Recent research from CyXcel highlights a concerning gap: 29% of UK businesses surveyed have only just implemented their first AI risk strategy. This figure is similar in the US, at 27%.
In addition, 31% of UK and 23% of US organizations do not have any AI governance policies in place.
This critical gap exposes organizations to substantial risks, including data breaches, regulatory fines, reputational damage, and serious operational disruption – especially as AI-related threats continue to evolve rapidly.
CyXcel’s research also reveals that 18% of UK and 20% of US companies surveyed are not prepared for AI data poisoning – a type of cyberattack that corrupts the training datasets of AI and machine learning (ML) models – or for deepfake or identity cloning incidents (16% / 19%).
Research methodology
The research was conducted by Censuswide among a sample of 400 cybersecurity professionals (aged 18+), each with a sound understanding of their company’s risk management processes. The sample included 200 respondents from the UK and 200 from the US. Data collection took place between 28 May 2025 and 2 June 2025.






