Full Breakdown
AI Adoption Outpaces Security Governance, Survey Finds
7/10/2026, 12:31:38 PM
Rapid AI Tool Deployment and Rising Incidents
A recent DigiCert survey shows that 75 % of organizations have deployed four or more AI tools in the past six months, and 35 % have rolled out more than ten. Despite this acceleration, 78 % (four in five) report having experienced an AI-related security incident or identified a vulnerability. The data suggest that AI is no longer experimental but a core business component, yet security breaches are becoming commonplace.
Governance Shortfalls and Emerging Inventory Practices
While 90 % of respondents say AI governance is discussed at the executive or board level, only half have established both dedicated AI security budgets and formal governance programs. Two-thirds (64 %) have begun logging AI inventories, indicating many firms are still mapping the tools they use. Nearly half lack centralized visibility into AI systems, and just 53 % can fully trace AI outputs back to the underlying models and source data, highlighting significant oversight gaps.
Expert View on Explainability and Trust
DigiCert recommends treating AI like any other enterprise system, embedding security throughout the strategy rather than viewing it as a pilot project. SVP Brian Trzupek emphasizes that the central challenge has shifted from adoption to accountability: organizations must be able to explain, govern, and trust the AI they have already deployed.
Implications for Organizations
The survey underscores a growing security headache for companies across sectors such as science, technology, banking, telecoms, and retail. Without robust governance, the risk of undetected vulnerabilities rises, potentially exposing sensitive data and undermining operational reliability. Firms that invest in dedicated AI security budgets, formal governance frameworks, and comprehensive inventory tracking are better positioned to mitigate these risks as AI adoption continues to expand.
Verbatim Quote
"The question is no longer whether organisations should adopt AI. It's whether they can explain, govern and trust the AI they've already deployed." — Brian Trzupek, SVP, DigiCert
