Optro
Reports
All Statistics
In the past 12 months, 40% of organizations reported inaccurate AI outputs.
In the past 12 months, 27% of organizations reported data breaches tied to AI use.
In the past 12 months, 26% of organizations reported regulatory action tied to AI use.
30% of organizations have never tested for agentic AI failure (loss of control or autonomous decision-making failures).
Nearly two-thirds of organizations experienced an AI agent-related incident in the past 12 months, resulting in data exposure, operational disruption, and financial losses.
One in three organizations use AI in critical resilience workflows.
85% of organizations have integrated AI into core operations.
Only 25% of organizations have comprehensive visibility into how employees are using AI.
58% of leaders believe their governance controls are keeping pace with AI adoption.
Only 18% of leaders have active risk mitigations in place for AI.
Only 18% of organizations automatically block unauthorized AI domains.
72% of Chief Information Security Officers report a significant increase in attacks, led primarily by AI-powered social engineering.
Only 34% of organizations maintain a formal AI model inventory.
82% of IT, security, audit, and GRC professionals report an increase in AI-enabled attacks over the last 12 months.
42% of Chief Information Security Officers say insufficient focus on AI governance is their primary concern about the future policy environment.
56% of organizations use embedded AI within third-party vendor tools that employees often do not recognize as using AI.
Over two-thirds of GRC and security leaders are only "somewhat confident" or "not very confident" that their organization can respond decisively to a fast-moving AI security incident.
23% of Chief Information Security Officers cite lack of AI security expertise as their top barrier.
82% of organizations report an increase in AI-enabled attacks over the past year.
Roughly 80% of organizations describe 'shadow AI' use as moderate to pervasive.
In the past 12 months, 27% of organizations report AI-related data breaches.
In the past 12 months, 40% of organizations report inaccurate outputs from AI.
No single function owns more than 25% of AI governance responsibility.
In the past 12 months, 26% of organizations report regulatory actions related to AI.
85% of organizations have integrated AI into core operations or multiple functions.
25% of organizations have comprehensive visibility into employee AI use.