technical one in closing it.

No formal AI governance structure

No formal AI governance structure

33% of GTM decision makers report an ad hoc AI operating model with no formal governance structure, against 27% of technical decision makers — a governance gap at the organizational layer, widest on the commercial side.

0%

AI operating model — GTM vs technical decision makers

“How is AI ownership and delivery primarily structured in your organization today?” GTM Decision Makers n=249 · Technical Decision Makers n=252 · Wave 3 · single-select · a further 2% of GTM decision makers answered unsure

0%10%20%30%40%Ad hoc / no formal structureAd hoc / no formal structure — GTM: 33%33%Ad hoc / no formal structure — Technical: 27%27%Hybrid (CoE + federated)Hybrid (CoE + federated) — GTM: 31%31%Hybrid (CoE + federated) — Technical: 33%33%Federated pods onlyFederated pods only — GTM: 20%20%Federated pods only — Technical: 14%14%Centralized CoECentralized CoE — GTM: 16%16%Centralized CoE — Technical: 25%25%
GTMTechnical

“How is AI ownership and delivery primarily structured in your organization today?” GTM Decision Makers n=249 · Technical Decision Makers n=252 · Wave 3 · single-select · a further 2% of GTM decision makers answered unsure