Report by Optro

Human behavior: The AI risk surface GRC can't ignore

8 FINDINGSPublished May 12, 2026
View Original Report →

Key Findings

Only 18% of organizations automatically block unauthorized AI domains.

AI GovernanceAI Domains

72% of Chief Information Security Officers report a significant increase in attacks, led primarily by AI-powered social engineering.

AI-Powered AttacksSocial Engineering

Only 34% of organizations maintain a formal AI model inventory.

AI GovernanceRisk ManagementAI Model Inventory

82% of IT, security, audit, and GRC professionals report an increase in AI-enabled attacks over the last 12 months.

AI-Powered Attacks

42% of Chief Information Security Officers say insufficient focus on AI governance is their primary concern about the future policy environment.

PolicyAI Governance

56% of organizations use embedded AI within third-party vendor tools that employees often do not recognize as using AI.

Third-Party RiskAI Adoption

Over two-thirds of GRC and security leaders are only "somewhat confident" or "not very confident" that their organization can respond decisively to a fast-moving AI security incident.

Incident ResponseAI Security IncidentAI Risk

23% of Chief Information Security Officers cite lack of AI security expertise as their top barrier.

Workforce SkillsAI Security