TL;DR: Claude Sonnet, ChatGPT and Gemini aligned reasonably well with survey responses on external business risk, but predicted materially lower ratings than mobile security leaders gave themselves on maturity, investment and readiness, according to NowSecure. The gap matters because 65% of organisations that rated their programs advanced or highly effective still reported incidents, while 95% said they deploy AI in mobile apps but 37% do not monitor that AI behavior.
NHIMG editorial — based on content published by NowSecure: AI predictions and mobile app security maturity gaps in the 2026 Mobile App Risk Management Survey
By the numbers:
- Every respondent in the survey rated mobile apps as very important or critical to their business, and 58% said a single day of downtime causes severe business damage.
- 37% said they do not monitor AI behavior, their organizations deploy AI in mobile apps, but 37% said they do not monitor AI behavior in the apps they develop and deploy.
Questions worth separating out
Q: How should security teams validate mobile app security maturity claims?
A: They should test the claims against runtime evidence.
Q: Why can AI predictions differ from internal security assessments?
A: AI models work best when the answer is anchored in widely available public information.
Q: What signals show that mobile app governance is failing?
A: A common signal is high confidence paired with continued incidents or unexplained exposure.
Practitioner guidance
- Tie maturity claims to runtime evidence Require every mobile app security maturity rating to be backed by runtime testing, data-flow analysis, and observed third-party interactions rather than self-assessment alone.
- Add AI behavior monitoring to app governance Define what AI features must be logged, reviewed, and escalated in mobile apps, including prompts, outputs, and downstream data handling.
- Validate identity-linked app dependencies Inventory federated identity flows, service tokens, API keys, and external dependencies so teams can see which identities and services each app actually relies on.
What's in the full report
NowSecure's full analysis covers the operational detail this post intentionally leaves for the source:
- The full survey breakdown behind the AI Prediction Score and the largest response gaps across maturity, investment, and readiness.
- Industry and vertical comparisons showing how mobile app risk perceptions differ across finance, healthcare, high tech, and retail.
- Additional findings on AI adoption, monitoring gaps, testing practices, and third-party risk in mobile applications.
- The survey's strategic recommendations for closing the gap between policy, AI visibility, and evidence-based testing.
👉 Read NowSecure's analysis of AI predictions and mobile app security maturity gaps →
Mobile app security maturity gaps: are AI predictions missing the mark?
Explore further
Confidence is not control, and mobile app security keeps proving it. The article’s central value is that it exposes the gap between perceived maturity and observable security reality. That gap is familiar across identity and application governance: policies, budgets, and attestations can all be present while runtime exposure remains poorly measured. In practice, this means organisations should stop treating maturity scores as evidence and start treating them as hypotheses that require validation.
A question worth separating out:
Q: How should identity and appsec teams share responsibility for mobile app risk?
A: Identity teams should govern the access paths, secrets, and service identities that mobile apps depend on, while appsec teams validate runtime behaviour and data movement. The two functions only work together if governance covers both who can access what and what the application actually does with that access.
👉 Read our full editorial: AI predictions missed mobile app security maturity and AI visibility