CSA, the Cloud Security Alliance, has released The State of AI Security and Governance. Commissioned by Google, it provides a ‘data-driven look at how enterprises are adopting generative and agentic AI’.
Based on a global industry survey, the report shows that AI governance is the strongest predictor of AI readiness and risk management.
Key findings include:
AI governance is the ‘maturity multiplier’ driving responsible adoption
Organizations with formal AI governance are significantly more advanced in terms of AI adoption. They are also twice as confident in their ability to protect AI systems.
Security teams are leading early use of AI in cybersecurity workflows
Over 90% of respondents are testing or planning to use AI for threat detection, red teaming, and access control.
Multi-model strategies are growing, dominated by a small group of providers
Organizations are pursuing multi-model strategies—using an average of 2.6 models – but deployments are increasingly concentrated among the ‘Big Four’: Gemini, Claude, GPT, and LLaMA. While this signals growing operational maturity, it also introduces new resilience, interoperability, and vendor lock-in concerns.
Executive AI enthusiasm, questions about ability to secure
Executive enthusiasm for AI remains high, yet most respondents (72%) were either not confident or neutral in their organization’s ability to secure it.
AI ownership is diffuse – security is stepping up
Responsibility for AI deployment is distributed across functions, but security teams now lead AI protection in 53% of organizations.
Data risk takes centre stage – but model risk & safety still lags behind
Organizations are prioritizing well-understood risks: 52% cite sensitive data exposure as their top concern, followed by regulatory compliance (50%). These traditional issues far outweigh newer AI-specific threats like model drift, prompt injection, and model theft.






