Strategy & CIO

80% of CISOs Name Unsanctioned AI Their Top Data Challenge, and 76% Lack Visibility Into the Traffic It Creates

Gigamon's survey of 307 CISOs found AI governance has outrun the ability to see what AI is actually doing on the network. Gartner's latest guidance says the fix starts with treating every frontier AI deployment as an insider risk.

October 6, 2026 · Strategy & CIO
An empty monitoring room with banks of status screens above a curved desk of keyboards, desk phones and paperwork

Key Takeaways

  • Gigamon surveyed more than 1,000 security and IT leaders, including 307 CISOs: 80% name governance of unsanctioned AI as their top data security challenge and 76% cite limited visibility into AI-driven traffic.
  • Among organisations that suffered a breach, 83% reported AI-related security incidents, with internal leaks into AI systems and unsanctioned AI use each cited by 30%.
  • A Gartner survey of 297 cybersecurity leaders found 54% of organisations have no defined approach to limiting AI agent access, or simply reuse predefined human access.
  • Only 27% of CISOs say they can identify a root cause and restore normal operations within 72 hours, against 48% of other C-level executives.

Most enterprises now have an AI policy. Far fewer can prove anyone is following it. Two pieces of research published in the last week of September put numbers on that gap, and both point at the same uncomfortable conclusion: AI adoption has moved from a governance question to a visibility question, and most security teams cannot yet see enough to answer it.

Governance Without Sight

Gigamon's 2026 Hybrid Cloud Security Survey, released September 29 and now in its fourth year, polled more than 1,000 security and IT leaders, 307 of them CISOs, across Australia, France, Germany, Singapore, the United Kingdom and the United States. Eighty percent of CISOs cite inadequate governance of unsanctioned AI use as the top challenge to securing data, and 76% say limited visibility into AI-driven traffic is a major barrier to securing AI adoption. Forty-three percent now rank AI corporate governance as a top security priority.

The two numbers are linked. A policy that bans an unapproved model, or restricts which data a sanctioned one can touch, is only enforceable if someone can observe the traffic. In a hybrid estate, where some models run in public clouds, some on private infrastructure and some inside SaaS products, that traffic crosses boundaries no single tool watches. "Hybrid AI is moving faster than governance," said Grant Yacomeni, CISO at Gigamon. "Organizations want the flexibility to choose the right AI model for every workload, but that flexibility depends on having the visibility to govern it."

The incidents are already arriving. Among organisations that experienced a breach, 83% reported AI-related security incidents. Internal leaks into AI systems and unsanctioned AI use were each cited by 30%. Breaches overall rose 18% year over year, and 36% of respondents identified East-West lateral traffic, the movement between systems inside the network, as their greatest breach risk. That is precisely the traffic machine-to-machine AI workflows generate, and the traffic perimeter tools were never built to inspect.

Agents Inherit Human Keys

Gartner's view, set out on September 30 in its top five actions for CISOs and reported by IT-Online, sharpens the access side of the same problem. A Gartner survey of 297 cybersecurity leaders in the second quarter of 2026 found 54% of organisations have no defined approach to limiting AI agent access, or rely on predefined human access. In other words, an agent acting for an employee often carries that employee's full set of permissions.

Gartner's recommended response is blunt: treat all frontier AI deployments as insider risks. That means governing autonomous multiagent systems by the actions they are allowed to take rather than by how capable the underlying model is, and using guardian agents to constrain the blast radius when something goes wrong. Its other actions include cementing the CISO's authority in AI safety, replacing recognition as proof of identity in the face of mainstream deepfakes, budgeting for preemptive capabilities and starting postquantum cryptography pilots by 2027. Gartner warned that waiting risks migration costs 200% higher, and found 51% of CISOs have not begun any postquantum work.

"Detection and response capabilities are no longer sufficient," said Luis Castillo, senior director analyst at Gartner, arguing for deception, automated moving target defence and predictive threat intelligence. The point lines up with Gigamon's data on recovery: only 27% of CISOs believe their organisation can identify a root cause and restore normal operations within 72 hours, compared with 48% of other C-level executives.

The Mandate Keeps Growing

None of this lands on an idle function. Splunk's CISO Report, based on Oxford Economics interviews with 650 CISOs in nine countries, found nearly all respondents now count AI governance and risk management among their responsibilities. Ninety-two percent still name improving threat detection and response as a top priority, followed by identity and access management at 78% and investment in AI security capabilities at 68%.

The board is part of the friction. Gigamon found 70% of CISOs are concerned about their board's understanding of security best practices, 41% rank improving board understanding of AI risk among their top priorities for the next 12 months, and more than a quarter worry about losing their job after a serious incident. Spending is not the missing ingredient either: 88% have deployed new tools to improve detection and visibility, and 87% call deep observability foundational to securing AI. The gap is in connecting what those tools see into evidence that a policy is being honoured.

The surveys agree that the AI question has changed. Boards are no longer asking whether to adopt it; CISOs are being asked to prove it is under control. Without visibility into the traffic AI creates and limits on what agents can reach, that proof does not yet exist.

Share

More in Strategy & CIO

All Resources →