AI Adoption Surges in Cybersecurity Defense, Governance Gaps Highlighted
A report released by the SANS Institute on July 13 indicates that the adoption rate of AI among enterprise security teams has jumped from 50% to 78% within a year, but governance policies lag significantly behind. 40% of security practitioners report that their organizations lack a formal AI adoption policy, and over 60% are unable to track AI model usage and data exposure risks. Report author Matt Bromiley points out a 14-percentage-point perception gap between security leaders and frontline practitioners, highlighting the practical challenges in governance implementation.

Briefing
- Enterprise security teams are incorporating AI into their security programs at an unprecedented pace, but there are significant gaps in the governance policies supporting this expansion. This conclusion comes from a report released by the SANS Institute on Monday (July 13).
- The report shows that four in ten security practitioners say their organizations have no formal AI adoption policy; more than six in ten practitioners say they have no visibility into where AI models are used or what types of information are exposed.
- About 75% of security practitioners bear governance responsibilities related to enterprise AI, but more than half of respondents say no established framework for AI auditing has been put in place.
Deep Analysis
The SANS report highlights a concern widely shared by security and corporate governance experts: AI adoption is outpacing the installation of guardrails needed to protect customer data and other sensitive information.
Report author and SANS Institute certified instructor Matt Bromiley noted a significant perception gap between security leaders and frontline practitioners tasked with executing the primary responsibilities of security programs.
While half of security leaders say their organizations have established formal AI risk management programs, only 36% of practitioners say such programs actually exist.
"That 14-point gap is a perception problem," Bromiley told Cybersecurity Dive.
Bromiley said security leaders in the same program believe governance exists, but "the people running the tools don't see" any real safeguards in actual implementation.
The report is based on a survey of 536 cybersecurity and IT practitioners worldwide. SANS said the research included a dedicated module of 57 senior security leaders, covering roles such as CISOs, CSOs, and vice presidents of security.
S&P has previously warned that companies could face credit rating downgrades if they fail to strengthen their security governance.
The report also shows how AI adoption is changing the use of specific security practices. For example, six in ten practitioners say their programs use AI for red team testing, compared to just one-third a year ago.