Better AI security today does not guarantee confidence about tomorrow

CISOs can assess current AI risk as relatively low while remaining uncertain about their ability to manage it over the next 24 months. The 2026 IANS AI Security Survey, conducted with Artico Search between April and May 2026 among 113 CISOs, separates these judgments. Nick Kakolowski, Senior Research Director, IANS, called the weak relationship between them one of the biggest surprises in the data. He said how organisations feel about AI risk today has “little bearing” on how confident they are about managing it tomorrow.

For executives, the distinction matters because the judgments track different conditions in the survey. AI-security programme maturity has a strong association with lower perceived current risk. Future confidence instead appears alongside leadership understanding, governance ownership, budget authority, staffing and effective AI use by the security team. These are associations in CISO responses rather than evidence that one condition causes another.

AI exposure is already running ahead of one preparation measure

An earlier benchmark study from IANS and Artico Search found that 74% of AI environments pull data from external sources through APIs, Model Context Protocol servers or third-party plug-ins. APIs allow software systems to exchange data and invoke services. Model Context Protocol servers can connect AI systems to external data and tools. These connections expand the set of external systems involved in an AI environment.

Only 29% of organisations in that benchmark had conducted adversarial testing, which deliberately probes a system for weaknesses or unsafe behaviour under hostile or manipulative inputs. The two figures measure different things: external connectivity and the use of one testing practice. They do not establish that organisations without adversarial testing are insecure. They show that external connectivity is common while this specific testing method is much less common.

Steve Martano, IANS Faculty and Partner, Artico Search, described the 2026 survey as a view from executives advising companies on AI-risk decisions. He called CISO responses the “demand side,” contrasting them with AI-risk data derived from vendor feedback. IANS and Artico Search conducted the research, so they have a commercial and institutional interest in how its value is understood. The survey figures measure how security leaders assess their organisations; they are not direct measurements of technical compromise or losses.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Technical maturity changes how CISOs see current risk

The strongest reported result for present-day exposure is a 4.1-point gap on a 10-point scale. CISOs with more mature AI-security programmes rated current AI risk at an average of 3.7 out of 10, compared with 7.8 out of 10 among CISOs reporting low AI-security maturity. The result shows a strong association between reported programme maturity and perceived current risk.

Kakolowski argues that organisations investing in stronger programmes rate their risk substantially lower. The ratings support that characterization within the limits of a survey, but they do not establish that programme maturity caused the difference. Other differences between organisations could affect how their CISOs assess exposure.

The relationship changes when CISOs look ahead. IANS reports that current anxiety about AI risk has little relationship to confidence in managing that risk over the next 24 months. A CISO can give a relatively favorable assessment of current exposure while expressing less confidence about future management. The survey links that future judgment to a different set of organisational conditions.

Future confidence tracks organisational authority and capacity

The survey divides respondents into “optimistic” CISOs, who were confident about managing AI risk over the next 24 months, and a corresponding less-confident “pessimistic” group. The optimistic group reports stronger conditions across leadership understanding, governance ownership, budget authority, staffing and security-team use of AI. Governance ownership means clarity about who is accountable for setting and overseeing the organisation’s approach to AI.

Organisational indicator Optimistic CISOs Pessimistic CISOs Gap
Senior leadership has a fair or good understanding of AI risk 80% 48% 32 percentage points
AI governance ownership is clearly defined 74% 40% 34 percentage points
CISO controls the AI security budget 81% 50% 31 percentage points
Security team is fully staffed 41% 9% 32 percentage points
Security team uses AI effectively 70% 38% 32 percentage points

These indicators cover distinct parts of organisational readiness. Leadership understanding describes the executive context for AI-risk decisions. Governance ownership concerns accountability, while budget control measures a CISO’s spending authority. Staffing and effective AI use describe the security team’s reported capacity and execution.

All five indicators move in the same direction when optimistic and pessimistic CISOs are compared, with reported gaps ranging from 31 to 34 percentage points. That pattern supports an association between future confidence and the organisational conditions surrounding the security function. It does not establish that changing any one condition will increase confidence or reduce actual AI risk.

“Long-term confidence comes from somewhere else: leadership that understands what is at stake, clear accountability for governance, and a security team with the capacity and budget to act,” Kakolowski said. The comparisons are consistent with his interpretation. Confidence remains an executive perception of the organisation’s ability to manage future risk. It is separate from both current perceived risk and independently observed security outcomes.

The AI-security mandate is becoming an organisational design question

For CISOs, CIOs, AI-governance executives and budget owners, preparedness reviews can examine the security function’s mandate alongside its technical controls. The survey offers concrete measures for that examination: executive understanding of AI risk, clear governance ownership, CISO control of the AI-security budget, full staffing, and effective use of AI within the security team. These measures are associated with confidence about managing AI risk over the next 24 months.

The data also points to a potential mismatch between responsibility and organisational capacity. Pessimistic CISOs report weaker conditions across governance ownership, budget control, staffing, leadership understanding and effective AI use. Because the evidence is associative and perception-based, it cannot show that those conditions cause lower confidence or greater security risk. It does show which organisational conditions most clearly separate the two groups in this survey.

For senior executives, authority and capacity are concrete design issues. The earlier IANS and Artico Search benchmark found widespread use of external data connections, while the 2026 survey links future confidence with clear ownership, spending authority and team capacity. A preparedness review can test whether the people responsible for AI security also have defined decision rights and the resources represented by these measures. That organisational design question sits alongside the technical work of securing AI systems.

Key takeaways for leaders

  • Current readiness does not guarantee future confidence: CISOs can view today’s AI risk as relatively low while remaining uncertain about the next 24 months. Leaders should assess future organisational readiness separately from current technical exposure.
  • External connectivity is common while adversarial testing is less common: 74% of AI environments in an earlier benchmark used external data connections, while 29% had conducted adversarial testing. Executives should evaluate whether testing practices match their organisation’s AI exposure.
  • Security maturity aligns with lower perceived current risk: CISOs with mature AI-security programmes rated current risk at 3.7 out of 10, versus 7.8 among those with low maturity. The association supports continued investment in programme maturity, though it does not prove lower actual risk.
  • Future confidence tracks authority and capacity: More confident CISOs report stronger leadership understanding, governance ownership, budget control, staffing and effective security-team use of AI. Executives should examine these organisational conditions alongside technical controls.
  • AI security is also an organisational design issue: Leaders should ensure responsibility for AI security comes with clear decision rights, governance ownership and sufficient resources. Technical maturity alone does not determine confidence in managing future AI risk.

Alexander Procter

September 7, 2026

6 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.