Insight

AI Cyber Benchmark 2026: Governance matures, operational security lags

Published September 14, 2026

  • Cybersecurity

AI is becoming embedded in employee workflows, customer services and critical business processes. The question is no longer whether organizations should adopt it, but how they can scale it securely while maintaining trust and control.

Our latest AI Cyber Benchmark, covering 30 large public and private organizations, reveals an uneven picture. Governance and protection capabilities are advancing, but detection, incident response and recovery remain immature. As organizations increasingly build and operate their own AI systems, this operational security gap becomes harder to ignore.

 

 
 
 
 
 

Organizations are moving from using AI to building it

Organizations are taking greater ownership of how AI systems are built and operated. Half of the benchmark panel now designs AI systems internally using existing frameworks or pre-trained models, compared with 35% in 2025.

Meanwhile, the share of organizations only consuming existing AI functionalities has fallen sharply. End-to-end AI development is also gaining ground, increasingly supported by advanced generative AI use cases.

AI adoption approach 2025 2026

Only use existing AI functionalities

30%

10%

Design AI systems using existing frameworks or pre-trained models

35%

50%

Manage the entire AI development chain

35%

40%

This shift reflects a growing ambition to reduce external dependencies and gain control over critical AI capabilities. It also changes the security equation: the more organizations own their AI systems, the more responsibility they assume for securing them throughout their lifecycle.

AI security improves, but progress remains uneven

The emergence of agentic AI, growing regulatory expectations and the increasing scale of AI deployment are expanding the scope of security challenges.

To reflect these developments, we updated our assessment framework to address agentic AI security, AI-specific protection controls, monitoring and incident response alongside governance and risk management.

 

Overall AI cybersecurity maturity by NIST function

The benchmark indicates progress across all assessed pillars compared with 2025. Governance structures are becoming established, AI-related risks are entering existing processes, and dedicated protection controls are supporting deployment.

However, monitoring, investigation and response capabilities remain comparatively immature.

Organizations are becoming better at governing AI than at operating it securely once deployed into production.

Gérôme Billois, Partner, Wavestone

Agentic AI raises the stakes for identity and control  

AI agents can access corporate resources, interact with applications and execute actions on behalf of users or services. Security must therefore extend beyond models and data to the identities, permissions and tools that enable these workflows.

While 33% of organizations have integrated agentic AI into governance frameworks, only 17% have incorporated secure access to AI functions and tools into development standards. Organizations need to constrain delegated permissions, trace agent actions and monitor activity across the entire workflow.

The challenge also extends to attackers, who may use agentic AI to automate reconnaissance, social engineering and attack execution at scale.

Organizations must control not only what AI generates, but what it is authorized to do.

 

  •  
  •  
  •  

AI security cannot be treated as a one-time approval. As models, capabilities and agent permissions evolve, governance, testing and monitoring must adapt throughout the lifecycle. The challenge is to move from validating AI at deployment to maintaining control continuously.

The AI security paradox

AI security is increasingly being designed alongside the technology it protects, rather than added after adoption. Cybersecurity teams are involved earlier, but must make decisions about systems whose capabilities and risks keep changing.

AI security therefore cannot be treated as a one-time approval. As models, capabilities and agent permissions evolve, governance, risk assessments, testing and monitoring must adapt throughout the lifecycle. The challenge is to move from validating AI at deployment to maintaining control continuously.

What comes next for AI security?

Three priorities will shape the next phase of maturity.

Build trusted resilience

Building resilient AI systems means more than ensuring availability. Availability remains a key requirement, especially where organizations depend on a limited number of providers. After an incident, organizations must also verify that models, datasets and knowledge bases remain trustworthy. Resilience planning should therefore combine continuity measures with asset restoration, integrity checks and the safe resumption of operations. Where appropriate, failover across models or providers can help reduce dependencies and strengthen resilience.

Take ownership of model security

Fine-tuned, open-weight and self-hosted models offer greater flexibility, but also transfer more security responsibility to organizations. Security teams need to assess models before adoption, validate fine-tuned versions and monitor changes and dependencies throughout their lifecycle. These responsibilities should shape adoption decisions from the outset, rather than being addressed only after deployment.

Control autonomous actions

As AI agents gain access to enterprise systems, organizations must ensure their actions remain bounded, traceable and interruptible. Recent incidents have shown that harmful autonomous actions are not merely a theoretical risk, making effective controls an immediate priority. This means limiting permissions, monitoring abnormal activity and maintaining the ability to revoke access to critical systems immediately. Risk assessments and response procedures should explicitly address harmful autonomous actions, whether caused by compromise, misuse or unexpected behavior.

 

 

From AI governance to operational resilience

The 2026 AI Cyber Benchmark shows meaningful progress. Organizations are establishing governance, integrating AI risks into existing processes and deploying protection controls.

The next step is to make those foundations operational.

That means assigning clear accountability for AI systems, assessing their risks, implementing security controls, connecting them to security monitoring, testing them throughout their lifecycle and preparing teams to respond to and recover from incidents. Agentic AI and greater ownership of models make these capabilities more urgent.

The next measure of AI security maturity will be whether organizations can maintain control, trust and continuity when something goes wrong.

About the benchmark

The 2026 AI Cyber Benchmark draws on assessments of 30 large public and private organizations, complemented by insights from Wavestone’s AI security engagements over the past three years.

The assessment is structured around five pillars based on the NIST Cybersecurity Framework, each evaluated through more than 30 questions to assess AI security maturity on a scale from 0 to 100%. This edition expands coverage of agentic AI security, AI-specific protection controls, monitoring and incident response.

Percentages refer to the organizations assessed and should be read as findings from this panel, rather than estimates for the entire market.

For background on the previous assessment and its findings, read the 2025 AI Cyber Benchmark.

 

Download the full benchmark

AI Cyber Benchmark 2026

pdf · 1008KO

Learn more
Share this content