Report by Optro
Human behavior: The AI risk surface GRC can't ignore
Key Findings
Only 18% of organizations automatically block unauthorized AI domains.
72% of Chief Information Security Officers report a significant increase in attacks, led primarily by AI-powered social engineering.
Only 34% of organizations maintain a formal AI model inventory.
82% of IT, security, audit, and GRC professionals report an increase in AI-enabled attacks over the last 12 months.
42% of Chief Information Security Officers say insufficient focus on AI governance is their primary concern about the future policy environment.
56% of organizations use embedded AI within third-party vendor tools that employees often do not recognize as using AI.
Over two-thirds of GRC and security leaders are only "somewhat confident" or "not very confident" that their organization can respond decisively to a fast-moving AI security incident.
23% of Chief Information Security Officers cite lack of AI security expertise as their top barrier.