# The AI Security Decisions Report: 2026

By Lenny Zeltser and Sounil Yu.

Wave 1, 2026. Version 1.1, 2026-09-15. CC BY-NC 4.0.
Web version: https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1

## Summary

The security professionals who completed this survey described which AI assets their organizations have, which of those assets have dedicated security controls, who is accountable for AI security decisions, and how their organizations add AI security controls. Their answers, in brief:

- **How much of the AI attack surface has dedicated controls:** Among respondents who could identify their AI assets and their controls, one in three have no dedicated security control for any of those assets. Another 28% have a dedicated control for every AI asset they named, and 39% for some.
- **Which AI assets have dedicated controls:** Among respondents’ organizations with AI traffic paths, 65% have a dedicated security control for them, the highest of the eight AI assets the survey asked about. Among those that have runtime AI data, agent identities, or orchestration tools, only 40% have a dedicated control for that asset.
- **What respondents worry about:** Asked in their own words, respondents most often named risks to the data flowing through AI and to agents with too much access. Nearly four in ten answers described a risk broader than any single AI asset, such as governance, unsanctioned AI use, or attackers using AI.
- **How organizations add AI security controls:** Respondents most often cover AI with the security tools and processes they already own (43%). Buying an AI-security-specific product was the least common of the four ways respondents added controls (26%).
- **Who is accountable:** The CISO or central security leadership is accountable for AI security decisions at 38% of respondents’ organizations. One in three respondents describe that accountability as shared, not yet established, or unknown to them.
- **Which AI assets organizations have:** AI-generated code is the AI asset most often reported, by 64% of respondents who could identify their organization’s AI asset classes. One in ten respondents at organizations that use AI could not say which AI assets they have.

Thank you to [SANS Institute](https://www.sans.org/) for spreading the word about the survey behind this report. Their help brought it to many members of the cybersecurity community. And thank you to everyone who answered the survey, so that we can all learn from each other.

## Finding 1. One in three respondents who could identify their AI assets and their controls have no dedicated control for any of those assets.

**33%** of respondents who could identify their AI assets and their controls have no dedicated security control for any of those assets.

Among respondents who named at least one AI asset at their organization and could say which of those assets have a dedicated control, 33% have no dedicated control for any of them. Another 28% have a dedicated control for every AI asset they named, and 39% for some of them. The average share of an organization’s AI assets with a dedicated control is 48%, but most respondents have a dedicated control for all of their AI assets or for none.

**For executives and operators.** Find out which security controls exist for your AI assets and whether they are appropriate for the job. Where an asset lacks a dedicated control, check whether other security measures adequately address the risk.

### The data

The chart groups respondents by the share of their AI asset classes that have a dedicated control.

Bar chart of respondents by the share of their AI asset classes with a dedicated control: none 70 (33%), up to half 53 (25%), over half 31 (14%), all 61 (28%), of 215 respondents.

Drawing: [figures/figure-1.svg](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-1.svg). Data: [figures/figure-1.csv](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-1.csv).

Of the respondents who could say which asset classes their organization has, 3% named none and 10% could not say which have a dedicated control. The rest are the respondents behind this finding. The chart groups them by the share of their organization’s AI asset classes with a dedicated control. On average that share is 48%, and for half of them it is 50% or less.

_The table gives the same distribution in numbers._

| Share of their asset classes with a dedicated control | Respondents | Share of 215 |
| --- | --- | --- |
| None of them | 70 | 33% |
| More than none, up to half | 53 | 25% |
| Over half, not all | 31 | 14% |
| All of them | 61 | 28% |

The values in this chart are published as a [CSV file](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-1.csv).

### Going deeper

Respondents with only one asset class necessarily land at none or all. 27% of respondents named only one asset class, so their score could only be 0% or 100%. Even among respondents whose organizations have three or more classes, 40% sit at one end or the other.

Two other explanations are consistent with the pattern. Some organizations may have a program that covers every asset they know about, while others have not started one. Some respondents may have answered both questions the same way throughout.

## Finding 2. AI traffic has a dedicated control more often than runtime AI data, agent identities, and orchestration tools.

**65%** of respondents whose organizations have AI traffic paths report at least one security control dedicated to them, the highest share of the eight AI assets.

Of the respondents whose organizations have AI traffic paths, the network paths to AI services, 65% report at least one security control dedicated to them (a dedicated control, in the survey’s words). For runtime AI data, AI agent identities, and AI orchestration tools, only 40% of respondents’ organizations that have them report a dedicated control for that asset. The other four classes fall between 44% and 50%.

The three classes with the fewest dedicated controls are all parts of how an agent operates. Runtime AI data is the prompts, responses, retrieved content, and memory that flow through AI. Agent identities are the credentials and permissions an agent acts with. Orchestration tools connect models and agents to tools and data.

The chart shows the share with a dedicated control for each of the eight classes.

**For executives.** For each AI asset your organization has, find out which security control covers it and who owns that control. An existing control that also covers the asset can be an acceptable answer, as long as someone has checked that it does. For AI agents, find out what credentials they hold and who is accountable for them, as you would for service accounts.

**For operators.** Among respondents, runtime AI data, agent identities, and orchestration tools were the assets most often left without a dedicated control. If your organization already reviews service accounts and other non-human identities, consider adding agents to that inventory and those reviews.

**For vendors.** Runtime AI data, agent identities, and orchestration tools have the fewest dedicated controls among respondents. They are also what respondents worry about most (finding 3). Buyers already know those three assets need attention. Lead with which of them your product covers and what the control does for that asset.

### The data

Questions, in the survey’s words:

- “Which of these AI-related assets are part of your organization’s attack surface today, meaning present in your environment or used on your behalf? Select all that apply.”
- “For which of these AI-related assets has your organization implemented at least one dedicated security control? Select all that apply.”

Each percentage is out of the respondents whose organization has that asset, and the table shows how many that is for each class.

Respondents judged for themselves whether an asset has a control, and the survey did not test control quality, so these shares may overstate how well the assets are secured.

The Unsure column counts the respondents who were not sure which of their assets have a dedicated control.

_The table gives, for each AI asset class, how many respondents have it and how many of those report a dedicated control._

| Asset class | Have it | Have a dedicated control | Unsure | Share with a dedicated control |
| --- | --- | --- | --- | --- |
| AI Traffic | 71 | 46 | 5 | 65% |
| AI-Workload Platforms | 108 | 54 | 11 | 50% |
| AI Model | 106 | 52 | 15 | 49% |
| AI-Generated Code | 159 | 75 | 22 | 47% |
| Training Data | 70 | 31 | 8 | 44% |
| AI Orchestration Tools | 131 | 53 | 16 | 40% |
| Runtime AI Data | 111 | 44 | 15 | 40% |
| AI Agent Identities | 98 | 39 | 12 | 40% |

The values in this chart are published as a [CSV file](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-2.csv).

### Going deeper

Control types dedicated to the three classes with the fewest dedicated controls, from the [AI Defense Matrix](https://aidefensematrix.com):

- Runtime AI data: defenses against instructions smuggled into the content a model reads (prompt injection), sanitizing of retrieved content (the documents and search results pulled into a prompt), and data-loss prevention for AI content.
- AI agent identities: an inventory of agents and other non-human identities, short-lived credentials, and permissions scoped to what each agent needs.
- AI orchestration tools: sandboxing, hardening of the agent harness, and allowlists for the plugins, skills, and MCP servers an agent may use.

The differences among the four middle classes are too small to treat as meaningful.

Organizations that run AI agents report a dedicated control for agent identities about as often as organizations overall. Of respondents whose organizations run AI agents and have agent identities among their AI assets, 44% report a dedicated control for those identities. Among all respondents whose organizations have agent identities among their AI assets, the share is 40%.

_The table shows how respondents whose organizations run agents narrow to those with agent identities among their AI assets._

| Step | Respondents |
| --- | --- |
| Respondents at organizations that use AI | 275 |
| Of those, run agents that use tools, credentials, or systems on their own | 95 (35%) |
| Of those, have agent identities among their AI assets | 68 |
| Of those, report a dedicated control for agent identities | 30 (44%) |

## Finding 3. Asked in their own words, respondents worried most about the data flowing through AI and about agents with too much access.

**46%** of the answers that named an AI asset class were about runtime AI data alone, and 25% about agent identities alone. No other class reached 5%.

In their own words, respondents worry most about the data flowing through AI and about agents with too much access. Of the answers that named an AI asset class, 46% were about runtime AI data alone and 25% about agent identities alone, chiefly permissions, credentials, and oversight. Another 21% spanned two or three classes, most often those same two.

Nearly four in ten answers described a risk broader than any single AI asset: governance, unsanctioned AI use, the pace of adoption, or attackers’ use of AI. An inventory of AI assets does not cover those risks.

**For executives.** Find out who owns the governance questions, such as which AI services employees may use and who approves them, and whether the AI risk your team names first has an owner.

**For operators.** Many of the worries respondents named are about how AI is used rather than about a single asset. Governance and unsanctioned use are two of them. Find out who uses which AI services, who approved them, and how you would learn of unsanctioned use.

### The data

Question, in the survey’s words:

- “In a few words: what AI security risk is most on your mind right now?”

The chart counts the answers that named a single AI asset class.

Bar chart of unaided worries by AI asset class, counting answers that named one class: Runtime AI Data 62, AI Agent Identities 34, AI Orchestration Tools 5, AI-Generated Code 2, Training Data 2, AI Model 1, AI-Workload Platforms 0, AI Traffic 0.

Drawing: [figures/figure-3.svg](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-3.svg). Data: [figures/figure-3.csv](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-3.csv).

In respondents’ words, quoted as written:

- “Ai agents with too high permissions and too little control.”
- “Not a understanding exactly what an agent does and what it has access to.”
- “Employees sharing confidential data.”
- “Data leakage via chatbots.”
- “The speed an organisation adopts AI without the right security to keep up with it.”
- “How AI use outside of IT control effects security. AI Shadow IT.”

_The table shows how the answers were classified._

| Classification | Answers |
| --- | --- |
| Named one asset class | 106 |
| Spanned two or three asset classes | 28 |
| Named at least one asset class, the two rows above together | 134 |
| Named no asset class (governance, unsanctioned use, adoption pace, attackers’ use of AI) | 104 |
| Could not be interpreted | 29 |

_The second table gives the answers that named one asset class, by class._

| Asset class | Answers |
| --- | --- |
| Runtime AI Data | 62 |
| Agent Identities | 34 |
| Orchestration Tools | 5 |
| AI-Generated Code | 2 |
| Training Data | 2 |
| AI Model | 1 |
| Workload Platforms | 0 |
| AI Traffic | 0 |

Of the answers spanning classes, 54% paired runtime AI data with agent identities. Within the runtime-data answers, 81% mention sensitive data moving into AI tools and 16% mention prompt injection. A few are about both. 39% of all answers, or 44% of those that could be interpreted, described a risk broader than any single AI asset.

The values in this chart are published as a [CSV file](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-3.csv).

### Going deeper

Which classes come first depends on the question. The asset classes organizations most often have are AI-Generated Code (64% of those who could identify their AI asset classes), Orchestration Tools (53%), and Runtime AI Data (45%). The ones most often named as the top worry are Runtime AI Data and Agent Identities. Only 2 of the 106 answers that named one class were about AI-Generated Code, the class respondents most often have. The one with a dedicated control most often is AI traffic (65%). The two most-worried-about classes are among the three with the fewest dedicated controls in the chart in finding 2. The three questions differ in wording and in who answered them, so their numbers should not be compared directly.

The authors classified every answer against the eight class definitions in a written [codebook](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/codebook.md), which is published with this report, and checked the classifications for consistency before settling the remaining differences.

## Finding 4. Respondents most often cover AI with the security tools and processes they already own.

**43%** of respondents at organizations that use AI used security tools or processes they already own to cover AI, the most common way to add AI security controls.

Using security tools already in place to cover AI is the most common way respondents’ organizations add AI security controls. Among respondents at organizations that use AI, 43% used security tools or processes they already own, 39% rely on protections built into AI or cloud providers’ offerings, 33% built controls in-house, and 26% adopted AI-security-specific products. 

AI-security-specific products were the least common of the four technical approaches. 71% chose at least one of the four technical approaches. Of those, 59% chose two or more, so most organizations that added a technical control did it in more than one way. 16% selected “we have not added AI-specific controls yet,” although some of them also selected a technical approach.

**For executives and operators.** Finding 2 names the three classes with the fewest dedicated controls: runtime AI data, agent identities, and orchestration tools. Before buying a product for one of them, it is worth knowing what is already in place. Your existing tools and your AI and cloud providers may already cover part of that asset. Another team may already operate the control you are considering. A vendor you already pay may have added the AI-specific feature.

**For vendors.** AI-security-specific products were the least common way respondents added AI security controls. More respondents relied on the tools they already own, or on protections built into their AI and cloud providers’ offerings. Buyers are likely to weigh a new product against what is already in place. Be ready to explain what your product adds to what a buyer already has.

### The data

Question, in the survey’s words:

- “Which approaches has your organization used to add AI security controls? Select all that apply.”

The chart shows how many respondents chose each approach.

Horizontal bars of seven approaches to adding AI security controls among 275 respondents at organizations that use AI, from security tools already owned at 43% (119 of 275) to not sure at 11% (31 of 275), with AI-security-specific products at 26% (72 of 275).

Drawing: [figures/figure-4.svg](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-4.svg). Data: [figures/figure-4.csv](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-4.csv).

_The table gives the counts behind the chart._

| Approach | Respondents | Share of 275 |
| --- | --- | --- |
| Extended security tools or processes we already own | 119 | 43% |
| Relied on protections built into AI or cloud providers’ offerings | 108 | 39% |
| Built controls in-house | 91 | 33% |
| Added policies or training but no technical controls yet | 84 | 31% |
| Adopted AI-security-specific products | 72 | 26% |
| We have not added AI-specific controls yet | 44 | 16% |
| Not sure | 31 | 11% |

The survey listed four technical approaches, the ones in the first paragraph of this finding, alongside adding policies or training, adding nothing yet, and not sure. Respondents could pick several approaches, so the shares add to more than 100%. Fewer than half of respondents chose any single approach.

The values in this chart are published as a [CSV file](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-4.csv).

### Going deeper

Two of the answer options overlap with the technical ones. 31% chose “added policies or training but no technical controls yet.” 74% of those also chose a technical approach, so that option reads as “we added policies and training.” 36% of those who chose “we have not added AI-specific controls yet” also chose a technical approach.

29% chose no technical approach at all. 10% chose only “not sure.”

By organization size, 47% of respondents at organizations with 10,000 or more employees adopted AI-security-specific products, against 14% to 23% at smaller organizations.

## Finding 5. Accountability for AI security decisions is split, with the CISO the most common answer but far from a majority.

**38%** of respondents’ organizations make the CISO or central security leadership primarily accountable for AI security decisions.

The CISO or central security leadership is primarily accountable for AI security decisions at 38% of respondents’ organizations, more than any other answer but far from a majority. A dedicated AI security leader or team holds that accountability at 13%, and platform or engineering leadership at 7%. Since 43% of respondents are CISOs or security directors, the CISO’s share here may run higher than at organizations in general.

One in three respondents describe accountability for AI security decisions as shared across several leaders with no primary owner (13%), not yet established (13%), or unknown to them (8%). Sharing it can be a deliberate model, although the survey did not ask whether it was.

**For executives and operators.** Find out who is accountable for which AI security decisions in your organization. Those can range from which AI services employees may use to how AI incidents are handled. Then confirm with those people that they accept that responsibility.

### The data

Question, in the survey’s words:

- “Who is primarily accountable for AI security decisions in your organization?”

The chart shows the answers.

Horizontal bars of eight accountability answers among all 317 respondents, from CISO or central security leadership at 120 (38%) to all other answers at 12 (4%). No answer has a majority.

Drawing: [figures/figure-5.svg](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-5.svg). Data: [figures/figure-5.csv](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-5.csv).

_The table gives the counts behind the chart._

| Who is primarily accountable | Respondents | Share of 317 |
| --- | --- | --- |
| CISO or central security leadership | 120 | 38% |
| A dedicated AI security leader or team | 42 | 13% |
| Shared accountability with no single primary owner | 40 | 13% |
| No clear accountability yet | 40 | 13% |
| Not sure | 25 | 8% |
| Platform or engineering leadership | 21 | 7% |
| Risk, compliance, or legal leadership | 17 | 5% |
| All other answers | 12 | 4% |

Shared, not yet established, and unknown together account for 33% of respondents.

The values in this chart are published as a [CSV file](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-5.csv).

### Going deeper

Respondents whose organizations have not yet established accountability for AI security decisions also report a dedicated control for none of their AI asset classes more often. Among the respondents whose controls could be measured (the group behind finding 1), 52% of those with no clear accountability report a dedicated control for none of their classes, against 24% where the CISO is accountable. With only 25 respondents in the first group, the size of the difference is uncertain.

Two other explanations fit the same numbers. Organizations without an owner could be smaller or earlier in their AI adoption. Some may not have named an owner because they have not yet made a deliberate AI control decision. Among respondents, accountability did not clearly differ by organization size.

## Finding 6. AI-generated code is the AI asset respondents most often report having.

**64%** of respondents who could identify their organization’s AI asset classes report AI-generated code, more than any other of the eight AI assets the survey asked about.

AI-generated code is present at more respondents’ organizations than any other AI asset class. Among respondents who could say which of the eight classes their organization has, 64% report AI-generated code, 53% report AI orchestration tools, and 45% report runtime AI data. Training data comes last at 28%.

One in ten respondents at organizations that use AI could not say which AI assets their organization has. 22% of all respondents, including those at organizations still evaluating AI, chose “we haven’t organized AI security work into categories yet.”

The most commonly reported uses are employee assistants and AI features in purchased applications. At organizations that use AI, 83% of respondents report employees using AI assistants and copilots, and 64% report AI features inside applications the organization bought. Fewer build their own, with 35% running agents and 25% fine-tuning or training models.

**For executives.** Consider requesting an inventory of the eight AI asset classes defined by the [AI Defense Matrix](https://aidefensematrix.com). Each class would be marked present, absent, or unsure. An “unsure” is worth recording too, because it marks an asset the organization cannot yet see.

**For operators.** One place to start is the AI-enabled services and applications your organization uses. Those include assistants and purchased applications that no one in your organization built. Each contains AI assets of its own. A purchased assistant, for example, runs on a model consumed as a service. The prompts and responses that pass through it are runtime AI data. If the assistant can act on your systems, it also has credentials of its own.

**For vendors.** One in ten respondents at organizations that use AI could not say which AI assets their organization has. That share was highest among respondents whose organizations only use purchased or externally hosted AI. Be prepared for buyers who cannot yet list their AI assets.

### The data

Questions, in the survey’s words:

- “How is your organization using AI today? Select all that apply.”
- “Which of these AI-related assets are part of your organization’s attack surface today, meaning present in your environment or used on your behalf? Select all that apply.”

The chart shows how respondents’ organizations use AI.

Horizontal bars of six ways respondents’ organizations use AI, among 275 respondents at organizations that use AI, from employees using AI assistants at 83% (229 of 275) to fine-tuning or training models at 25% (69 of 275).

Drawing: [figures/figure-6.svg](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-6.svg). Data: [figures/figure-6.csv](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-6.csv).

_Respondents could choose several uses, so the shares add to more than 100%._

| How the organization uses AI | Respondents | Share of 275 |
| --- | --- | --- |
| Employees use third-party AI assistants or copilots | 229 | 83% |
| Business applications we buy include embedded AI features | 175 | 64% |
| We build products or internal tools using external AI models (APIs) | 130 | 47% |
| We run AI agents that can use tools, credentials, or systems on their own | 95 | 35% |
| We host or run models on infrastructure we control | 92 | 33% |
| We fine-tune or train our own models | 69 | 25% |

_The second table gives the share of respondents whose organization has each AI asset class._

| Asset class | Respondents | Share of 248 |
| --- | --- | --- |
| AI-Generated Code | 159 | 64% |
| AI Orchestration Tools | 131 | 53% |
| Runtime AI Data | 111 | 45% |
| AI-Workload Platforms | 108 | 44% |
| AI Model | 106 | 43% |
| AI Agent Identities | 98 | 40% |
| AI Traffic | 71 | 29% |
| Training Data | 70 | 28% |

The values in this chart are published as a [CSV file](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/figures/figure-6.csv).

### Going deeper

Respondents who used only purchased or externally hosted AI were the ones most often unable to identify their AI assets. Of the respondents who report no hosting, building, fine-tuning, or agents, 22% answered only “not sure” about which asset classes are present, against 4% of the others. Fewer respondents stand behind this comparison than behind the rest of this finding, so the difference is less certain.

By role, among respondents at organizations that use AI, 9% of those in leadership roles and 12% of those in governance, risk, and compliance could not identify their AI assets. Other role groups have too few such respondents to show, and roles could overlap. The differences between roles are too small to support a conclusion.

Respondents may not count a provider’s model as part of their attack surface. Every AI assistant depends on a model, and the survey’s definition of the class includes a model consumed as a service. Yet the AI model itself comes fifth of the eight, at 43%.

## About the survey and report

### Who answered

Respondents described their role, their organization’s size, and their region. They could choose several roles.

| Role | Respondents | Share of 317 |
| --- | --- | --- |
| CISO or most senior security leader | 96 | 30% |
| Security architect or engineer | 88 | 28% |
| Governance, risk, or compliance | 69 | 22% |
| Security operations or incident response | 51 | 16% |
| Security director reporting to the CISO | 49 | 15% |
| Other | 25 | 8% |
| Application or product security | 20 | 6% |

137 of the 317 (43%) are CISOs or security directors, counting each respondent once.

_The next two tables give organization size and region._

| Employees | Respondents | Share of 317 |
| --- | --- | --- |
| Fewer than 100 | 51 | 16% |
| 100 to 999 | 67 | 21% |
| 1,000 to 9,999 | 98 | 31% |
| 10,000 or more | 67 | 21% |
| Prefer not to say | 34 | 11% |

| Region | Respondents | Share of 317 |
| --- | --- | --- |
| North America | 160 | 50% |
| Europe | 86 | 27% |
| Asia-Pacific | 54 | 17% |
| Elsewhere | 17 | 5% |

### How the survey ran

The findings describe the 317 security professionals who completed this survey between July 13 and August 30, 2026.

_The table shows how many responses reached each stage._

| Stage | Responses |
| --- | --- |
| Answered at least one question | 754 |
| Answered every required question | 323 |
| Kept after the quality check | 317 |

A response counts as completed when it answers every required question, so the 18 respondents who answered everything without submitting the final page, which held only an optional email field, are included. The quality check removed 6 responses that selected every option across four questions. 42 respondents whose organizations only evaluate AI, or who were unsure, are left out of the asset and control figures.

The people who started the survey without completing it ranked the ways their organizations use AI in the same order and named the same two worries most often.

### Definitions and counting rules

A “dedicated control” is at least one security control dedicated to that AI asset, as the respondent judged it. An existing control that someone has applied to that asset counts.

An “unsure” answer counts as no dedicated control reported in the per-asset shares. Respondents unsure about all of their controls are left out of the none-or-all measure in finding 1. Counting them as having none would lower that finding’s average from 48% to 43%.

Percentages about specific AI assets include only respondents whose organizations use AI and who could identify their AI asset classes. Each chart and table states the respondents behind it.

Percentages are rounded to whole numbers, so a set of shares can add to 99% or 101%. Comparisons by organization size were not planned before the responses came in and carry the widest margins in this report.

### The eight AI asset classes

_The survey defined the eight AI asset classes in these words._

| Asset class | The survey’s definition |
| --- | --- |
| AI-Workload Platforms | the compute and serving infrastructure models run on (inference servers, vector databases) |
| AI Orchestration Tools | the application layer connecting models to tools and data (agent frameworks, agent harnesses, MCP clients) |
| AI-Generated Code | code produced by AI assistants and coding agents |
| AI Gateways and Routers | the network path to AI services (LLM routers, MCP gateways) |
| AI Model | the model itself, self-hosted or consumed as a service, including its weights |
| Training Data | datasets used to train or fine-tune models |
| Runtime AI Data | prompts, responses, RAG content, and agent memory flowing through AI at runtime |
| AI Agent Identities | AI agents and other non-human identities, and the credentials they act with |

In those descriptions, an LLM is a large language model, MCP is the Model Context Protocol that connects AI tools to data and systems, and RAG is retrieval-augmented generation, which feeds documents to a model as it answers. The [AI Defense Matrix](https://aidefensematrix.com) describes each class in plain language.

After the survey ran, the authors renamed the Matrix asset class AI Gateways and Routers to AI Traffic. The survey defined that class as the network path to AI services. The new name describes the same thing, so this report uses it.

The authors also renamed AI Orchestration Tools to AI Coding and Orchestration Tools and changed its scope. This report keeps the survey’s name and definition for that class.

The survey instrument and the codebook keep the names respondents saw.

### How well the eight AI asset classes fit

This survey grouped AI security work by the eight AI asset classes of the [AI Defense Matrix](https://aidefensematrix.com), the framework the authors published. The Matrix is a grid. Each row is one class of AI asset an organization may have to defend, from the platforms models run on to the identities agents act with. The table above gives the survey’s definition of each. Each column is one of the six functions of the NIST Cybersecurity Framework 2.0, from Govern to Recover. A cell names the kind of control that defends one asset at one stage. A team can use the grid to list the assets it has, mark the cells where it runs a control, and see which cells are empty.

The survey tested whether those eight rows match how practitioners think, in two ways. The first was an open question, asked before respondents saw the list: what AI security risk is most on your mind? Every answer that named an AI asset fit one of the eight classes. One in five fit two or three classes at once, most often runtime AI data together with agent identities. Nearly four in ten answers named a risk broader than any single asset, such as governance or unsanctioned use. The rows do not try to hold those. The Matrix places policy and oversight in its Govern column instead.

The second question asked how well the list matches the way the respondent’s organization groups its AI security work. 36% said very well or mostly, 23% only partly or not well, and 18% were not sure. The most common single answer, at 22%, was that the organization has not organized AI security work into categories at all. Among respondents whose organizations have organized the work and who had an opinion, 61% said the list fits at least mostly.

Read together, the answers say two things: every risk practitioners named unprompted fits one of the eight classes, and for many teams the harder step is having any structure at all. A team without one can start from the list: mark each class present, absent, or unsure, then find out which control covers each present class and who owns it. Finding 2 shows how often peers report a dedicated control for each class.

Respondents who suggested changes to the list agreed on no single change. Two suggestions came up more than once: AI that no one in the organization built or vetted, such as personal AI services and AI embedded in purchased software, and governance as a category of its own. The authors explain where those services and features belong on the [AI Defense Matrix](https://aidefensematrix.com) site, under Considered and Rejected. Governance belongs in the Govern column.

### Limitations

The following limitations apply to every claim in this report.

- Respondents chose to take the survey after hearing about it through our networks and communities, so the findings describe them rather than all organizations.
- Only 323 of the 2,023 responses started were completed. Those who completed it are more senior than those who did not, so that shapes every number.
- Respondents decided for themselves which AI assets their organization has, so an organization whose respondent overlooked an asset is missing from that asset’s control rate. If overlooked assets tend to have weaker controls, the reported rates run high.
- Each response is one person’s account. Nothing verifies that two respondents do not describe the same organization, or that one person did not respond more than once.

### Data and supporting materials

_The files listed here are published with this report._

| File | What it holds |
| --- | --- |
| [Survey instrument](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/instrument.md) | The ten questions as respondents saw them |
| [Codebook](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/codebook.md) | The definitions used to classify the open answers |
| [Aggregated results](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/data/aggregates.csv) | Every count and share behind the charts and tables, the uncertainty range around each per-asset share, and every headline figure before and after counting the 18 respondents who skipped the optional final page |
| [Schema](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/data/schema.md) | What each column of the aggregated results means |
| [Report as Markdown](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/report.md) | The whole report in one Markdown file, in reading order |
| [Report manifest](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/report.json) | The report content, its authors, its version, and its file list as structured data |

### Citation and reuse

Cite as: Zeltser, L. and Yu, S. (2026). The AI Security Decisions Report: 2026, wave 1. AI Defense Matrix. reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/

License: this report is © 2026 Zeltser Security Corp and Cyber Defense Matrix LLC and is licensed CC BY-NC 4.0. Quote it, cite it, and reproduce its charts as part of your own work with attribution, in any setting including commercial ones. Selling or commercially redistributing the report, its data, or a chart on its own requires written permission.

Version 1.1, 2026-09-15.

Machine-readable companions: [report.json](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/report.json), [data/aggregates.csv](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/data/aggregates.csv),
[data/schema.md](https://reports.aidefensematrix.com/ai-security-decisions/2026-wave-1/data/schema.md), and one `figures/figure-N.csv` per figure, linked beneath its chart.

© 2026 Zeltser Security Corp and Cyber Defense Matrix LLC. Except where stated otherwise, original content is licensed under [CC BY-NC 4.0](https://creativecommons.org/licenses/by-nc/4.0/). Quote it, cite it, and reproduce its figures and charts as part of your own work or presentation, with attribution, including in commercial settings. Selling or commercially redistributing a report, a data file, all or a substantial part of the report data, or a figure or chart on its own requires written permission unless the law permits the use without permission.

The reports and data are provided “as is” and without any warranty of accuracy or completeness. You use them at your own risk. The authors and operators are not liable for decisions made on the basis of these reports, to the extent the law allows. Nothing here is legal or professional advice. Use of this site is subject to the [Terms and Disclaimers](https://reports.aidefensematrix.com/terms).
