Only 6% of organizations have an advanced AI security strategy, signaling widespread unpreparedness for AI-driven threats according to the AI Risk & Readiness in the Enterprise: 2025 Report from BigID.
The study surveyed security, compliance, and data leaders across multiple industries and found that nearly two-thirds (64%) of organizations lack full visibility into their AI risks, leaving them vulnerable to security blind spots and compliance failures. This issue is exacerbated by the rise of shadow AI, unauthorized or unmonitored AI tools used within enterprises, further increasing exposure to data misuse and regulatory violations.
The rapid adoption of AI has created a critical security oversight for many organizations. Our research reveals that while businesses are eager to leverage AI capabilities, they’re simultaneously exposing themselves to unprecedented risks by neglecting proper security governance. This gap between innovation and protection must be addressed immediately before these vulnerabilities lead to significant breaches.
Dimitri Sirota, CEO, BigID
Other key findings include:
- AI-powered data leaks: 69% of organizations cite AI-powered data leaks as their top security concern in 2025, yet nearly half (47%) have no AI-specific security controls in place.
- Regulatory unpreparedness: nearly 55% of organizations are unprepared for AI regulatory compliance, risking potential fines and reputational damage as new regulations take effect.
- Data protection gaps: almost 40% of organizations admit they lack the tools to protect AI-accessible data, creating a dangerous gap between AI adoption and security controls.
- Limited maturity: only 6% of organizations have an advanced AI security strategy or a defined AI TRiSM (Trust, Risk, and Security Management) framework, signaling widespread unpreparedness for AI-driven threats.
Industry-specific challenges
Key industries remain critically underprepared for AI risks, with significant gaps in protection, compliance, visibility, and risk management across sectors.
- The financial services sector, despite handling highly sensitive data, shows that only 38% of firms have AI-specific data protection measures in place.
- In healthcare, 52% of organizations cite compliance with AI regulations as a major challenge.
- 48% of retailers lack visibility into how AI models handle customer data.
- Technology companies, ironically, are among the least prepared, with 42% operating without any AI risk management strategy, despite leading AI innovation.
Recommendations
To improve their AI risk posture, organizations must strengthen AI governance through the implementation of new strategies. Companies should:
- Deploy AI risk monitoring and response mechanisms
- Establish AI-aware data governance strategies
- Implement access controls to mitigate shadow AI & prevent unauthorized AI data interactions
- Align AI security and compliance strategies with evolving regulations through a comprehensive AI TRiSM approach.
Methodology
The report is based on survey responses from security, compliance, and data professionals across multiple industries, with representation from technology (34%), financial services (21%), government (8%), healthcare (5%), retail (5%), and other sectors (27%). The survey included small-to-mid-sized enterprises (54%), mid-market companies (26%), and large enterprises (20%) across North America, Europe, Asia-Pacific, the Middle East, Africa, and Latin America.






