Artificial IntelligenceBusinessCybersecurityNewswireWhat's Buzzing

AI Adoption Surges Ahead of Safety Policies, Leaving Firms Vulnerable

Originally published on: May 6, 2026
▼ Summary

– Only 38% of organizations have a formal, comprehensive AI policy, while 25% have no AI policies at all, leaving them exposed to data breaches and privacy failures.
– The lack of AI policies has led to the rise of Shadow AI, where employees use tools like LLMs and may share sensitive company information without IT knowledge.
– 56% of respondents do not know how long it would take to halt an AI system during a security incident, and only 20% have a process to shut down or override AI.
– 71% of professionals say AI-powered phishing and social engineering attacks are harder to spot, and 58% say AI makes authenticating digital information more difficult.
– 43% of respondents report that AI-based cybersecurity tools have improved their organization’s ability to detect and respond to cyber threats.

Artificial intelligence has become deeply integrated into daily operations across industries, yet a startling gap remains in organizational preparedness. According to new data released by ISACA on May 5, a full 90% of digital trust professionals report that employees within their organizations are actively using AI tools. However, fewer than half of these companies have any formal AI safety or security policies in place, leaving them dangerously exposed to data breaches, privacy violations, and other cyber threats.

The findings reveal a stark disconnect. Only 38% of respondents said their organization maintains a comprehensive, formal AI policy governing tool usage. Another 30% reported having only a limited policy, while a worrying 25% admitted to having no AI-related policies at all. This policy vacuum has fueled the rise of Shadow AI, where employees turn to large language models and other AI tools to streamline their work without official oversight. The risk is clear: sensitive company data may be inadvertently shared with these models, creating fresh vulnerabilities.

Those surveyed in ISACA’s annual AI Pulse Poll expressed significant doubt about their ability to prevent a security incident triggered by a Shadow AI tool unknown to their security and IT teams. The uncertainty extends beyond detection. A majority of respondents, 56%, said they do not know how long it would take to shut down an AI system in the event of a security incident. Only 20% reported having any process to halt or override AI systems if they began performing malicious activity or fell victim to data poisoning attacks.

“With only 38% of practitioners confident in their board’s understanding of AI risks, the leadership deficit is as real as the technology one,” said Ulrika Dellrud, a member of ISACA’s Emerging Trends Working Group and chief privacy and data ethics officer at Smarter Contracts. “Effective AI governance also starts with mastering your data: without strong data and privacy governance as a foundation, organizations cannot manage AI risk, ensure trust, or unlock sustainable value. The path forward is clear: AI success will depend not just on innovation, but on disciplined governance, informed leadership and responsible data stewardship.”

The poll also highlights an escalating threat landscape. Data privacy and security professionals believe that AI-powered cybersecurity threats are growing, and many fear these attacks are going unnoticed. Among the key challenges identified: 71% said AI-fueled phishing and social engineering attacks have become harder to detect, 58% noted that AI makes authenticating digital information significantly more difficult, and 38% reported a decline in trust for traditional threat detection methods.

Still, there is a silver lining. Many respondents see AI as a powerful ally for cyber defenders. 43% said deploying AI-based cybersecurity tools has improved their organization’s ability to detect and respond to threats. The ISACA AI Pulse Poll, based on responses from 3,400 global digital trust professionals in IT audit, governance, cybersecurity, privacy, and emerging technology roles, underscores a critical moment: organizations must move quickly to close the gap between adoption and governance.

(Source: Infosecurity Magazine)

Topics

ai policies 95% shadow ai 92% ai security risks 90% ai governance 88% ai incident response 85% ai cybersecurity threats 83% Data Privacy 80% AI Adoption 78% board understanding 75% ai defense tools 72%