Eight in 10 organisations suffered at least one security or AI-related incident in the past year, according to new research that scores firms on deployed controls rather than self-reported confidence.kiteworks+1
The 2026 Data Security and Compliance Risk: Annual Survey Report** from Kiteworks, based on primary research with security, compliance, risk and IT professionals across 10 industries and three regions, found a mean Data Security Maturity Score (DSMS) of 39 out of 100 and an AI Governance Maturity Score (AIGMS) of 35 out of 100. Combined, these produce a Data Security and Compliance Readiness Index (DSCRI) of just 16.2 out of 100, with 70% of organisations classified as Tier 1 or Tier 2 – still developing maturity at best.
** The surveyed region are North America, the Middle East and Europe.
Incidents and compliance fallout
The incidents are already carrying tangible consequences. Sixty-three per cent of organisations reported a compliance outcome in the past 12 months, including audit findings, required remediation plans, board escalations, contractual penalties or formal regulatory investigations.
At the same time, 65% discovered employees using unapproved AI tools with sensitive organisational data, underscoring the scale of “shadow AI” in practice.
Among those that detected unapproved AI use, 36% found customer and client data flowing through these tools, 33% uncovered IT credentials, and 31% identified employee personal and HR data. The 35% that reported no such discovery likely lack the detection capability to see it, the report notes.
Controls gap underpins risk
What sets the survey apart is its focus on what is technically operational. The DSMS evaluates 11 binary security controls – eight general controls protecting everyday human-driven data access and three AI-specific ones – while the AIGMS measures 19 AI and agent governance capabilities. Neither can be inflated by perception.kiteworks+1
The governance gap is measurable: no AI containment control in the survey is deployed by more than 31% of organisations. Half cannot produce a complete AI data access audit record within one business day, creating direct exposure under frameworks such as DORA, NIS2 and the EU AI Act.
Meanwhile, 73% have no technical enforcement over which channels employees can use for sensitive data, and only 27% have deployed AI-specific data loss prevention (DLP).
“Architectural” response required
“Organizations have deployed AI far faster than they’ve built the governance infrastructure to manage it,” said Tim Freestone, chief strategy officer at Kiteworks. “The incidents have already happened, and the compliance consequences are already being felt. The path forward is architectural. It requires a data policy engine that enforces controls at the data layer for every person and every agent alike, not behavioral policy people can route around.”
The difference between leaders and laggards is stark. The 19% of organisations in the “Resilient” quadrant (DSMS and AIGMS both at least 50) carry a mean DSCRI of 46, versus a mean of 8 for the 66% in the “Exposed” quadrant (both below 50). At the survey mean DSMS of 39, raising AIGMS from 35 to 60 adds roughly 10 DSCRI points – nearly double the gain from adding four security controls while AIGMS stays fixed.
The report identifies seven priorities for closing the gap, including classifying and enforcing sensitive data, deploying AI-specific DLP through a centralized policy engine, integrating managed file transfer and AI infrastructure with a SIEM, implementing and testing an AI kill switch, building audit trails that meet regulatory production timelines, assigning dedicated AI data governance ownership, and consolidating sensitive data exchange platforms.








