Gigamon's survey of 307 CISOs found AI governance has outrun the ability to see what AI is actually doing on the network. Gartner's latest guidance says the fix starts with treating every frontier AI deployment as an insider risk.
Key Takeaways
Most enterprises now have an AI policy. Far fewer can prove anyone is following it. Two pieces of research published in the last week of September put numbers on that gap, and both point at the same uncomfortable conclusion: AI adoption has moved from a governance question to a visibility question, and most security teams cannot yet see enough to answer it.
Gigamon's 2026 Hybrid Cloud Security Survey, released September 29 and now in its fourth year, polled more than 1,000 security and IT leaders, 307 of them CISOs, across Australia, France, Germany, Singapore, the United Kingdom and the United States. Eighty percent of CISOs cite inadequate governance of unsanctioned AI use as the top challenge to securing data, and 76% say limited visibility into AI-driven traffic is a major barrier to securing AI adoption. Forty-three percent now rank AI corporate governance as a top security priority.
The two numbers are linked. A policy that bans an unapproved model, or restricts which data a sanctioned one can touch, is only enforceable if someone can observe the traffic. In a hybrid estate, where some models run in public clouds, some on private infrastructure and some inside SaaS products, that traffic crosses boundaries no single tool watches. "Hybrid AI is moving faster than governance," said Grant Yacomeni, CISO at Gigamon. "Organizations want the flexibility to choose the right AI model for every workload, but that flexibility depends on having the visibility to govern it."
The incidents are already arriving. Among organisations that experienced a breach, 83% reported AI-related security incidents. Internal leaks into AI systems and unsanctioned AI use were each cited by 30%. Breaches overall rose 18% year over year, and 36% of respondents identified East-West lateral traffic, the movement between systems inside the network, as their greatest breach risk. That is precisely the traffic machine-to-machine AI workflows generate, and the traffic perimeter tools were never built to inspect.
Gartner's view, set out on September 30 in its top five actions for CISOs and reported by IT-Online, sharpens the access side of the same problem. A Gartner survey of 297 cybersecurity leaders in the second quarter of 2026 found 54% of organisations have no defined approach to limiting AI agent access, or rely on predefined human access. In other words, an agent acting for an employee often carries that employee's full set of permissions.
Gartner's recommended response is blunt: treat all frontier AI deployments as insider risks. That means governing autonomous multiagent systems by the actions they are allowed to take rather than by how capable the underlying model is, and using guardian agents to constrain the blast radius when something goes wrong. Its other actions include cementing the CISO's authority in AI safety, replacing recognition as proof of identity in the face of mainstream deepfakes, budgeting for preemptive capabilities and starting postquantum cryptography pilots by 2027. Gartner warned that waiting risks migration costs 200% higher, and found 51% of CISOs have not begun any postquantum work.
"Detection and response capabilities are no longer sufficient," said Luis Castillo, senior director analyst at Gartner, arguing for deception, automated moving target defence and predictive threat intelligence. The point lines up with Gigamon's data on recovery: only 27% of CISOs believe their organisation can identify a root cause and restore normal operations within 72 hours, compared with 48% of other C-level executives.
None of this lands on an idle function. Splunk's CISO Report, based on Oxford Economics interviews with 650 CISOs in nine countries, found nearly all respondents now count AI governance and risk management among their responsibilities. Ninety-two percent still name improving threat detection and response as a top priority, followed by identity and access management at 78% and investment in AI security capabilities at 68%.
The board is part of the friction. Gigamon found 70% of CISOs are concerned about their board's understanding of security best practices, 41% rank improving board understanding of AI risk among their top priorities for the next 12 months, and more than a quarter worry about losing their job after a serious incident. Spending is not the missing ingredient either: 88% have deployed new tools to improve detection and visibility, and 87% call deep observability foundational to securing AI. The gap is in connecting what those tools see into evidence that a policy is being honoured.
The surveys agree that the AI question has changed. Boards are no longer asking whether to adopt it; CISOs are being asked to prove it is under control. Without visibility into the traffic AI creates and limits on what agents can reach, that proof does not yet exist.
Whitepaper
Seventy-six percent of CISOs cannot see where AI-driven traffic goes. This whitepaper explains how mapping every system, user and integration that moves data turns an AI policy into something you can actually verify.
Download
Whitepaper
Hybrid AI spreads models across public cloud, private infrastructure and SaaS, exactly where Gigamon's respondents lose sight of traffic. This whitepaper covers closing those cloud visibility and policy gaps from one platform.
Download
Guide
Thirty percent of breached organisations traced incidents to internal leaks into AI systems. This guide shows how bringing AI to governed content, rather than content to unapproved AI, removes the reason to leak it in the first place.
Download
Cisco found only one in five organizations can deploy a new control within six months of budget approval.
macOS 27 is the first release that will not run on an Intel Mac, arriving with Apple at 65% of enterprise endpoints.
Splunk found 46% of security teams spend more time maintaining tools than defending, and 52% have thought about leaving the field.