Three-Quarters of CISOs Use Legacy Controls for AI Risks
New survey data reveals most enterprises are securing AI workflows with tools built for earlier threats, while entry points multiply without IT oversight.

Legacy tools meet new attack surface
A Pentera survey of chief information security officers found that 75 percent are securing AI-driven workflows with controls designed for other attack surfaces, according to a September analysis in Security Magazine. At the same time, a Lenovo survey cited in the same piece found 61 percent of IT leaders have seen a rise in AI-related security threats while only 31 percent feel confident managing those risks.
Read together, the two surveys suggest most enterprises are governing a new class of data flow with tooling built for the last one. That gap matters because AI is entering organizations through channels that bypass traditional procurement and review.
Michael Leland's analysis in Security Magazine catalogs eight entry points where AI tools reach corporate data without IT visibility. The most common is the browser tab, where employees access AI services through both corporate and personal accounts. The problem is blunt: most IT teams cannot distinguish which account a user is signed into when they type a prompt. Proprietary data entered into a personal ChatGPT account can end up in a training set.
Browser extensions change after approval
AI browser extensions present a second control gap. Extensions can read page content, insert text into prompts, and move data out in ways traditional data loss prevention tools were not built to inspect, Security Magazine reports. Grammarly and Claude are named as examples of a category that runs to thousands.
The detail that should concern procurement teams is the update problem. An extension that clears a risk review today can change behavior after a future update, Leland writes. A one-time approval is therefore a weak control on its own. Static allow and deny lists cannot distinguish between a grammar extension helping with a personal email and the same extension reading customer records inside an ERP screen.
AI arrives through feature updates, not contracts
The volume of unsanctioned AI becomes clearer in light of research from Omdia. In surveys of 733 large-enterprise decision-makers, Omdia found nearly 80 percent are active AI adopters, mostly through upgrades to software they already own. Security vendors add AI threat analysis, business applications add scheduling optimization, inventory systems become more predictive.
That pattern explains why entry points multiply without a procurement event to trigger review. A feature update does not go through vendor risk assessment the way a new contract does. The honest inventory of AI touchpoints is probably larger than the list of AI tools anyone approved.
Desktop AI applications and coding environments represent deeper exposure. Desktop apps can access local files, clipboard contents, and sometimes the screen itself, beyond the reach of browser controls. Developer tools like GitHub Copilot and Cursor give AI direct access to codebases, including credentials, API keys, and proprietary logic. Most governance frameworks do not account for that depth of exposure.
Why it matters
The gap between AI adoption patterns and security controls creates a planning problem for 2027 budgets. CIOs now have fairly precise data showing where borrowed tools stop working. The question is whether to add standalone products for each entry point or invest in controls that follow the work across browsers, desktops, and development environments. Either path requires staff to run it, and an Enterprise Management Associates study found 52 percent of organizations now find it difficult to hire network technology experts, up from 26 percent in 2022.
Security Magazine argues the control has to sit where the employee actually interacts with the AI, with the ability to recognize corporate versus personal logins and enforce policy before content reaches the AI provider. For IT security directors evaluating browser management products this quarter, that reframes the demo around tenant recognition at the moment of the prompt, not just domain blocking.
The details in this analysis were first reported by Security Magazine, with additional survey data from Network World, InformationWeek, and CIO Dive.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call