Although 66% reported dedicated AI policies, only 19% had controls designed to detect attacks that manipulate an AI system’s instructions.
Key takeaways
- 71% of the organizations surveyed have not conducted AI security testing. 34% planned testing within 12 months, while 37% said it was not a current priority.
- 66% reported having a dedicated AI policy, but adoption of individual technical controls ranged from 12% to 31%.
- 74% said their AI environments pull information from external sources, while controls for reviewing connections and limiting AI agents’ access remained far less common.
IANS Research and Artico Search reported that AI security testing had not been conducted at 71% of the organizations represented in a survey of 113 chief information security officers, even though 66% had dedicated AI policies.
The AI Security: 1H 2026 Benchmark Report defines AI security testing as efforts to expose weaknesses specific to AI systems. Examples include malicious instructions intended to override an AI system, attempts to extract information from a model, and tests for possible data leaks.
Among the respondents, only 29% said their organizations conducted AI security testing. That included 14% whose security teams tested internally, 7% that used an outside company, and 8% that used both approaches.
Another 34% planned to begin testing within 12 months. The remaining 37% said AI-specific testing was not a current priority.
Written policies outpace actual AI security testing
The survey found that written policies were much more common than technical controls intended to enforce them.
In addition to the 66% with dedicated AI policies, 20% said they had added AI language to an existing acceptable-use or security policy. Another 10% were developing an AI policy.
However, no individual AI-specific security control covered by the survey had been adopted by more than 31% of respondents’ organizations.
Logging and monitoring AI prompts was the most common control, at 31%. Reviews of how AI models and their training data were developed followed at 29%, while 25% had requirements for classifying data used with AI.
Just 19% employed controls intended to detect malicious instructions that manipulate AI systems. 16% said they employ AI-specific red-team testing, and 15% filtered AI responses before they reached users.
AI systems retrieve outside data with limited safeguards
Enterprise AI systems often connect to other software and services to retrieve information. AI agents can also use those connections to perform actions for users.
74% of respondents said their organizations’ AI environments retrieve information from other software or services. That included 40% using direct software connections, 35% using company-built servers that connect AI with other tools, and 34% using third-party plug-ins. Respondents could select more than one method.
The report separately asked what safeguards organizations use when AI agents retrieve information or act on users’ behalf. Formal security reviews of the servers and plug-ins connected to those agents were the most common safeguard, but only 31% reported using them. 25% limited agents to the minimum access needed for their tasks. Another 25% reported recording and reviewing agents’ actions. Only 18% specified which information or systems each AI agent could access and which actions it was allowed to take, while 11% separated AI systems from other parts of the company’s network to help prevent an incident from spreading.
Senior leaders’ understanding remains limited
Security chiefs also reported a gap between the risk they saw and senior leaders’ understanding of it.
65% rated their organizations’ AI security risk at four or five on a five-point scale. However, only 20% rated senior leaders’ understanding of that risk as good or very good. Another 45% rated it fair, while 35% described it as poor or very poor.
Asked about their organizations’ ability to manage AI security risks over the next 24 months, 38% were somewhat or very pessimistic. Another 41% were somewhat or very optimistic, and 21% were neutral.
AI vendor reviews remain limited
Organizations were more likely to ask AI suppliers general security questions than to examine how their models were developed or maintain lists of approved AI products.
68% added AI-specific security questions to vendor assessments. However, only 30% reviewed information about how vendors developed their models and what data they used for training. Only 21% maintained an approved list of AI models and software connections.
The report covers 113 responses collected in April and May 2026 from CISOs across organization sizes and industries. IANS said the survey will remain open through the end of 2026.

