AI production deployment — especially in R&D, with agent-based coding — appears to be moving faster than the IT governance structures needed to manage it. Securing AI products appears to be lagging behind AI adoption. While IT guardrails are often a blend of automated and manual controls, our data suggests a larger reliance on manual controls around AI products. As a result, we see AI-related security incidents happening at scale. This gap is not theoretical, and it appears to be widening.
Finding 1
Incidents are a production reality
The governance gap is not a risk on the horizon — it is a production reality. More than half of B2B software technical decision makers report experiencing an AI-related incident in the past year. The most common is hallucinations causing business errors, at 40% — statistically equal to the 44% who cite hallucinations as their top barrier to scaling agentic AI.
While the impact of some of these incidents is only internal, we believe the potential for external incidents such as data leakage, jailbreak attacks, and compliance exposure sits at levels unacceptable for the vast majority of technical decision makers.
Experienced at least one AI-related incident
55% of technical decision makers experienced at least one AI-related incident in the past 12 months — most commonly hallucinations causing business errors (40%).
0%
“Which AI-related incidents has your organization experienced in the past 12 months?” Technical Decision Makers · n=252 · Wave 3. Causality between guardrails and incidents is not implied.
“Which AI-related incidents has your organization experienced in the past 12 months?” Technical Decision Makers · n=252 · Wave 3. Causality between guardrails and incidents is not implied.
Finding 2
The Runner paradox
55% of all technical decision makers say AI adoption has moved ahead of their security capabilities — but the organizations furthest along in AI deployment are the most aware of the security lag their own velocity has created. We view this not as a comment on security at Runner-tier organizations, but as evidence that deployment speed has outpaced security program adaptation.
Runners saying AI adoption is ahead of security
67% of Runners say their AI adoption has moved ahead of their security capabilities — the highest of any maturity tier, versus 55% across all technical decision makers.
0%
“How would you describe the balance between AI adoption and AI security capabilities?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
“How would you describe the balance between AI adoption and AI security capabilities?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
Finding 3
Guardrails lean manual
While the data shows most technical decision makers using around three AI guardrails on average, it also suggests a guardrail automation gap may exist between manual approaches and automated ones. Human approval gates are the most common single guardrail (75%), and the most formalized automated enforcement is the least adopted (policy-as-code, 29%) — suggesting teams lean on human review and lighter-weight automated controls rather than codified runtime policy.
The guardrail automation gap
75% rely on human approval gates while only 29% use policy-as-code enforcement — a 46-point gap between manual and automated guardrails.
“Which AI guardrails does your organization currently have in place?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
“Which AI guardrails does your organization currently have in place?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
Finding 4
Two threats dominate the agentic landscape
The agentic threat landscape has a clear center of gravity among those surveyed. Excessive agency — over-permissioned agents with read, write, or deploy access that create a large blast radius when compromised — is ranked #1 by 32% of technical decision makers. Prompt injection — inputs that redirect agent behavior — is ranked #1 by 28%. Together they account for 60% of all #1 rankings; no other category reaches 15%. Both are characteristically agentic: they exist because agents take autonomous actions in response to inputs. These are new threat categories directly named as a result of AI.
As this benchmark series continues, we will track the evolution of cybersecurity and its ability to reduce AI threat-vector concerns and reduce incident rates.
Two threats account for most top-ranked concerns
Excessive agency (32%) and prompt injection (28%) together account for 60% of all #1-ranked agentic security concerns — no other threat category reaches 15%.
0%
“Which agentic AI security threat is your greatest concern?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
“Which agentic AI security threat is your greatest concern?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
Finding 5
Security is shifting left, but not far enough
AI security appears to be entering into consideration earlier in the AI development lifecycle — 63% of technical decision makers now integrate security at the requirements or early-development phase, and Runners lead at 73% early integration versus 56% of Walkers. But 31% still integrate security late in development or only after deployment, and 5% report no formal AI security integration at all. Late-stage security integration may be linked to the higher AI incident rates noted in Finding 1.
Integrate AI security early or at requirements
63% of technical decision makers integrate AI security at the requirements or early-development phase — but 31% still integrate late or never.
0%
“At what stage does your organization integrate AI security considerations?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
“At what stage does your organization integrate AI security considerations?” Technical Decision Makers · n=252 · Wave 3 · Significant (95%)
Finding 6
A governance gap in the org chart
The governance gap is not only a security-tooling story — it is reflected in organization design. Roughly a third of surveyed B2B companies have no formal AI governance structure at all, and the shortfall is not evenly distributed. Ad hoc is the single most common operating model on the go-to-market side (33%), while technical decision makers most often report a hybrid structure and are less likely to be operating with no structure at all (27%). The starkest contrast is the centralized Centre of Excellence: 25% among technical decision makers against 16% in GTM.
We believe this is a gap that needs to be filled quickly and adequately. It is not just a security risk; it is a general risk to your AI strategy overall, across all dimensions — productivity, ROI, and costs — along with security concerns. And on the evidence here, the commercial organization is roughly a maturity rung behind the technical one in closing it.
No formal AI governance structure
33% of GTM decision makers report an ad hoc AI operating model with no formal governance structure, against 27% of technical decision makers — a governance gap at the organizational layer, widest on the commercial side.
0%
“How is AI ownership and delivery primarily structured in your organization today?” GTM Decision Makers n=249 · Technical Decision Makers n=252 · Wave 3 · single-select · a further 2% of GTM decision makers answered unsure
“How is AI ownership and delivery primarily structured in your organization today?” GTM Decision Makers n=249 · Technical Decision Makers n=252 · Wave 3 · single-select · a further 2% of GTM decision makers answered unsure