TL;DR: Across a survey of more than 900 IT and security leaders, 83% of enterprises said they are already using AI, but only 13% reported strong visibility into how AI interacts with sensitive data, according to Cyera and CyberSecurity Insiders. The gap shows that governance, monitoring, and access control are still trailing AI adoption, especially where AI behaves like an identity with data access.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “Cyera Unveils Cyera Research Labs with First-Ever AI Readiness Report on Data Security”.
By the numbers:
- 83% of enterprises are already using AI.
- Only 13% report strong visibility into how AI interacts with sensitive data.
- Only 11% can automatically block risky AI activity.
Key questions
Q: What breaks when AI tools are allowed broad write access to internal systems?
A: Broad write access turns an AI tool from a helper into an unreviewed operator.
A: Autonomous AI agents create more risk because they can respond to triggers, APIs, and data changes without a human prompting each action.
Q: How can security teams tell whether AI lifecycle controls are working?
A: They should look for evidence that access requests, policy enforcement, and usage visibility are centrally recorded and current.
Practitioner guidance
- Define AI as a governed identity class Create a policy model that assigns AI systems explicit identity scope, permitted datasets, and approval boundaries instead of inheriting broad default access.
- Enforce data-scoped access for AI Replace blanket access with dataset-level entitlements so AI systems can only retrieve information tied to an approved business purpose.
- Move monitoring to retrieval time Instrument AI requests against sensitive data so over-access is detected and blocked when the interaction happens, not after review cycles close.
Bottom line: AI adoption is outrunning the governance model needed to control what AI systems can see, retrieve, and expose.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI data security readiness is now an identity governance issue, not a narrow data protection issue. When AI systems can reach sensitive data, the organisation is deciding who or what is allowed to act on that data. That makes policy, entitlement scope, and accountability the real control plane. Practitioners should stop treating AI access as a feature toggle and start treating it as governed identity.
A few things that frame the scale:
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption, according to the 2026 Infrastructure Identity Survey.
- Business leaders plan to spend $124 million on average on AI in 2026, and 91% say data security and risk will shape their AI strategy.
A question worth separating out:
Q: What is the difference between governing human access and governing AI agent access?
A: Human access governance focuses on people with relatively stable roles, while AI agent governance must account for autonomous behavior, changing integrations, and multiple machine identities behind one action stream. The same principles still apply, including least privilege and accountability, but they must be enforced continuously across scopes, sessions, and connected tools. That is why lifecycle control matters more for agents.
👉 Read our full editorial: AI data security readiness is lagging enterprise adoption