AI adoption is moving faster than security governance
AI use in cybersecurity is accelerating, but governance is not keeping pace. That is the central finding from a SANS Institute report based on a global survey of 536 cybersecurity and IT practitioners. The research also included a dedicated group of 57 senior security leaders, including chief information security officers, chief security officers, and security vice presidents.
The core issue is not whether AI can improve cyber defense. It can help security teams analyze threats, automate tasks, and expand testing. The constraint is control. Organizations are putting AI into security workflows faster than they are establishing clear rules for how these systems access data, make decisions, and are monitored.
This matters because security systems routinely interact with sensitive information. AI can introduce additional questions about what data enters a model, where that data is processed, who can access outputs, and whether human review is required. Governance should answer these questions before deployment. A written policy alone is not enough. Controls need to operate inside the actual tools and workflows used by security teams.
The SANS findings indicate that many organizations have not reached that point. AI deployment is advancing while practical guardrails remain uneven. This creates an avoidable governance gap: companies may gain new security capabilities while also introducing risks that management cannot consistently see or control.
For executives, the priority should therefore be operational governance rather than slower AI adoption. Boards and management teams need evidence that AI controls work in practice. That includes defined ownership, approved use cases, data-handling requirements, access controls, monitoring, and escalation procedures when systems behave unexpectedly.
The opportunity remains significant. Companies do not need to choose between AI innovation and strong governance. But the sequence matters. As AI becomes part of core cyber defense, its controls must become part of core enterprise risk management. The companies that establish that discipline can expand AI use with greater confidence and clearer accountability.
Security leaders and practitioners see AI governance differently
50% of security leaders say their organization has a formal AI risk management program. Only 36% of frontline practitioners say the same. That 14-percentage-point difference is one of the clearest governance problems identified by the SANS Institute research.
Matt Bromiley, a certified instructor at the SANS Institute and author of the report, called the difference a “perception problem.” Security leaders may believe formal governance exists, while employees responsible for operating security tools do not see equivalent controls in their daily work. As Bromiley put it, leaders believe there is real governance, but “the people running the tools can’t see” legitimate guardrails on the ground.
This distinction matters. A company can have an AI policy without having effective AI governance. Policies define expectations. Operational controls determine what employees and systems can actually do. If practitioners cannot identify approval requirements, data restrictions, access controls, monitoring processes, or escalation procedures, executives should not assume that a documented framework is working as intended.
Communication may explain part of the gap, but it should not be the default conclusion. The more important question is whether controls are technically and operationally enforceable. For example, organizations need to know which AI tools security teams use, what sensitive information those tools can process, who can approve new uses, and how violations are detected. These controls should produce evidence that management can verify.
The SANS survey provides important context. It covered 536 cybersecurity and IT practitioners globally and included a dedicated module of 57 senior security leaders, such as chief information security officers, chief security officers, and security vice presidents. The results measure respondents’ reported perceptions, so the 14-point gap does not by itself prove that controls are absent. It does show that leaders and practitioners do not have a consistent view of their governance environment.
For the C-suite, that inconsistency is itself a risk signal. Effective governance should be visible from policy through execution. Leaders should test whether stated controls appear in actual security workflows and whether practitioners understand how to apply them. Closing the gap requires more than better messaging. It requires governance that employees can identify, use, and demonstrate in practice.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Weak cybersecurity governance can become a financial risk
Cybersecurity governance now matters beyond the security function. S&P has previously warned that companies could put their credit ratings at risk if they fail to strengthen security governance. That makes cyber oversight relevant to the CEO, CFO, board, and other executives responsible for enterprise risk.
The reason is straightforward. A serious cyber incident can disrupt operations and create substantial costs. The financial impact can include remediation expenses, lost revenue, legal liabilities, and other business consequences. Weak governance can increase exposure by leaving unclear who owns security risks, how controls are enforced, and when senior management must intervene.
AI adds another governance requirement. As companies introduce AI into security operations, executives need clear oversight of the systems, data, and decisions involved. The SANS findings indicate that governance practices are not always keeping pace with adoption. That matters when AI tools can interact with customer information or other sensitive corporate data.
The S&P warning does not mean that every governance weakness will cause a credit downgrade. Credit ratings consider a wider set of business and financial conditions. But cybersecurity can become relevant when an incident or persistent weakness has a material effect on a company’s operations, liquidity, reputation, or ability to meet financial obligations.
For executives, the key requirement is measurable control. Cybersecurity and AI governance should sit within enterprise risk management rather than remain isolated technical programs. Management needs clear accountability, defined risk thresholds, tested controls, and reliable reporting that allows the board to understand material exposure.
Strong governance therefore supports more than regulatory compliance. It gives management better information for allocating capital, approving technology deployments, and deciding which risks the company is prepared to accept. As AI use grows, companies that can demonstrate effective controls will be better positioned to expand adoption without adding unmanaged financial risk.
AI is becoming a standard tool for red teaming
60% of practitioners surveyed by SANS said their security programs use AI for red teaming, up from about one-third in the previous year’s survey. That increase shows how quickly AI is moving from experimentation into active cybersecurity work.
Red teaming tests an organization’s defenses by simulating techniques that real attackers could use. AI can support this work by helping security teams generate test scenarios, analyze potential weaknesses, and handle parts of the testing process more efficiently. The objective is to identify vulnerabilities before they can contribute to a real security incident.
The year-over-year increase also reinforces the report’s central governance concern. More AI use means more systems, data flows, permissions, and outputs to control. Red teaming is particularly sensitive because the work can involve information about vulnerabilities, system configurations, attack techniques, and other security-critical data. Organizations need explicit rules governing what information can enter AI systems and how generated content can be used.
The SANS result is important, but its scope should remain clear. The survey shows reported adoption among practitioners; it does not establish that AI makes red teams more effective or produces better security outcomes. Nor does the increase from roughly 33% to 60% explain which AI technologies respondents use or how extensively they use them. The data demonstrates rapid adoption.
For executives, that distinction should shape investment decisions. Measuring the number of AI tools deployed says little about their business value. Security leaders should instead track whether AI reduces testing time, increases useful vulnerability discovery, improves coverage, or allows skilled employees to focus on higher-value investigations. Those gains should be measured against new security and governance risks.
The right response is not to restrict useful AI by default. It is to make governance part of deployment. Organizations should define approved AI tools and use cases, control access to sensitive data, validate important outputs, maintain appropriate human oversight, and monitor how the technology is used.
AI adoption in red teaming is already moving quickly. The 60% adoption figure suggests governance cannot be treated as a later-stage task. Companies that establish practical controls alongside deployment can pursue the productivity and defensive benefits of AI while maintaining clear accountability for how the technology operates.
Key highlights
- Governance must match AI adoption: AI is entering cyber defense faster than organizations are implementing effective controls. Executives should make governance part of deployment, with clear ownership, data rules, monitoring, and escalation processes.
- Close the 14-point governance gap: 50% of security leaders report formal AI risk management, versus 36% of practitioners. Leaders should verify that policies translate into controls frontline teams can identify, follow, and demonstrate.
- Treat cyber governance as financial risk management: S&P has warned that weak cybersecurity governance can put corporate credit ratings at risk. Boards and executives should integrate cyber and AI oversight into enterprise risk management rather than leave it within the security function.
- Govern AI red teaming as adoption scales: AI use in red teaming rose from about one-third of practitioners to 60% in a year. Organizations should measure security outcomes while controlling sensitive data, access, AI outputs, and human oversight.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


