Artificial Intelligence

PwC Survey Finds AI Security Lags as Data Governance Gaps Persist

avatar

Written by: Tathagata Sen

Updated 2:47 AM EDT, October 5, 2026

post detail image

Photo credit: Unsplash.com

Organizations are increasing their cybersecurity spending as AI adoption accelerates, but many still lack the data and governance controls needed to manage emerging AI risks, PwC found in its 2027 Global Digital Trust Insights survey published October 1. 

The survey collected responses from 3,934 business and technology leaders across 71 countries.

The findings show that attacks targeting AI systems were the top cyber threat organizations felt least prepared to address, with 50% of security leaders identifying them as a preparedness gap. 

At the same time, many organizations have yet to fully implement basic data-risk measures or establish clear ownership for AI governance. PwC’s findings point to gaps in the foundations organizations need to deploy AI securely and at scale.

AI Security Outpaces Governance Readiness

Half of security leaders identified attacks targeting AI systems as one of the cyber threats their organizations are least prepared to address. That ranked ahead of cloud-related threats at 40%, third-party breaches at 34% and ransomware at 33%. 

Meanwhile, 84% of security and finance leaders expect their cyber budgets to increase over the next year, with 58% of security leaders ranking AI among their top cyber spending priorities.

The survey also found limits in organizations’ ability to secure the data that increasingly feeds AI systems. Companies had implemented an average of only three of seven key data-risk measures surveyed, while only 5% had implemented all seven. 

Data Governance Becomes an AI Control Point

For chief data officers (CDOs), the findings highlight the connection between AI adoption and the underlying data environment. 

PwC found that 51% ranked data protection and trust as their top choice when identifying factors influencing their cyber spending priorities for the coming year. This was ahead of securing against AI-enabled attacks at 46% and securing AI and autonomous agents at 45%.

The survey also found no single model for AI governance and risk management. Twenty-nine percent of CEOs and security and risk leaders said accountability sits with the CIO, CTO or technology function, while 26% pointed to a dedicated AI leader or AI function and 17% to the CISO or cyber function.

That lack of clear ownership matters as organizations give AI systems greater autonomy. Only 22% of respondents said they would authorize AI agents to execute defensive actions fully autonomously, while 38% would allow partial autonomy and 36% would keep execution human-led with AI support.

For CDOs, the findings reinforce the need to treat data protection and trust as part of AI readiness. Strong data classification, loss prevention, access controls and clear ownership can give organizations a more reliable foundation for deploying AI and autonomous agents.

Related Stories

Similar Topics
Artificial Intelligence
Data Management
Diversity
Testimonials
background imagebackground image
Community Network

Join Our Community

starElevate Your Personal Brand

starShape the Data Leadership Agenda

starBuild a Lasting Network

starExchange Knowledge & Experience

starStay Updated & Future-Ready

logo
Social media icon
Social media icon
Social media icon
Social media icon
About