Skip to main content

Cybersecurity statistics / Policy

42% of Chief Information Security Officers say insufficient focus on AI governance is their primary concern about the future policy environment.

PublisherOptro
ReportHuman behavior: The AI risk surface GRC can't ignore
Published12 May 2026
TopicsPolicy, AI Governance

Published by Optro in Human behavior: The AI risk surface GRC can't ignore, 12 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Compare this across sources

12 sources answer what share of organisations have an ai governance policy in place. They report between 18% and 44%, with a median of 36.5%.

See all 12 sources

Related statistics

74% of healthcare organizations identify visiting clinicians as requiring the most granular policy attention.
Elisity & Omdia, 27/05/2026
50% of organizations have formal, active AI policies in place, and 42% are actively developing AI governance frameworks.
Tines, 04/02/2026
42% of companies globally do not have a policy in place to govern the use of AI by employees as of 2025.
Riskonnect, 22/10/2025
72% of companies globally do not have a policy for the use of generative AI by partners and suppliers as of 2025.
Riskonnect, 22/10/2025
67% of organisations are implementing usage guidelines for GenAI.
Proofpoint, 26/08/2025
The share of organizations requiring human review before high-risk AI actions dropped from 40% to 25% in six months.
JumpCloud Inc., 18/07/2026

Get the newsletter

Weekly cybersecurity statistics by email.