Kiteworks survey finds 80% of organizations hit by security or AI incidents
Kiteworks released its 2026 annual risk report on July 30, finding that 80% of organizations reported at least one security or AI-related incident in the past year. The survey points to a major gap between AI adoption and deployed governance controls, with a combined readiness score of 16.2 out of 100.
Why it matters: - The survey suggests most organizations are already facing AI and security risk, not just planning for it. - Kiteworks says the gap is now operational, with compliance outcomes and shadow AI use showing up in day-to-day business. - The findings point to a controls problem that could affect regulatory exposure, data protection and audit readiness.
What happened: - Kiteworks released its 2026 Data Security and Compliance Risk: Annual Survey Report on July 30, 2026. - The report is based on primary research with security, compliance, risk and IT professionals across 10 industries and three global regions. - The survey found that 80% of organizations experienced at least one security or AI-related incident in the past 12 months. - Sixty-three percent of organizations reported a compliance outcome, including an audit finding, remediation plan, board escalation, contractual penalty or formal regulatory investigation. - Sixty-five percent discovered employees using unapproved AI tools with sensitive organizational data.
The details: - Kiteworks said the report focuses on deployed controls rather than self-reported confidence. - The Data Security Maturity Score evaluates 11 binary security controls, including eight general controls and three AI-specific controls. - The AI Governance Maturity Score measures 19 AI and agent governance capabilities. - The combined Data Security and Compliance Readiness Index averaged 16.2 out of 100. - The mean Data Security Maturity Score was 39 out of 100. - The mean AI Governance Maturity Score was 35 out of 100. - Seventy percent of organizations landed in Tier 1 or Tier 2, which the report describes as developing maturity at best. - No AI containment control in the survey was deployed by more than 31% of organizations. - Fifty percent could not produce a complete AI data access audit record within one business day. - Seventy-three percent had no technical enforcement over which channels employees can use for sensitive data. - Only 27% had deployed AI-specific data loss prevention. - Among organizations that found unapproved AI use, 36% saw customer and client data in those tools. - Another 33% found IT credentials in unapproved AI tools. - A further 31% found employee personal and HR data. - Thirty-five percent reported no discovery, which suggests limited detection capability. - The report says 19% of organizations are in the Resilient quadrant, with both DSMS and AIGMS at least 50, and those organizations had a mean DSCRI of 46. - Sixty-six percent are in the Exposed quadrant, with both scores below 50, and those organizations had a mean DSCRI of 8. - The gap between the top and bottom of the survey was 38 DSCRI points. - At the survey mean DSMS of 39, raising AIGMS from 35 to 60 adds roughly 10 DSCRI points. - The report says that is nearly double the gain from adding four security controls while AIGMS stays fixed. - The report's seven priorities include classifying and enforcing sensitive data, deploying AI-specific DLP through a centralized policy engine, integrating MFT and AI infrastructure with a SIEM, implementing and testing an AI kill switch, building audit trails that meet regulatory production timelines, assigning dedicated AI data governance ownership and consolidating sensitive data exchange platforms. - The full report includes industry, regional and organization-size breakdowns, plus a Security Maturity Readiness Checklist. - Centiment conducted the research on behalf of Kiteworks in Q2 2026.
Between the lines: - Kiteworks is framing AI risk as an architecture problem, not a training or policy-awareness problem. - The report implies that organizations with better outcomes are those that deploy enforceable controls, not those that document intent. - The findings also suggest many firms may be undercounting exposure because they do not have the detection tools to find shadow AI.
What's next: - Kiteworks is pushing organizations toward centralized policy enforcement, stronger auditability and AI-specific data protection. - The report is intended to help leaders prioritize remediation investment using the included readiness checklist. - The company says organizations need controls that govern both people and agents under one standard.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Global HR Reporter
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.