Lightbeam’s perspective on the 2026 SANS AI Survey
The 2026 SANS AI Survey shows AI adoption is accelerating, governance is lagging, and AI-enabled attacks are already here. Lightbeam explains why AI security starts with controlling sensitive data access, exposure, and governance.
Seth Knox
Executive Summary
AI adoption is no longer theoretical. According to the 2026 SANS AI Survey, active AI use in cybersecurity strategy jumped from 50% in 2025 to 78% in 2026. But adoption has moved faster than the governance, validation, and workforce maturity needed to support it. The report also found that 63% of practitioners report significant AI shortcomings in threat detection and response, while 78% of organizations have observed confirmed or suspected AI-enabled attacks in the past year.
Lightbeam’s perspective is simple: AI security starts with data security.
The biggest AI security risk is not only the model. It is the sensitive data GenAI tools, copilots, SaaS AI, and AI agents can reach, use, assemble, and expose.
That means AI governance cannot stop at policies, frameworks, or one-time assessments. To safely scale AI, security teams need operational guardrails around enterprise data: what sensitive data exists, whose data it is, who or what can access it, whether AI should be allowed to use it, and what action is needed to reduce exposure before AI amplifies risk.
Download the full 2026 SANS AI Survey report

61%. Source: 2026 SANS AI Survey Insights.
AI Adoption Has Outpaced Operational Readiness
The first major finding from the SANS report is that AI adoption has crossed the threshold from experimentation into everyday security operations. AI is now used for log analysis, threat explanation, code writing, incident reporting, and other core security tasks. The report notes that Microsoft Copilot, ChatGPT, Google Security, custom in-house models, open-source AI tools, and coding assistants are all already in use across organizations.
But more AI adoption does not automatically mean more AI confidence.
SANS found that 63% of practitioners report significant shortcomings when AI detects or responds to threats, up from 45% in 2025. The report also found that AI guidance has led many teams in the wrong direction, creating a new layer of validation work for practitioners who adopted AI to reduce workload.
|
THE CONFIDENCE PARADOX: Organizations are using AI more, but they are also seeing more ways for AI to be wrong, misunderstood, or over-trusted. |
For security leaders, the question is no longer, “Should we allow AI?” That decision has largely been made by the business. The real question is, “Can we validate, govern, and control AI safely?”
Governance Responsibility Has Grown, But Governance Maturity Has Not
The second major SANS finding is that security teams are being pulled into enterprise AI governance faster than their programs are maturing.
SANS found that 76% of security teams now hold a governance role for enterprise AI, up from 68% in 2025. Yet only 36% have a formal AI risk management and compliance program in place, while 43% are still in the early stages of developing AI governance policies.

2026 SANS AI Survey Insights
For organizations that do not yet have a formal AI risk program, adopting a recognized framework such as NIST AI RMF or ISO/IEC 42001 is a strong starting point. Frameworks create common language for AI risk, accountability, governance, and control objectives.
But frameworks are not the finish line.

The report makes clear that governance programs often remain too abstract. Practitioners’ biggest governance challenge is lack of visibility into where AI models are used and what they expose. SANS found that 63% cite this visibility gap as a major challenge, and 54% say there are no established frameworks for AI audits.
That is where AI governance has to become operational.
Security teams need to answer practical questions:
- Which AI tools, copilots, and agents are in use?
- What sensitive data can AI reach?
- Whose data is being accessed, uploaded, retrieved, or exposed?
- Which users, service accounts, copilots, or agents have excessive access?
- Should that AI use be allowed, restricted, remediated, or blocked?
- What evidence proves the policy was enforced?
AI governance should start with a framework, but it only works when it becomes visible, enforceable, and auditable in daily workflows.
The Business Mandate Is to Enable AI Safely
AI adoption is being driven from the top of the business. Security teams are not being asked to simply block usage. They are being asked to help the business move faster, safely.
That creates a hard problem.
Policies alone do not stop sensitive data from flowing into AI tools. Policies alone do not prevent a copilot from surfacing over-permissioned data. Policies alone do not control what an AI agent can retrieve, combine, or act on. If AI can reach the wrong data, the risk already exists.
The SANS report highlights this operational gap. AI adoption is increasing, security teams are gaining governance responsibility, but visibility into AI data risk remains limited.
|
THE PRACTICAL QUESTION: How do we enable AI adoption without creating sensitive data exposure, privacy incidents, or broken trust? |
Lightbeam’s answer: put guardrails around the data AI can reach, use, and expose.
AI-Enabled Attacks Expand the Data Exposure Blast Radius
The third major finding from the SANS report is that AI-enabled attacks are not a future risk. They are already being observed at scale.
SANS found that 78% of organizations observed confirmed or suspected AI-enabled attacks in the past year, and 95% believe threat actors are using AI. The report also found that 61% of practitioners now use AI in red team work, nearly double the 33% reported in 2025.

The important point for data security is not just that attackers can use AI for phishing, deepfakes, reconnaissance, or vulnerability exploitation. It is that AI increases the speed and scale of data exposure.
A compromised identity, manipulated workflow, over-permissioned copilot, or poorly governed AI agent can only expose what it is allowed to reach. But when that access is broad, AI can retrieve, summarize, combine, and expose sensitive data at machine speed.
SANS makes this point directly: AI-enabled attacks extend beyond faster phishing or automated exploitation because a compromised identity or manipulated AI workflow can reach whatever sensitive data that identity or workflow is permitted to touch. What an attacker can extract depends heavily on how tightly access is scoped.
That makes least privilege a core AI security control. It also makes sensitive data discovery, classification, labeling, access governance, and data minimization foundational to AI readiness.
AI Security Starts with Data Security
The biggest AI security risk is not only the model.
It is the sensitive data GenAI tools, copilots, SaaS AI, and AI agents can access, use, assemble, and expose.
AI can receive sensitive data through prompts. It can process files, screenshots, and attachments. It can inherit broad access through copilots and agents. It can assemble context across SharePoint, Slack, Salesforce, Google Drive, databases, documents, SaaS applications, and other enterprise systems.
That creates a new kind of exposure.
AI often operates through permissions the organization already granted, so the activity may appear authorized. But without identity, access, and business-purpose context, AI can assemble a real person, customer, employee, deal, or piece of intellectual property from fragments scattered across the enterprise.
To govern AI safely, organizations need to answer three questions:
- Where is AI using sensitive data, including unsanctioned shadow AI tools?
- What sensitive data is being accessed, uploaded, retrieved, or exposed, and whose data is it?
- Should that AI use be allowed, restricted, remediated, or blocked based on governance policy?
These are the questions that turn AI governance from policy into operational control.
What Security Leaders Should Do Now
The goal is not to slow AI down. The goal is to make AI safe enough to scale.
Here are seven steps security leaders can take to move from AI policy to operational AI governance.
1. Discover where AI tools, copilots, and agents are being used
You cannot govern what you cannot see. Shadow AI, embedded SaaS AI, browser-based GenAI tools, copilots, and emerging agents all create new pathways to enterprise data.
2. Assess what sensitive data AI can reach
Generic AI risk is difficult to act on. Specific data exposure is actionable. Security teams need to know what sensitive data AI can access, whose data is involved, and what business impact exposure would create.
3. Label data for AI use, restriction, or exclusion
AI guardrails depend on knowing whether data is approved, restricted, or prohibited for AI use. Labels can help control AI ingestion, retrieval, and policy enforcement.
4. Apply least privilege to users, copilots, service accounts, and agents
AI often inherits access that already exists. If privilege sprawl exists in SharePoint, Slack, Salesforce, file shares, cloud storage, or databases, AI can amplify it.
5. Monitor prompts, responses, files, and data exposure paths
Organizations need visibility into how sensitive data moves through AI interactions, including prompt uploads, attached files, referenced documents, generated responses, and copilot retrieval paths.
6. Minimize unnecessary data before AI can amplify risk
The less stale, duplicate, orphaned, over-retained, or overexposed sensitive data AI can reach, the smaller the blast radius.
7. Generate audit evidence for every policy decision and remediation action
AI governance must be provable. Security, privacy, risk, and compliance teams need evidence showing what data was involved, what policy applied, what action was taken, and how risk was reduced.
The Lightbeam Perspective: AI Guardrails for Your Data
Lightbeam helps enterprises safely adopt and scale AI by governing the sensitive data AI can reach, use, and expose.
Our perspective aligns closely with the SANS findings: AI adoption is accelerating, governance responsibility is expanding, and organizations need to close the gap between written AI policy and real-world AI data exposure.
Lightbeam’s approach is grounded in identity-centric data security. The platform helps organizations discover and classify sensitive data, map it to identity and business context, understand who or what can access it, apply labels and policies for AI use, detect risky AI exposure, remediate excessive access, and generate evidence throughout the process.
That matters because AI governance is not just about the model. It is about the data.
Security teams need to know:
- Whose sensitive data AI can reach
- Where that data lives
- Who or what can access it
- Why that data exists
- Whether AI should be allowed to use it
- Which access paths create the most risk
- What action will reduce exposure before AI amplifies it
That is how organizations move from AI anxiety to AI adoption with confidence.
AI Readiness Starts with Data Readiness
The 2026 SANS AI Survey shows a clear market reality: organizations have committed to AI. Now they have to make it work safely.
Adoption is rising. Trust is still uneven. Governance maturity is lagging. AI-enabled attacks are already being observed. And the data AI can reach has become a central control point.
The next phase of AI security will not be defined by organizations that simply say yes to every AI tool or no to every AI risk. It will be defined by organizations that can govern AI access to sensitive data continuously, with enough identity, access, business context, and audit evidence to move at the speed AI requires.
AI readiness starts with data readiness.
FAQ
What is AI data security?
AI data security is the practice of protecting the sensitive data that AI tools, copilots, SaaS AI, and AI agents can access, use, retrieve, process, or expose. It includes sensitive data discovery, classification, labeling, access governance, least privilege, monitoring, data minimization, and audit evidence.
Why does AI security start with data security?
AI security starts with data security because AI risk often comes from the data AI can reach. If a GenAI tool, copilot, or agent can access sensitive customer data, employee data, regulated data, or intellectual property, it can potentially expose that data through prompts, responses, retrieval, automation, or agentic workflows.
What did the 2026 SANS AI Survey find?
The 2026 SANS AI Survey found that active AI use in cybersecurity strategy rose from 50% in 2025 to 78% in 2026. It also found that 63% of practitioners report significant AI shortcomings in threat detection and response, 76% of security teams now hold a governance role for enterprise AI, and 78% of organizations observed confirmed or suspected AI-enabled attacks in the past year.
How can organizations operationalize AI governance?
Organizations can operationalize AI governance by moving beyond written policy into daily controls. That includes discovering AI use, assessing what sensitive data AI can access, labeling data for AI use or exclusion, applying least privilege to users and agents, monitoring AI data exposure, minimizing unnecessary data, and generating audit evidence.
Are NIST AI RMF and ISO/IEC 42001 enough for AI governance?
NIST AI RMF and ISO/IEC 42001 are strong starting points because they provide structure for AI risk management and governance. But frameworks alone are not enough. Organizations also need operational visibility, access control, remediation workflows, and evidence that policies are being enforced against real AI usage and real enterprise data.
Source Notes
Statistics and findings are from the 2026 SANS AI Survey Insights report, “Poisoned Wells and Pure Springs: Drawing Security and Compromise from the Same AI Source,” written by Matt Bromiley, July 2026.