Security

68% of Unstructured Data Sits Unprotected, and Enterprises Are Feeding It to AI Anyway

A Cloud Security Alliance and Thales study of 210 IT and security professionals found most organisations cannot see, scan, or protect the majority of their unstructured data. Nearly half now name AI the top future threat to that same data, even as they connect more of it to AI systems every quarter.

September 11, 2026 · Security
A dark, close-up view of server hardware in a data centre rack, lit by rows of blue and green status indicators

Key Takeaways

  • A Cloud Security Alliance and Thales survey of 210 IT and security professionals found 68% report that less than 80% of their unstructured data is protected.
  • Only 9% of organisations can scan unstructured data in real time, and 23% cannot scan it at all.
  • 47% now name AI the top future threat to unstructured data, yet 40% also call AI a core capability for managing it.
  • A separate survey of 1,500-plus security leaders found 61% cite sensitive data exposure as their top AI concern, and 73% say AI-powered threats are already having a significant impact.

Every enterprise AI rollout runs on the same assumption: that the documents, emails, contracts, and file shares being fed into a model are at least as well governed as the databases IT has spent two decades locking down. A Cloud Security Alliance study published with Thales in March found that assumption does not hold. Most of that unstructured data cannot be seen, scanned, or protected at anything close to the standard applied to structured systems.

Most Unstructured Data Cannot Be Seen, Let Alone Secured

The CSA surveyed 210 IT and security professionals in November 2025 and found unstructured data already makes up roughly a third of the average organisation's data, with Gartner estimating the true figure runs as high as 70 to 90% once semi-structured formats are counted in. Nearly a third of respondents said unstructured data now accounts for more than half of their annual data growth.

Visibility has not kept pace. 56% of organisations reported only partial visibility into where that data actually lives, and 68% said less than 80% of it is protected at all. Scanning capability is worse still: just 9% can scan unstructured data in real time, and 23% cannot scan it under any circumstances. “The explosive growth of unstructured data...has become a defining characteristic of modern organisations,” said Hillary Baron, CSA's AVP of research, and the study's numbers suggest most security programmes have not defined a response to it.

Tool sprawl is compounding the gap rather than closing it. 32% of organisations use 11 or more separate tools to manage unstructured data, and 12% use more than 21. Todd Moore, Thales's VP of data security, put the mismatch plainly: today's organisations are generating unstructured data at a pace that traditional tools were never designed to handle.

AI Is Simultaneously the Fix and the Newest Risk

The same survey found 47% of respondents now rank AI as the single greatest future threat to unstructured data, ahead of every other named category. At the same time, 40% called AI a core capability for actually managing that data, which means nearly as many organisations are counting on the technology to solve a problem they also expect it to make worse.

A separate CSA survey of more than 1,500 security leaders, published in April, found 61% name sensitive data exposure their top AI-related concern and 56% cite regulatory compliance violations. 73% said AI-powered threats are already having a significant impact on their organisation today, not a future one, and 92% agreed AI agents operating across the workforce demand a security response most teams have not built yet.

Feeding ungoverned unstructured data into that environment does not stay contained to one system. Nearly three in five business leaders told CIO Dive that key decisions at their organisation are already being made on inaccurate or inconsistent data, a gap that widens every time an AI model trains or reasons over a file share nobody has fully catalogued.

Regulators Are Starting to Treat AI Infrastructure as Critical Infrastructure

The exposure is not limited to the files themselves. The infrastructure running the AI workloads that touch them is drawing its own regulatory attention. NIST convened a two-day workshop in July on securing AI data centres, covering everything from model training pipelines and access control to supply chain security and physical facility protection. The initiative sits under America's AI Action Plan, which calls explicitly for new technical standards for high-security AI data centres.

That framing matters because it treats the data centre running AI training and inference as a distinct security perimeter, not an extension of the general-purpose network it sits inside. A facility processing unstructured business data through a model carries obligations that a standard compute cluster does not, and most organisations' data centre security posture predates that distinction.

None of the three surveys cited here describe a hypothetical risk. They describe data that already exists, sits largely unprotected today, and is already being connected to AI systems that 73% of security leaders say are already causing measurable harm.

The number worth carrying forward is not 47%, the share who see AI as the biggest coming threat. It is 68%, the share of unstructured data that is unprotected right now, before AI enters the picture at all.

Share

More in Security

All Resources →