TL;DR: AI is now deployed inside mobile apps by 95% of respondents, yet 65% of organisations with self-reported advanced security programs still experienced incidents, according to NowSecure’s 2026 Mobile App Risk Management Survey of 485 senior security leaders. The gap matters because mobile app risk is now an AI and software supply chain governance problem, not just a testing cadence problem.
NHIMG editorial — based on content published by NowSecure: 2026 Mobile App Risk Management (MARM) Survey
By the numbers:
- 95% deploy AI inside them today.
- 485 senior security leaders
- 65% of organizations that rate their own security program as advanced still report experiencing a security incident.
Questions worth separating out
Q: How should security teams govern mobile apps that now include AI features?
A: Treat AI-enabled app functions as separate governed paths, not as ordinary code changes.
Q: Why do advanced mobile security programs still report incidents?
A: Because maturity labels often measure intent rather than operational evidence.
Q: What do security teams get wrong about third-party mobile SDKs?
A: They often treat SDKs as implementation details instead of governed dependencies.
Practitioner guidance
- Replace maturity scoring with evidence-based control validation Measure mobile security by runtime observability, release-specific findings, and dependency-level changes rather than by programme maturity labels.
- Inventory every third-party SDK and library Create an authoritative inventory for each app, then review network access, data collection, and authentication interactions before release approval.
- Separate AI-enabled app paths from standard app logic Define distinct review steps for AI-generated outputs, data access patterns, and any downstream actions triggered by the app.
What's in the full report
NowSecure's full report covers the operational detail this post intentionally leaves for the source:
- Program ownership breakdowns that show which teams are taking responsibility for mobile app risk.
- AI-specific governance controls and the survey’s model-vs-human prediction comparison.
- Industry-by-industry benchmark data for finance, healthcare, high tech, and retail.
- Survey methodology and the full question set behind the 485-leader sample.
👉 Read NowSecure's 2026 Mobile App Risk Management Survey findings →
Mobile app AI risk and incident gaps - are controls keeping up?
Explore further
Mobile app risk is becoming a governance problem, not a testing problem. The survey shows that strong self-description does not reliably predict fewer incidents, which means mobile security cannot be judged by release cadence alone. Programmes need evidence of runtime control, dependency visibility, and scope management. The broader lesson for identity teams is that app governance now intersects with access governance whenever mobile software can reach sensitive services or data.
A question worth separating out:
Q: When should organisations tighten release controls for mobile apps?
A: Whenever the app includes AI features, sensitive data access, or significant third-party dependency change. Those conditions increase the chance that a normal release alters privilege, visibility, or trust boundaries. Release control should become stricter as app behaviour becomes less predictable.
👉 Read our full editorial: Mobile app AI risk is outpacing security program maturity