Skip to content

Security1 publisher2 min readPublished

AI governance lands on 79% of CISOs without a matching increase in resources

Proofpoint's 2026 Voice of the CISO puts AI risk ownership on top of data protection, identity and compliance duties, in the same year fewer leaders expect to be attacked, which makes the funding argument harder to win.

The Watch · Security desk

Illustration accompanying AI governance lands on 79% of CISOs without a matching increase in resources

What happened

  • Proofpoint's 2026 Voice of the CISO report finds 79% of CISOs are expected to manage AI-related risks without a proportional increase in resources or expertise.
  • 78% of the security leaders surveyed consider GenAI a security risk, with the potential loss of customer data through public AI platforms named as a key concern.
  • The report says the job is getting harder because AI has moved beyond standalone tools into the applications employees already use for everyday work.
  • Among organizations that lost sensitive information, malicious or criminal insiders were the most commonly identified root cause, with AI misuse or misconfiguration also named.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Because policy has to run across every platform where employees reach data, use AI and automate tasks, the mandate cannot be discharged by allowing or blocking tools, which is the only version of it that a procurement cycle can absorb.
  • decision The remit grew in a year when leaders' own expectation of being attacked dropped 15 points, so the ask has to be justified on data-loss consequence rather than threat likelihood.
  • exposure Departing employees were implicated in 93% of material data-loss cases, and those same identities and permissions now reach AI features embedded in sanctioned applications.
  • cost Regulatory sanctions, financial losses, recovery costs and reputational damage are all rising per incident even as incident counts fall, so an under-resourced program carries more liability per failure.

Where the AI sits decides who pays for it. Proofpoint's respondents rank collaboration platforms first among the technologies that could introduce security risk, with SaaS applications carrying third-party integrations and AI built into business workflows close behind, then public GenAI tools, cloud storage and automation [9]. None of that is a standalone product a security team can put behind a proxy and forget.

Teams say they can see the inventory. They report strong visibility into how many data repositories and GenAI tools are in use, and the report identifies the hard part as turning that visibility into controls that account for user intent, data sensitivity, permissions and how information moves between work environments [14]. That is program work measured in people and review cycles, not a line item with a vendor attached.

The board arithmetic is where this gets awkward. Expectation of an attack in the next 12 months sits at 61%, down from 76% in 2025 [6], a fall of 15 points on the report's own figures [16], while more than half of respondents still say their organization is unprepared for a targeted attack [7]. Both can hold at once: perceived likelihood is not readiness. In a budget meeting they pull opposite ways. The report puts it in terms of expectations rather than volume, quoting: "Stronger board alignment is a positive sign, but it also raises expectations" [18].

The loss picture supports the remit argument better than the threat rankings do. Human risk is named the biggest cyber vulnerability by 79% of respondents [10], and cloud account takeover or compromise now tops the threat list, with email fraud, ransomware and malware falling in the rankings [8]. Account takeover, insider data movement and employee use of embedded AI resolve to the same control surface: identity, permission and egress. A CISO asking for an AI line and an account-security line is asking twice for one set of controls.

Two limits on this evidence. It is one vendor's survey of security leaders, and the material publishes percentages without a sample size, a respondent count or a full country list [19]. The gap also is not uniform: India recorded the highest GenAI security concern and the widest AI resource gap, France the highest level of restrictions on employee GenAI use, and Singapore the greatest concern about employees exposing sensitive data through AI [15]. A remit argument built on the global 79% will read differently in Paris, where the restriction lever has already been pulled [1][15].

What to watch

  • Whether Proofpoint publishes sample size and country breakdown for the 2026 Voice of the CISO figures.
  • Whether the 79% resource-gap figure moves in the 2027 survey, after AI features ship on by default in major SaaS suites.
  • Whether regulators name AI misuse or misconfiguration as a root cause in a sanction decision, which would move the cost line the report describes.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories