
The AI Security Decisions
Report: 2026
Executive summary
The security professionals who completed this survey described which AI assets their organizations have, which of those assets have dedicated security controls, who is accountable for AI security decisions, and how their organizations add AI security controls. Their answers, in brief:
- How much of the AI attack surface has dedicated controls: Among respondents who could identify their AI assets and their controls, one in three have no dedicated security control for any of those assets. Another 28% have a dedicated control for every AI asset they named, and 39% for some.
- Which AI assets have dedicated controls: Among respondents’ organizations with AI traffic paths, 65% have a dedicated security control for them, the highest of the eight AI assets the survey asked about. Among those that have runtime AI data, agent identities, or orchestration tools, only 40% have a dedicated control for that asset.
- What respondents worry about: Asked in their own words, respondents most often named risks to the data flowing through AI and to agents with too much access. Nearly four in ten answers described a risk broader than any single AI asset, such as governance, unsanctioned AI use, or attackers using AI.
- How organizations add AI security controls: Respondents most often cover AI with the security tools and processes they already own (43%). Buying an AI-security-specific product was the least common of the four ways respondents added controls (26%).
- Who is accountable: The CISO or central security leadership is accountable for AI security decisions at 38% of respondents’ organizations. One in three respondents describe that accountability as shared, not yet established, or unknown to them.
- Which AI assets organizations have: AI-generated code is the AI asset most often reported, by 64% of respondents who could identify their organization’s AI asset classes. One in ten respondents at organizations that use AI could not say which AI assets they have.
Thank you to SANS Institute for spreading the word about the survey behind this report. Their help brought it to many members of the cybersecurity community. And thank you to everyone who answered the survey, so that we can all learn from each other.
Finding 1
One in three respondents who could identify their AI assets and their controls have no dedicated control for any of those assets.
Finding 2
AI traffic has a dedicated control more often than runtime AI data, agent identities, and orchestration tools.
Finding 3
Asked in their own words, respondents worried most about the data flowing through AI and about agents with too much access.
Finding 4
Respondents most often cover AI with the security tools and processes they already own.
Finding 5
Accountability for AI security decisions is split, with the CISO the most common answer but far from a majority.
Finding 6
AI-generated code is the AI asset respondents most often report having.
About the survey and report
Who answered
Respondents described their role, their organization’s size, and their region. They could choose several roles.
| Role | Respondents | Share of 317 |
|---|---|---|
| CISO or most senior security leader | 96 | 30% |
| Security architect or engineer | 88 | 28% |
| Governance, risk, or compliance | 69 | 22% |
| Security operations or incident response | 51 | 16% |
| Security director reporting to the CISO | 49 | 15% |
| Other | 25 | 8% |
| Application or product security | 20 | 6% |
137 of the 317 (43%) are CISOs or security directors, counting each respondent once.
The next two tables give organization size and region.
| Employees | Respondents | Share of 317 |
|---|---|---|
| Fewer than 100 | 51 | 16% |
| 100 to 999 | 67 | 21% |
| 1,000 to 9,999 | 98 | 31% |
| 10,000 or more | 67 | 21% |
| Prefer not to say | 34 | 11% |
| Region | Respondents | Share of 317 |
|---|---|---|
| North America | 160 | 50% |
| Europe | 86 | 27% |
| Asia-Pacific | 54 | 17% |
| Elsewhere | 17 | 5% |
How the survey ran
The findings describe the 317 security professionals who completed this survey between July 13 and August 30, 2026.
The table shows how many responses reached each stage.
| Stage | Responses |
|---|---|
| Answered at least one question | 754 |
| Answered every required question | 323 |
| Kept after the quality check | 317 |
A response counts as completed when it answers every required question, so the 18 respondents who answered everything without submitting the final page, which held only an optional email field, are included. The quality check removed 6 responses that selected every option across four questions. 42 respondents whose organizations only evaluate AI, or who were unsure, are left out of the asset and control figures.
The people who started the survey without completing it ranked the ways their organizations use AI in the same order and named the same two worries most often.
Definitions and counting rules
A “dedicated control” is at least one security control dedicated to that AI asset, as the respondent judged it. An existing control that someone has applied to that asset counts.
An “unsure” answer counts as no dedicated control reported in the per-asset shares. Respondents unsure about all of their controls are left out of the none-or-all measure in finding 1. Counting them as having none would lower that finding’s average from 48% to 43%.
Percentages about specific AI assets include only respondents whose organizations use AI and who could identify their AI asset classes. Each chart and table states the respondents behind it.
Percentages are rounded to whole numbers, so a set of shares can add to 99% or 101%. Comparisons by organization size were not planned before the responses came in and carry the widest margins in this report.
The eight AI asset classes
The survey defined the eight AI asset classes in these words.
| Asset class | The survey’s definition |
|---|---|
| AI-Workload Platforms | the compute and serving infrastructure models run on (inference servers, vector databases) |
| AI Orchestration Tools | the application layer connecting models to tools and data (agent frameworks, agent harnesses, MCP clients) |
| AI-Generated Code | code produced by AI assistants and coding agents |
| AI Gateways and Routers | the network path to AI services (LLM routers, MCP gateways) |
| AI Model | the model itself, self-hosted or consumed as a service, including its weights |
| Training Data | datasets used to train or fine-tune models |
| Runtime AI Data | prompts, responses, RAG content, and agent memory flowing through AI at runtime |
| AI Agent Identities | AI agents and other non-human identities, and the credentials they act with |
In those descriptions, an LLM is a large language model, MCP is the Model Context Protocol that connects AI tools to data and systems, and RAG is retrieval-augmented generation, which feeds documents to a model as it answers. The AI Defense Matrix describes each class in plain language.
After the survey ran, the authors renamed the Matrix asset class AI Gateways and Routers to AI Traffic. The survey defined that class as the network path to AI services. The new name describes the same thing, so this report uses it.
The authors also renamed AI Orchestration Tools to AI Coding and Orchestration Tools and changed its scope. This report keeps the survey’s name and definition for that class.
The survey instrument and the codebook keep the names respondents saw.
How well the eight AI asset classes fit
This survey grouped AI security work by the eight AI asset classes of the AI Defense Matrix, the framework the authors published. The Matrix is a grid. Each row is one class of AI asset an organization may have to defend, from the platforms models run on to the identities agents act with. The table above gives the survey’s definition of each. Each column is one of the six functions of the NIST Cybersecurity Framework 2.0, from Govern to Recover. A cell names the kind of control that defends one asset at one stage. A team can use the grid to list the assets it has, mark the cells where it runs a control, and see which cells are empty.
The survey tested whether those eight rows match how practitioners think, in two ways. The first was an open question, asked before respondents saw the list: what AI security risk is most on your mind? Every answer that named an AI asset fit one of the eight classes. One in five fit two or three classes at once, most often runtime AI data together with agent identities. Nearly four in ten answers named a risk broader than any single asset, such as governance or unsanctioned use. The rows do not try to hold those. The Matrix places policy and oversight in its Govern column instead.
The second question asked how well the list matches the way the respondent’s organization groups its AI security work. 36% said very well or mostly, 23% only partly or not well, and 18% were not sure. The most common single answer, at 22%, was that the organization has not organized AI security work into categories at all. Among respondents whose organizations have organized the work and who had an opinion, 61% said the list fits at least mostly.
Read together, the answers say two things: every risk practitioners named unprompted fits one of the eight classes, and for many teams the harder step is having any structure at all. A team without one can start from the list: mark each class present, absent, or unsure, then find out which control covers each present class and who owns it. Finding 2 shows how often peers report a dedicated control for each class.
Respondents who suggested changes to the list agreed on no single change. Two suggestions came up more than once: AI that no one in the organization built or vetted, such as personal AI services and AI embedded in purchased software, and governance as a category of its own. The authors explain where those services and features belong on the AI Defense Matrix site, under Considered and Rejected. Governance belongs in the Govern column.
Limitations
The following limitations apply to every claim in this report.
- Respondents chose to take the survey after hearing about it through our networks and communities, so the findings describe them rather than all organizations.
- Only 323 of the 2,023 responses started were completed. Those who completed it are more senior than those who did not, so that shapes every number.
- Respondents decided for themselves which AI assets their organization has, so an organization whose respondent overlooked an asset is missing from that asset’s control rate. If overlooked assets tend to have weaker controls, the reported rates run high.
- Each response is one person’s account. Nothing verifies that two respondents do not describe the same organization, or that one person did not respond more than once.
Data and supporting materials
The files listed here are published with this report.
| File | What it holds |
|---|---|
| Survey instrument | The ten questions as respondents saw them |
| Codebook | The definitions used to classify the open answers |
| Aggregated results | Every count and share behind the charts and tables, the uncertainty range around each per-asset share, and every headline figure before and after counting the 18 respondents who skipped the optional final page |
| Schema | What each column of the aggregated results means |
| Report as Markdown | The whole report in one Markdown file, in reading order |
| Report manifest | The report content, its authors, its version, and its file list as structured data |
Citation and reuse
Cite as: Zeltser, L. and Yu, S. (2026). The AI Security Decisions Report: 2026, wave 1. AI Defense Matrix. reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/
License: this report is © 2026 Zeltser Security Corp and Cyber Defense Matrix LLC and is licensed CC BY-NC 4.0. Quote it, cite it, and reproduce its charts as part of your own work with attribution, in any setting including commercial ones. Selling or commercially redistributing the report, its data, or a chart on its own requires written permission.
Version 1.1, 2026-09-15.