// research commentary

76% own AI governance. 54% have no way to audit it.

The 2026 SANS AI Survey — written by Matt Bromiley for the SANS Research Program in July 2026, drawing on 536 practitioners and 57 senior leaders and CISOs — reads less like a story about AI adoption and more like a story about what adoption outran. Security teams have taken ownership of enterprise AI governance. The visibility and audit infrastructure that ownership implies did not arrive with it. This is MoorAI's independent reading of a third-party report, with every number attributed to SANS and none of them ours.

The finding in one line: SANS reports that 76% of security teams now hold a governance role for enterprise AI, up from 68% in 2025 — while 63% cite lack of visibility into where AI models are used and what they expose, and 54% say there are no established frameworks for AI audits. Responsibility moved. The instrumentation did not.

01Adoption is settled — and the survey is precise about whose adoption

2026 SANS AI Survey · adoption & maturity

SANS records the largest year-over-year move in the survey's history: active AI use in cybersecurity strategy rose from 50% in 2025 to 78% in 2026. That is the headline most coverage will lead with, so it is worth being exact about what it measures.

Read this one carefully. The 50% → 78% figure describes security teams using AI inside their own workflows — detection, triage, analysis. It is not a measure of employees running coding agents, and it should not be stretched into one. We flag this because the stretch is tempting and it would be wrong.

Adoption is also not the same as maturity. SANS finds only 27% describe their AI deployment as mature production, with 33% in early production and 21% still experimental or pilot. Meanwhile the threat side has caught up: 78% of organizations reported confirmed or suspected AI-enabled attacks (45% confirmed, 33% suspected), and 95% believe threat actors are using AI.

And AI is not quietly solving the SOC's problems. SANS reports 63% of practitioners now see significant AI shortcomings in threat detection and response — up sharply from 45% in 2025. That number belongs to the tooling, and we want to say plainly: MoorAI does not fix it. We do not improve detection accuracy, and we do not reduce hallucination in security tooling. That is a different problem with different vendors.

02The governance gap: owned, but not seen

2026 SANS AI Survey · governance ownership & maturity

Here is where the survey stops being about adoption. SANS reports 76% of security teams now hold a governance role for enterprise AI (68% in 2025) — and then reports that practitioner AI risk maturity barely moved: 43% are in the "early stages of developing AI governance policies," and only 36% have a formal AI risk management program. The 2025 figures were 42% and 35%. Within the margin of a rounding error.

The perception gap is sharper still. SANS finds 50% of leaders report a formal AI risk program, while only 36% of practitioners agree. The survey's own comment is the most quotable line in it: "A program that the people doing the work cannot see is not governing much in practice."

The two numbers this post is named for. SANS ranks lack of visibility into where AI models are used and what they expose as the #1 governance challenge at 63% (up from 56%), and finds 54% say there are no established frameworks for AI audits (52% in 2025). Correspondingly, 52% name "increasing visibility into where AI is being used" as their single most common planned adaptation.

Unlike the 50%→78% adoption figure, these findings are about enterprise AI broadly — the AI the whole organization runs, not just the AI the security team runs. That is the distinction that makes them relevant to what MoorAI does, and it is why we are careful to separate the two.

03Policy, shadow AI, and the data-leakage worry

2026 SANS AI Survey · policy coverage & data exposure

SANS finds only 41% use generative AI for security tasks under strict policy — and 39% say usage is informal, with no policy at all. Separately, 36% of practitioners worry about sensitive data or company IP leaking through employee use of AI tools. Training has felt the shift too: 73% say AI changed their team's training requirements, up from 51%.

Chris Cochran, SANS Field CISO and VP of AI Security, frames the response in the survey this way: telling people "don't use AI" just drives usage into the shadows — "The goal is to pull it into visibility where it can be governed. Name an owner, inventory your AI tools, write a one-page policy, brief your team, and reassess in 90 days."

That is a practical program, and the first two steps of it — owner and inventory — are exactly the steps the 63% visibility gap says most teams have not completed.

04Why point-in-time assessment cannot close this

2026 SANS AI Survey · assessment cadence

The survey observes that governance work skews heavily toward point-in-time checks, and states the limitation directly: "An assessment is a snapshot. It does not watch model behavior between evaluations, enforce policy in daily workflows, or catch output drift over time."

SANS also makes a specific structural point about agents: because copilots and AI agents inherit the permissions of the users and service accounts behind them, the survey frames "least privilege [as] a practical AI governance control rather than a separate IAM concern." An agent is not a new identity to govern — it is an existing identity, operating faster and unattended.

The thesis: if the gap is visibility and auditability rather than adoption, then more assessments will not close it. What closes it is enforcement that runs continuously, at the point of use, and that leaves a record an auditor can read.

05Where MoorAI maps — and where it does not

honest mapping · SANS findings → shipped MoorAI controls

These are MoorAI's capabilities set against the SANS findings above. SANS did not evaluate MoorAI and does not endorse it; the mapping is ours.

Governance without surveillance. The uncomfortable version of the SANS visibility finding is that most ways to see where AI is used involve reading what people wrote. MoorAI's position is that you can have the inventory, the enforcement and the audit trail while every artifact stays content-free — category and one-way hash, never the prompt.

Independent commentary. Every statistic on this page is from the 2026 SANS AI Survey (Matt Bromiley, SANS Research Program, July 2026; 536 practitioners, 57 senior leaders/CISOs) and is attributed as such. SANS did not review, evaluate, sponsor, or endorse MoorAI, and is unaffiliated with it — as are Optro and Zenity. The interpretation, the capability mapping and any errors in them are MoorAI's alone. Read the survey yourself before quoting it; the numbers here are reported findings, not our measurements.

Get the AI governance implementation guide →

MoorAI — content-free, on-device guardrails for AI agents. Governance without surveillance. See also what MoorAI does, the compliance crosswalk, and the ISO/IEC 42001 mapping.

glick.run — AGPL-3.0