Report by Pentera
AI Security & Exposure Benchmark 2026
Key Findings
1% of enterprises have a dedicated AI security budget.
21% of enterprises plan to introduce a dedicated AI security budget.
50% of CISOs cite lack of internal expertise as a top AI security challenge.
36% of CISOs report insufficient AI-specific security tools as a top challenge.
58% of CISOs say AI is influencing their security stack consolidation strategy.
3% of CISOs are actively consolidating their security stack due to AI.
11% of CISOs are consolidating their security stack for reasons unrelated to AI.
44% of CISOs acknowledge their AI security posture lags behind the rest of their security program.
48% of CISOs list limited visibility into AI usage as a top AI security challenge.
67% of CISOs report limited visibility into how AI is used across their environment.
75% of CISOs report their enterprises rely on extending controls originally designed for other attack surfaces to cover AI-driven workflows and infrastructure.
11% of enterprise CISOs have security tools specifically designed to protect AI systems.
78% of enterprises fund AI security through existing security budgets.