AI Security Research

IANS Report Finds Organizational Readiness — Not More Controls — Builds AI Confidence

Technology · Cybersecurity 3 min read

IANS and Artico Search have released CISO Perspectives on AI Risk, a new report examining what drives AI risk today and what separates the security leaders who feel confident about managing it over the next two years from those who don't. The finding at its center is counterintuitive: leadership understanding, clear governance ownership, budget authority, and staffing — not stronger technical controls — are what build lasting confidence.

The report draws a sharp line between two different questions. Perceptions of present-day risk correlate most closely with a program's AI security maturity, while optimism about the future correlates with organizational readiness. In other words, mature controls make today's risk feel lower, but they don't predict whether a CISO believes their organization can handle what's coming.

"One of the biggest surprises in our data is that how organizations feel about AI risk today has little bearing on how confident they are about managing it tomorrow."

— Nick Kakolowski, Senior Research Director, IANS

What Separates the Optimists

The data shows leadership understanding as the clearest dividing line. Among CISOs optimistic about managing AI risk over the next 24 months, 80% say senior leadership has a fair or good grasp of AI risk, compared with 48% of pessimistic CISOs — a 32-point gap. By contrast, the gap in AI security maturity between the two groups is just 12 points.

Ownership and capacity tell a similar story. Among optimistic CISOs, 74% report clearly defined AI governance ownership (versus 40% of pessimists), 70% say their security team uses AI effectively (versus 38%), and 81% own the AI security budget (versus 50%). Staffing matters too: 41% of optimistic CISOs report an adequately staffed team, versus only 9% of pessimistic ones — a 38-point gap.

"AI security risk isn't an unsolvable problem. But long-term confidence comes from somewhere else: leadership that understands what is at stake, clear accountability for governance, and a security team with the capacity and budget to act."

— Nick Kakolowski, Senior Research Director, IANS

A Widening Adoption Gap

The findings underscore a growing distance between how fast enterprises are adopting AI and how well they're securing it. A companion IANS and Artico benchmark published in July found that 74% of AI environments already pull data from external sources — via APIs, Model Context Protocol servers, or third-party plug-ins — while only 29% of organizations have conducted adversarial testing.

Based on responses from 113 CISOs surveyed between April and May 2026, the report concludes that organizations aiming to strengthen their AI security posture should focus on three things: improving executive understanding of AI risk, establishing clear ownership for AI governance, and investing in the security team's ability to use AI effectively in its own operations. The full report is available through IANS Research.

Key Takeaways
1

Readiness over controls. Leadership understanding, governance ownership, budget authority, and staffing — not technical controls — separate confident CISOs from anxious ones.

2

Two different questions. Security maturity shapes how risky AI feels today, but organizational readiness is what predicts long-term confidence.

3

Leadership is the divider. 80% of optimistic CISOs say leadership understands AI risk, versus 48% of pessimists — a 32-point gap, far wider than the 12-point maturity gap.

4

Adoption outpaces security. 74% of AI environments already pull external data, yet only 29% of organizations have run adversarial testing.

5

Three priorities. The report urges organizations to boost executive understanding, assign clear governance ownership, and equip security teams to use AI in their own work.