Back Wavestone AI Cyber Benchmark 2026: Governance matures, operational security lags
AI is becoming embedded in employee workflows, customer services and critical business processes. The question is no longer whether organizations should adopt it, but how they can scale it securely while maintaining trust and control.
Our latest AI Cyber Benchmark, covering 30 large public and private organizations, reveals an uneven picture. Governance and protection capabilities are advancing, but detection, incident response and recovery remain immature. As organizations increasingly build and operate their own AI systems, this operational security gap becomes harder to ignore.
Organizations are moving from using AI to building it
Organizations are taking greater ownership of how AI systems are built and operated. Half of the benchmark panel now designs AI systems internally using existing frameworks or pre-trained models, compared with 35% in 2025.
Meanwhile, the of organizations only consuming existing AI functionalities has fallen sharply. End-to-end AI development is also gaining ground, increasingly supported by advanced generative AI use cases.
Only use existing AI functionalities
Design AI systems using existing frameworks or pre-trained models
Manage the entire AI development chain
This shift reflects a growing ambition to reduce external dependencies and gain control over critical AI capabilities. It also changes the security equation: the more organizations own their AI systems, the more responsibility they assume for securing them throughout their lifecycle.
AI security improves, but progress remains uneven
The emergence of agentic AI, growing regulatory expectations and the increasing scale of AI deployment are expanding the scope of security challenges.
To reflect these developments, we updated our assessment framework to address agentic AI security, AI-specific protection controls, monitoring and incident response alongside governance and risk management.
The benchmark indicates progress across all assessed pillars compared with 2025. Governance structures are becoming established, AI-related risks are entering existing processes, and dedicated protection controls are supporting deployment.
However, monitoring, investigation and response capabilities remain comparatively immature.
Organizations are becoming better at governing AI than at operating it securely once deployed into production.
Organizations are becoming better at governing AI than at operating it securely once deployed into production.
Six trends shaping AI security
Governance is becoming established, but accountability remains fragmented. Only 32% of organizations have clearly defined activities, stakeholders and accountability models. Responsibilities are often spread across cybersecurity, data, digital and legal teams.
Expertise is another constraint: only 44% identify dedicated AI security experts capable of supporting business and technical teams throughout the AI lifecycle.
The most mature organizations bring governance closer to delivery. They embed AI risk assessments, security reviews and decision-making into existing project processes rather than treating governance as a separate compliance exercise.
The priority: make ownership explicit and extend AI security expertise beyond a small group of specialists.
Organizations are extending established data governance practices to AI. Across the panel, 72% have started implementing privacy measures for AI training, and 65% perform dataset quality checks.
Yet only 9% systematically assess both dataset quality and security before production use.
This distinction matters because data does more than support AI systems: it shapes their behavior. Manipulated datasets, compromised knowledge repositories or unauthorized data exposure can affect reliability and security.
The priority: treat datasets, vector databases and knowledge repositories as part of the AI attack surface , combining governance with security reviews and validation before deployment.
Cloud and AI platforms provide security capabilities that help organizations deploy initial use cases quickly. However, relying on these controls can obscure the responsibilities that remain with the organization.
Only 11% of the panel have started evaluating or implementing security capabilities beyond those offered natively by providers.
This dependency becomes more significant as organizations adopt custom models, self-hosted environments and agentic architectures. Controls previously supplied by a provider may need to be implemented and maintained internally.
The priority: understand which responsibilities are delegated and complement provider capabilities with internal expertise, independent validation and appropriate additional controls.
Two-thirds of the organizations surveyed perform dedicated AI security pentesting, while half conduct advanced AI-focused security assessments. The step is to turn these practices into recurring assurance programs across the AI lifecycle.
The most mature organizations are moving beyond one-off exercises. They integrate AI security testing into recurring audit and assurance programs , reassess systems after major changes and extend coverage across their AI portfolios.
Automated scanning can support this approach by identifying weaknesses and configuration issues, but it does not replace comprehensive AI red teaming.
The priority: make AI security testing a repeatable lifecycle practice rather than an exceptional project milestone.
Organizations are collecting AI telemetry, but they are not consistently using it to detect threats.
While 88% collect AI application logs, only 8% integrate those logs into security operations center monitoring.
Operational monitoring typically focuses on performance, reliability and model behavior. Cybersecurity teams need visibility into suspicious activity and potential compromise.
The gap is therefore not simply a lack of data. It reflects differences in tools, processes and objectives between AI operations and security teams.
The priority: connect AI telemetry to existing detection and response processes , define AI-specific detection use cases and strengthen collaboration between AI teams and the security operations center.
AI incidents can involve compromised datasets, manipulated prompts, unexpected model behavior or unauthorized agent actions. Traditional response procedures do not automatically cover these scenarios.
Investigation capabilities remain limited: only 8% of organizations can perform forensic investigations on AI platforms . Half of the panel still rely on ad-hoc remediation without a structured response process. Only 13% have documented AI-specific incident response plans , and these are not consistently applied.
Recovery is similarly immature: only 22% back up AI-related assets , with practices remaining largely non-standardized.
The priority: establish and exercise investigation, response and recovery procedures covering models, datasets, knowledge bases and agentic workflows, alongside the ability to restore trusted operations.
AI security cannot be treated as a one-time approval. As models, capabilities and agent permissions evolve, governance, testing and monitoring must adapt throughout the lifecycle. The challenge is to move from validating AI at deployment to maintaining control continuously.
The AI security paradox
AI security is increasingly being designed alongside the technology it protects, rather than added after adoption. Cybersecurity teams are involved earlier, but must make decisions systems whose capabilities and risks keep changing.
AI security therefore cannot be treated as a one-time approval. As models, capabilities and agent permissions evolve, governance, risk assessments, testing and monitoring must adapt throughout the lifecycle. The challenge is to move from validating AI at deployment to maintaining control continuously.
What comes for AI security?
Three priorities will shape the phase of maturity.
Build trusted resilience
Building resilient AI systems means more than ensuring availability. Availability remains a key requirement, especially where organizations depend on a limited number of providers. After an incident, organizations must also verify that models, datasets and knowledge bases remain trustworthy. Resilience planning should therefore combine continuity measures with asset restoration, integrity checks and the safe resumption of operations. Where appropriate, failover across models or providers can help reduce dependencies and strengthen resilience.
Take ownership of model security
Fine-tuned, open-weight and self-hosted models offer greater flexibility, but also transfer more security responsibility to organizations. Security teams need to assess models before adoption, validate fine-tuned versions and monitor changes and dependencies throughout their lifecycle. These responsibilities should shape adoption decisions from the outset, rather than being addressed only after deployment.
Control autonomous actions
As AI agents gain access to enterprise systems, organizations must ensure their actions remain bounded, traceable and interruptible. Recent incidents have shown that harmful autonomous actions are not merely a theoretical risk, making effective controls an immediate priority. This means limiting permissions, monitoring abnormal activity and maintaining the ability to revoke access to critical systems immediately. Risk assessments and response procedures should explicitly address harmful autonomous actions, whether caused by compromise, misuse or unexpected behavior.
From AI governance to operational resilience
The 2026 AI Cyber Benchmark shows meaningful progress. Organizations are establishing governance, integrating AI risks into existing processes and deploying protection controls.
The step is to make those foundations operational.
That means assigning clear accountability for AI systems, assessing their risks, implementing security controls, connecting them to security monitoring, testing them throughout their lifecycle and preparing teams to respond to and recover from incidents. Agentic AI and greater ownership of models make these capabilities more urgent.
The measure of AI security maturity will be whether organizations can maintain control, trust and continuity when something goes wrong.
The 2026 AI Cyber Benchmark draws on assessments of 30 large public and private organizations , complemented by insights from Wavestone’s AI security engagements over the past three years.
The assessment is structured around five pillars based on the NIST Cybersecurity Framework , each evaluated through more than 30 questions to assess AI security maturity on a scale from 0 to 100%. This edition expands coverage of agentic AI security, AI-specific protection controls, monitoring and incident response.
Percentages refer to the organizations assessed and should be read as findings from this panel, rather than estimates for the entire market.
For background on the assessment and its findings, read the 2025 AI Cyber Benchmark .
AI Cyber Benchmark 2026
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
