75% of CISOs secure AI with controls built for other risks #AI


Security Magazine’s Michael Leland catalogs eight routes unsanctioned AI takes into enterprises, from browser extensions to AI coding tools. A 2026 Pentera survey he cites finds 75% of CISOs secure AI workflows with controls built for other risks. The visibility gap shows up first at the browser and the endpoint, where IT often cannot tell which account an employee is using.

A developer wires an internal database into a homegrown AI app and never files a ticket. An administrator drafts company correspondence in a personal ChatGPT account. A marketing team’s AI agent chases sales leads on its own. Those are the opening scenes in a September 16 Security Magazine piece by Michael Leland, and none of them involves a purchase order, a vendor review, or anyone in IT knowing it happened.

The numbers Leland attaches to that picture are the part worth bookmarking. A 2026 Pentera survey of CISOs, cited in the piece, found 75% are securing AI-driven workflows with controls designed for other attack surfaces. A Lenovo survey, also cited by Security Magazine, found 61% of IT leaders have seen a rise in AI-related security threats while only 31% feel confident managing those risks.

Read together, the two surveys suggest most enterprises are governing a new class of data flow with tooling built for the last one. That is a planning fact for the year ahead. The CIO who signs the security budget now has a fairly precise map of where the borrowed tools stop working.

IT leaders on AI security: threats seen vs. confidence to manage them

Lenovo survey, as cited by Security Magazine · © MarketScaleDownload chart

The browser is where IT loses the thread

Leland’s catalog runs to eight entry points. The first, and by his account the most common, is the plain browser tab. Most employees meet AI tools there first, and the problem Security Magazine describes is blunt: IT usually cannot tell whether the person typing is signed into a corporate tenant or a personal account. Type proprietary data into the wrong one and it can end up in a training set.

The control Leland calls for is tenant recognition, meaning the ability to distinguish a company login from a personal one, paired with prompt visibility and policy enforcement before content reaches the AI provider. The placement matters as much as the capability. Security Magazine argues the control has to sit where the employee actually interacts with the AI, because downstream inspection catches the data after it has already left.

For an IT security director evaluating browser management or secure enterprise browser products this quarter, that reframes the demo. The useful question is whether the product knows which account a user is in at the moment of the prompt, not whether it can block a domain.

Extensions that pass review today and change tomorrow

AI browser extensions are Leland’s second door, and the mechanics he lays out explain why traditional data loss prevention struggles with them. Extensions can read page content, insert text into prompts, and move data out in ways DLP tools were never built to inspect, according to Security Magazine. Grammarly and Claude are named as examples of a category that runs to thousands.

The detail that should worry a procurement lead is the update problem. An extension that clears a risk review today can turn malicious after a future update, Leland writes. A one-time approval is therefore a weak control on its own.

Security Magazine’s proposed answer is risk scoring and categorization that refreshes as extension behavior changes, with the ability to restrict or block based on the current profile rather than the profile at approval time. Leland also draws a context line that most allow lists cannot: a grammar extension helping with a personal email is one thing, and the same extension reading customer records inside an ERP screen is another. Rigid allow and deny lists, in his view, create both a poor user experience and an administrative burden.

An extension that clears a risk review today can turn malicious after a future update, so a one-time approval is a weak control on its own.

Desktop apps, AI browsers and the developer’s IDE

Three more entry points sit outside the managed browser altogether. Consumer AI browsers ship with AI built into the interface, and when employees adopt them outside approved environments they operate beyond the managed browser and its policies, Security Magazine reports. Any control plan has to account for those tools as well.

Desktop AI applications go further. Most major AI tools now offer them, and they can access local files, clipboard contents and sometimes the screen itself. Browser controls cannot reach them, and Leland notes that most endpoint protection was not designed to monitor prompt activity. An employee can paste an entire contract, a customer list or source code into a desktop app and leave no record IT can find.

The fifth door is the coding environment. Developers increasingly work in JetBrains, Visual Studio, Cursor and GitHub Copilot, and Security Magazine points out that these tools give AI direct access to the codebase, including credentials, API keys, internal tooling and proprietary logic. Most governance frameworks do not account for that depth of exposure. For organizations with large engineering teams already on Copilot or Cursor, this is the entry point where the gap between policy and practice is likely widest, because the AI is not visiting the data. It lives inside it.

AI arrives through upgrades, so nobody signs for it

Leland’s list explains where unsanctioned AI enters. Omdia’s research explains why there is so much of it. In a March 2026 InformationWeek analysis, Omdia chief analyst Brian Washburn reported that nearly 80% of large enterprises are active AI adopters, based on surveys of 733 large-enterprise decision-makers conducted independently and with HPE Juniper Networking.

The more useful finding for a governance team is how that adoption happens. Most enterprises are not building models, Washburn wrote in InformationWeek. They are getting AI as features added to platforms they already run: security vendors adding AI threat analysis, business applications adding scheduling optimization and transcription, inventory systems becoming more predictive. Even companies that do not consider themselves AI adopters use it inside SaaS tools, collaboration suites and search.

That pattern indicates why the entry points multiply without a procurement event to trigger review. A feature update does not go through vendor risk assessment the way a new contract does. If Omdia‘s picture holds inside a given organization, the honest inventory of AI touchpoints is probably larger than the list of AI tools anyone approved.

CIO Dive’s Paige Gross reported in April 2026 that an Altimetrik and HFS Research survey of more than 500 tech leaders found just 14% of enterprises deploying AI have a clear strategy with defined goals and outcomes, while 71% describe theirs as incomplete or developing. The same report found that CIOs, CTOs and other tech leaders, who most often hold AI accountability, feel pressure to deploy before governance systems, employee training or a clear owner for problems are in place. Altimetrik’s Mark Baker described the dynamic to CIO Dive as a moment in which organizations pick generative AI as the solution and then go looking for a problem.

The teams asked to close the gap are already short-staffed

Every control Leland describes has to be run by someone. Network World’s Denise Dubie reported in June 2026 on Enterprise Management Associates‘ Network Management Megatrends 2026 study of 352 IT professionals in North America and Europe, and the staffing picture is tight. The share of organizations finding it somewhat or very difficult to hire network technology experts rose from 26% in 2022 to 41% in 2024 and 52% this year, according to EMA, with the shortage sharpest at senior and mid-career levels where cloud, security and automation skills concentrate.

EMA also found the typical IT organization runs four to ten monitoring and troubleshooting tools, a count that has barely moved in more than a decade, and saw no meaningful link between toolset size and operational success. Yet 73% of respondents said they are at least somewhat likely to replace a network observability or monitoring tool within two years, Network World reported.

Those two figures sit uneasily together, and EMA does not resolve the tension. For a CIO reading Leland’s list, though, they carry a practical caution. Adding a standalone product for each of eight entry points would push a ten-tool shop toward eighteen. Security Magazine’s own framing points the other way: controls that follow the work across browsers, desktops and IDEs, rather than one more console per door.

EMA’s Shamus McGillicuddy said in the firm’s public statement that networks will make or break AI projects and that CIOs need to fund the empty seats and better automation their operations teams are asking for. The plant manager or finance director whose team quietly adopted an AI extension last spring is not going to stop. The open question Leland’s piece leaves is which comes first in the 2027 budget: the tooling that can see a personal login at the prompt, or the people to run it.



Click Here For The Original Source.

——————————————————–

..........

.

.