Drata has released findings from its report, ‘The State of GRC in the Age of AI’. The study, conducted by Wakefield Research on behalf of Drata, surveyed 300 US-based IT and security professionals about AI adoption trends, corresponding risks, and the practices their organizations are adopting to close the gap.
While it has often been stated that AI tools have arrived faster than the governance needed to manage them, the precision needed to trust them, or the accountability needed to address their failures, the research supports these concerns and indicates potential consequences for organizational security. Only 13% of IT and security professionals confidently claim full visibility of the AI tools active within their organization, while the remaining 87% are not fully confident that they can identify every AI tool used by employees.
Additional findings include:
- 83% state that they are not fully prepared to handle the coming wave of AI integration.
- Three-quarters of organizations now discontinue underperforming AI tools faster than they previously did. When the tools expose shortcomings, more than half of organizations revert to manual processes.
- 86% of teams agree that many GRC-focused AI tools are not enterprise-ready.
- 64% of respondents prefer targeted agentic AI systems to broad, all-in-one platforms. Among risk-focused buyers, that figure rises to 70%.
The survey findings indicate a clear priority for GRC leaders: effective governance depends on sufficient visibility, and organizations need to address the visibility gap.






