AI security incidents are already creating multimillion-dollar financial exposure
More than 40% of enterprise decision-makers said AI-related incidents cost their organizations at least $2 million in the past year. That makes AI security a financial issue.
The exposure is also widespread. In a WitnessAI survey of 300 enterprise decision-makers, 86% said their organization had investigated at least one AI-related security or operational incident during the previous 12 months. Another 91% were concerned that AI agents could increase their financial risk.
The core problem is expanding access without equivalent control. AI systems can interact with corporate data, process sensitive information, and increasingly perform tasks on behalf of employees. Each additional connection or autonomous action creates another activity that companies need to identify, authorize, monitor, and audit.
For executives, incident cost is only part of the exposure. An AI failure can interrupt operations, expose confidential information, trigger investigation costs, and create legal or regulatory consequences. The exact impact will depend on how and where AI is deployed, but the survey results show that these risks are already material for many enterprises.
The priority should therefore be measurable control. Companies need to know which AI systems are operating, what data they can access, what actions they can perform, and who is accountable when something goes wrong. AI adoption can continue at speed, but security controls must develop at the same pace.
AI adoption is accelerating despite rising security risk
Worker access to AI increased 50% in 2025, according to Deloitte’s “State of AI in the Enterprise” report. Enterprises are expanding AI access even as security incidents become more common and expensive.
That combination matters. Conventional technology deployments often slow when security teams identify significant unresolved risk. AI adoption is behaving differently. Rick Caccia, CEO of WitnessAI, told Channel Dive that this is the first case he could recall in which risk was not slowing adoption. In his assessment, either organizations are not applying the usual brakes or those controls are no longer effective.
The reason is practical. AI can improve how employees find information, create content, analyze data, write software, and automate work. Employees can also access many AI services independently, without waiting for a large corporate deployment. Central IT therefore has less ability to control adoption through procurement alone.
This changes the executive decision. The choice is no longer simply whether to permit AI. Employees and business units are already adopting it. The real constraint is whether governance can keep pace with that use.
Companies should design controls around this operating reality. That means identifying the AI services in use, defining what corporate data they may access, setting rules for approved models and agents, and monitoring behavior continuously. Blocking every new tool is unlikely to be a durable strategy. Uncontrolled adoption is not acceptable either.
The opportunity is to make secure adoption faster. Enterprises that integrate governance into deployment can expand AI use while retaining visibility and accountability. Given the pace of adoption and the incident levels reported by WitnessAI, that capability is becoming a core requirement for enterprise AI programs.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
IT and infrastructure teams are the largest source of shadow AI activity
Shadow AI is now a direct enterprise security problem. It occurs when employees use AI tools without formal approval or outside company policies. WitnessAI’s survey found an unexpected source: IT and infrastructure departments account for the most shadow AI activity.
This matters because these teams often help define and enforce technology controls. Their unsanctioned AI use shows that the problem cannot be solved through employee policies alone. Technical staff have strong incentives to test new models, coding assistants, automation tools, and AI agents. They may also have broader access to sensitive systems and data than typical employees.
The data risk starts with what users send to external AI services. Employees can place source code, customer records, internal documents, credentials, or other confidential information into prompts and file uploads. Organizations may then have limited visibility into how the provider stores, processes, or reuses that information, depending on the service and contract terms.
Aditya Patel, cloud security specialist at Amazon Web Services (AWS), described the issue in a Cloud Security Alliance blog post: “Every prompt, upload, or query is a potential breach.” He added that the concern is not simply the volume of activity but its speed, arguing that AI-related risks can compound quickly.
Executives should focus on visibility before prohibition. Organizations need an accurate inventory of AI services, models, and agents in use. They also need clear rules for sensitive data, approved services, authentication, access rights, and logging. Controls should apply consistently to IT teams, developers, executives, and other employees.
The finding about IT is particularly important for leadership. A governance program has limited value when the teams responsible for implementing it work outside the same rules. Companies should examine why this happens. If approved AI tools do not meet technical teams’ needs, employees will have a strong incentive to find alternatives. Effective governance therefore requires usable, approved options alongside enforceable controls.
Enterprises are spending heavily on AI governance, but ownership remains unclear
More than half of respondents to the WitnessAI survey said their organizations allocate between 21% and 45% of AI spending to governance and risk management. That is a substantial commitment. Yet there is a more fundamental problem: many organizations still lack clear ownership of AI risk.
Rick Caccia, CEO of WitnessAI, summarized the uncertainty directly: “Is it the CFO? Is it the CEO? Is it legal? Who the heck owns control of AI risk?” The question matters because AI crosses several corporate functions. Security manages technical threats. Legal and compliance teams address regulatory and contractual exposure. IT manages systems and access. Business leaders decide where AI is deployed. Finance ultimately deals with its economic consequences.
Shared involvement is necessary, but unclear accountability is not. When nobody has final authority, decisions can become inconsistent. One business unit may approve a tool that security would reject. Legal teams may define data restrictions that are difficult to enforce technically. Incident response can also become slower when responsibility must be negotiated after an event occurs.
The scale of governance spending makes this an executive issue. Allocating 21% to 45% of an AI budget to risk management does not guarantee better control. Leadership needs to know what that spending produces: visibility into AI use, enforceable data policies, access controls, monitoring, incident response, and evidence that those measures reduce exposure.
A practical governance model should establish one accountable executive while distributing specific duties to the relevant functions. The exact owner will depend on the organization. What matters is explicit authority over policy, exceptions, risk acceptance, and escalation.
Governance should also support adoption rather than create avoidable delays. Business teams need a clear route to request and deploy approved AI services. Security teams need enough visibility to assess those services. Legal and compliance functions need reliable information about data handling and contractual terms. Executives need metrics that show both adoption and risk.
The central constraint is therefore not the size of the governance budget. It is accountability. Enterprises can spend heavily on AI controls and still remain exposed if authority, responsibilities, and enforcement are unclear.
Executives may have more confidence in AI oversight than their organizations can support
A 22-percentage-point gap separates C-suite executives and vice presidents on AI visibility. In WitnessAI’s survey, 68% of C-suite respondents said they were confident in their visibility into the AI tools, models, and agents accessing company data. Only 46% of VP-level respondents expressed the same confidence.
This difference matters because VP-level leaders are often closer to implementation and daily operations. Their lower confidence may indicate that senior executives have an incomplete view of AI use across the business. The survey alone does not prove that C-suite assessments are wrong, but the size of the gap gives leaders a clear reason to verify their assumptions.
Visibility becomes harder as AI use expands. A company may need to track approved enterprise platforms, public generative AI services, embedded AI features in existing software, developer tools, and autonomous agents. Procurement records alone may not reveal all of this activity, particularly when employees can access external services directly.
Rick Caccia, CEO of WitnessAI, identified visibility as the first requirement for control. The principle is practical: a company cannot consistently govern AI systems it does not know are being used. Effective oversight requires information about which systems are active, who uses them, what corporate data they access, and whether their behavior complies with policy.
For C-suite leaders, the priority is to replace confidence with evidence. Security and technology teams should provide measurable indicators of AI usage, unauthorized services, sensitive-data interactions, access rights, and policy violations. Reporting should also reconcile differences between what executives believe is deployed and what operational teams observe.
The 68% versus 46% confidence gap should therefore be treated as a governance signal rather than simply a difference of opinion. A reliable AI program needs a common operational view across leadership levels. Better visibility gives executives the information required to make faster decisions without accepting unnecessary risk.
Enterprise AI security creates a substantial opportunity for channel partners
Enterprises are spending heavily on AI governance while still struggling with visibility, shadow AI, security incidents, and unclear accountability. That combination creates demand for outside expertise. Channel partners can help organizations move from broad AI policies to controls that work in production.
Rick Caccia, CEO of WitnessAI, described this as a “generational opportunity for channel partners” because enterprise clients are still determining how to manage AI. He argued that partners have an opening to provide both strategy and practical solutions.
The opportunity extends beyond selling another security product. Enterprises need help identifying the AI systems already in use, controlling access to sensitive data, selecting approved tools, monitoring AI agents, and integrating these controls with existing identity and security systems. Partners that can connect governance requirements with technical implementation can address a clear operational need.
The strongest proposition is measurable risk reduction. Customers should be able to see what a partner discovers, what controls it implements, and how those measures change exposure. Useful outcomes can include broader visibility into AI use, fewer unauthorized tools, stronger access controls, faster investigation of incidents, and clearer reporting for senior management.
Channel partners should also avoid treating every enterprise as having the same AI risk profile. A financial institution, software company, manufacturer, and healthcare provider can have different data requirements, regulatory obligations, and levels of AI maturity. Effective services need to reflect the customer’s systems, data sensitivity, compliance requirements, and business objectives.
For enterprise leaders, external partners can add capacity and specialized expertise, but accountability remains internal. A supplier can deploy technology and advise on governance; it cannot decide how much business risk an enterprise should accept. Executive leadership still needs to define ownership, approve policy, and set acceptable risk levels.
For channel partners, this creates a durable role if they can prove results. AI adoption is moving faster than many enterprises’ governance capabilities. Closing that gap with clear controls, measurable outcomes, and practical implementation is the business opportunity Caccia identifies.
Key takeaways for leaders
- AI incidents carry material financial risk: More than 40% of surveyed enterprises reported AI-related incident costs of at least $2 million in the past year. Leaders should treat AI security as a financial and operational risk, not only an IT issue.
- Adoption is outpacing security controls: Worker access to AI increased 50% in 2025 even as enterprises reported costly incidents. Executives should build governance into deployment rather than rely on security reviews to slow adoption.
- IT is the biggest source of shadow AI: WitnessAI identified IT and infrastructure teams as the leading source of unauthorized AI use. Leaders should apply data, access, and monitoring policies consistently, including to the technical teams responsible for enforcing them.
- Governance spending needs clear ownership: More than half of surveyed organizations dedicate 21% to 45% of AI spending to governance and risk management, yet accountability remains unclear. Assign one accountable executive with explicit authority over AI risk decisions and escalation.
- AI visibility has a leadership gap: 68% of C-suite respondents expressed confidence in AI visibility versus 46% of VPs. Executives should verify oversight with operational data showing which AI systems are used, what data they access, and where policy violations occur.
- Channel partners can close execution gaps: Enterprises need practical help turning AI governance policies into working controls. Partners that deliver measurable improvements in visibility, access control, monitoring, and incident response can capture this growing demand.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


