ISACA Survey Reveals Governance and Security Gaps Amid Rapid Enterprise AI Adoption

manufacturing-news

Rapid adoption of artificial intelligence across enterprises is outpacing the development of governance, oversight, and security frameworks, according to preliminary findings from ISACA’s 2026 AI Pulse Poll, unveiled at RSA Conference 2026. The global survey, based on responses from more than 3,400 digital trust professionals spanning IT audit, cybersecurity, governance, privacy, and emerging technologies, highlights growing concerns around the lack of preparedness in managing AI-related risks. While organizations are accelerating AI deployment to enhance efficiency and innovation, many are struggling to establish the controls needed to ensure safe and responsible use.

One of the key findings indicates significant uncertainty in incident response readiness. More than half of respondents reported that they do not know how quickly their organization could halt an AI system in the event of a security incident. Only a third expressed confidence in being able to stop such systems within an hour, raising concerns about response capabilities during critical events.

Confidence levels in investigative readiness are also mixed. Less than half of respondents said they are highly confident in their ability to explain AI-related incidents to leadership or regulatory authorities, while a notable proportion expressed low or no confidence in handling such scenarios effectively.

The survey also points to ambiguity around accountability. While some respondents believe responsibility for AI-related failures lies with executive leadership or boards, others assign it to technology or security leaders. A significant share of participants indicated uncertainty about who would ultimately be accountable in the event of harm caused by AI systems.

Human oversight remains limited in many organizations. Only a minority reported that AI-generated decisions are consistently reviewed or approved before execution. In several cases, human intervention occurs only after anomalies are detected, while others lack clear visibility into how oversight is implemented.

Transparency is another area of concern. A relatively small percentage of organizations require disclosure when AI is used in generating work outputs, and enforcement of such policies remains inconsistent. Many organizations do not have formal disclosure requirements in place.

Industry experts note that as regulatory frameworks evolve globally, organizations will need to strengthen governance structures, improve transparency, and establish clear accountability mechanisms. ISACA emphasized the importance of equipping professionals with the skills and resources needed to manage AI risks effectively. The full report is scheduled for release in May 2026 and is expected to provide deeper insights into how enterprises can align innovation with trust, security, and regulatory compliance in the age of artificial intelligence.