TL;DR: Purple Book Community’s survey of 650+ senior cybersecurity leaders across seven industries finds a wide gap between claimed AI visibility and operational control, according to ArmorCode, with 59% still admitting shadow AI and 70% seeing AI code vulnerabilities reach production. The report shows why inventory alone is not governance, and why control, remediation, and policy enforcement now matter more than awareness.
NHIMG editorial — based on content published by ArmorCode: Purple Book Community Research State of AI Risk Management 2026 report
By the numbers:
- Purple Book Community surveyed 650+ senior cybersecurity leaders across seven industries and two continents to map the gap between AI adoption and enterprise control.
- 82% of security professionals say tool sprawl is actively hurting their ability to remediate the risks that actually matter.
Questions worth separating out
Q: How should security teams govern AI agents without creating a manual review bottleneck?
A: Use policy, automation, and class-based controls so agents are provisioned through deployment pipelines, not ticket queues.
Q: Why do complete AI inventories still miss shadow AI in practice?
A: Because discovery and governance are not the same thing.
Q: What do security teams get wrong about AI-generated code risk?
A: They often focus on catching insecure output after code is written, which is too late for AI-native workflows.
Practitioner guidance
- Establish continuous AI inventory controls Move beyond periodic discovery by tying asset ownership, approval status, and runtime validation to a continuous control process that can detect shadow AI after deployment.
- Gate AI-generated code before production Require explicit review, approval, and exception handling for generated code before release, and ensure rollback ownership is assigned when vulnerabilities bypass normal checks.
- Reduce AI risk tool fragmentation Create a single triage workflow that assigns findings, prioritises remediation, and records closure so separate scanners do not dilute accountability.
What's in the full report
ArmorCode's full report covers the operational detail this post intentionally leaves for the source:
- Cross-tab analysis of the confidence gap by survey segment and industry
- The report's full breakdown of shadow AI, detection trust, and tool-sprawl effects
- Survey methodology and respondent profile for the 650+ senior security leaders
- The complete set of research charts and data slices behind the executive summary
👉 Read ArmorCode's analysis of the AI risk management confidence gap →
AI governance confidence gap: what security teams are missing?
Explore further
The confidence gap is now a governance problem, not an awareness problem. Security leaders in this survey already know AI is spreading, yet the data shows that knowledge is not translating into control. That distinction matters because governance failure is usually caused by missing ownership, weak enforcement, or unclear decision rights, not lack of visibility. Practitioners should treat AI governance as an operating model issue, not a reporting exercise.
A question worth separating out:
Q: How can organisations tell whether AI governance is actually working?
A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped. If those four things are missing, the programme has policy language but not operational control. Auditors will notice the gap quickly.
👉 Read our full editorial: AI governance confidence is outpacing control in enterprise security