Kiteworks Flags One-Third AI Controls as Vegas Reckoning Nears

The average organization holds roughly one-third of the AI data governance controls needed to cut risk, even as autonomous agents gain freer access to sensitive information every day. That finding from Kiteworks’ new survey lands weeks before the company takes the stage at AI Governance World in Las Vegas.

Chief Strategy Officer Tim Freestone and General Counsel Camilo Artiga-Purcell will detail the exposure when AI systems touch privileged or regulated data. Their sessions rest on hard numbers from 459 security and compliance leaders surveyed in the second quarter of 2026.

Survey Puts Maturity Near the Bottom Third

Kiteworks and Centiment collected responses from professionals at firms mostly above 1,000 employees across technology, financial services, manufacturing, healthcare and other sectors. The resulting average AI Governance Maturity Score of 35/100 sits in the Developing tier. That equates to about seven of 19 measured capabilities.

The companion Data Security Maturity Score averages 39 out of 100. Multiply the two and the Data Security and Compliance Readiness Index falls to a mean of 16.2. Half of organizations score below 12 on that combined measure.

Index Mean Score Tier Share Below 45 Advanced Tier Share
AI Governance Maturity (AIGMS) 35/100 71% 9%
Data Security Maturity (DSMS) 39/100 70% 7%
Readiness Index (DSCRI) 16.2/100 median 11.5 4% above 70

No single AI containment control exceeds 35 percent deployment. Purpose binding, which restricts agents to authorized tasks and data, reaches only 26 percent. An automated kill switch sits at 21 percent. AI-specific data-loss prevention lands at 28 percent. Human-in-the-loop review for high-risk actions is present at 30 percent.

Sixty-four percent of organizations have AI in production or on external platforms. Among them, 70 percent run three or more distinct use cases at once. Yet 50 percent cannot produce a complete AI data-access audit record within one business day. Seventy-two percent cannot trace an AI output back to its source data.

Incidents Already Match the Gaps

These are not projections. In the 12 months before the survey closed, 80 percent of respondents reported at least one security incident of any type. Sixty-four percent of those with AI deployed experienced an AI-specific incident. Sixty-three percent faced a compliance consequence such as an audit finding, remediation order, board escalation, contractual penalty or regulatory probe. Sixty-five percent discovered employees using unapproved AI tools with company data.

  • 80% experienced at least one security incident
  • 65% found shadow AI usage
  • 63% recorded a compliance consequence
  • 54% still lack a standing board agenda item on AI data governance

Crowd discussion on the platform X tracks the same pattern: autonomous agents now trade, moderate and act with little formal ownership or lifecycle process in most shops. Separate industry snapshots show workloads rising nearly 30 times in a year while AI-specific controls stay near zero in many enterprises. The gap between discovery of agents and real-time control over what they can touch remains wide.

Why Governing Data at Rest No Longer Suffices

Freestone’s core argument is simple. Static controls on stored data leave the critical window open. AI agents request, use and share information while it moves. That is where exposure concentrates.

Governing data at rest is no longer enough. Organizations must extend the same rigor to data in motion, the point where AI agents request, use, and share information, because that is where the real risk lives.

Tim Freestone, Chief Strategy Officer, Kiteworks

Artiga-Purcell’s session, titled “Your AI Passed the Bar Exam. Your Governance Didn’t,” focuses on legal exposure once models reach privileged material. Privilege, confidentiality and regulatory duties do not pause for an agent’s query. Without technical enforcement of purpose, scope and audit, the organization cannot later prove what happened.

Earlier forecast work by the same firm already flagged the pattern. In late 2025, 100 percent of surveyed organizations had agentic AI on the roadmap while fewer than 40 percent held basic containment. The 2026 survey shows the gap did not close; in several places it widened. Boards that keep AI governance off the top agenda trail by 26 to 28 points on every major control.

Who Carries the Heaviest Exposure

Sector differences matter. Financial services often show stronger general security yet lag on AI-specific layers, producing a wide readiness spread. Healthcare faces acute incident-response shortfalls even while handling protected health information. Government respondents trail furthest on purpose binding and kill-switch capability. Manufacturing cites visibility gaps across multi-tier supply chains.

Across the board the same list of missing pieces repeats:

  • No centralized AI data gateway in 60 percent of organizations in earlier cuts
  • Fragmented or missing audit trails that cannot support one-hour or even one-day reconstruction
  • Training-data provenance that 77 percent cannot trace and 78 percent cannot validate before pipelines ingest it
  • Third-party AI attestations still rare even as vendor models enter workflows

Regulators are not waiting. The EU AI Act already creates measurable separation: organizations feeling its pressure lead those that do not by 20-plus points on impact assessments, purpose binding and red-teaming. U.S. firms largely report lower pressure today, yet supply-chain and multinational effects are spreading the same requirements. Data sovereignty has expanded from storage location to processing, training and inference locations.

What Kiteworks Puts on the Table

Kiteworks positions its Private Data Network control plane as the answer for both human and agent traffic. The platform unifies send, share, receive and use of private data under one set of identity, policy, encryption and audit rules. Its AI Data Gateway and Secure MCP Server enforce attribute-based access so an agent inherits the exact permissions of the user or process that launched it. Every interaction logs for forensics and compliance packages.

The company protects more than 100 million end users and thousands of enterprises and agencies. It holds certifications spanning FedRAMP, GDPR, HIPAA, NIST 800-171 and CMMC. At the conference it will stress that technical enforcement, not policy documents alone, closes the exposure.

Freestone has repeated the theme in earlier briefings: the question is no longer whether AI will be regulated. It is whether an organization can produce the evidence package when the auditor or plaintiff arrives. Delegation chains, policy records, encryption proofs and tamper-evident logs must assemble in hours, not weeks.

Las Vegas Dates and the Broader Stage

AI Governance World runs October 12 to 14 at the Flamingo Hotel on the Las Vegas Strip. It is the sixth annual gathering hosted by the Certified Information Governance Officers Association and InfoGov World. Monday offers training and an executive forum; Tuesday and Wednesday bring full sessions, workshops, networking and an awards ceremony.

Kiteworks is listed as premier sponsor. Other named speakers and companies include voices from OpenAI, Oracle, Cisco, Google, Dentons, Foley & Lardner and multiple law and technology firms. Attendees span CIOs, chief data officers, privacy leads, legal counsel, risk officers and information-governance professionals from finance, healthcare, energy, government and manufacturing.

Rooms start at $84 a night. The program emphasizes agentic AI governance, real program case studies and practical frameworks that move from data collection through model retirement.

The same week will also surface competing surveys and vendor claims. One recent gateway study put AI-specific governance controls near zero even as traffic exploded. Another found most firms still lack formal processes for deciding what agents may access or who owns them. The common thread is that deployment outran accountability.

Controls That Separate Leaders From the Pack

The Kiteworks data isolates a small advanced cohort. Only 7 percent reach the top DSMS tier and 9 percent the top AIGMS tier. Those organizations treat governance as architecture: automated rather than manual, technical rather than behavioral, measurable rather than attested. They deploy kill switches that have been tested, purpose binding that actually blocks, SIEM-forwarded AI logs and board-level reporting that forces investment.

Four practical moves appear repeatedly among higher scorers. Close containment first so agents can be constrained or stopped. Build evidence-grade audit trails and training-data provenance because those two capabilities predict nearly every other control. Put AI data governance on the board agenda; the correlation is the strongest in the survey. Consolidate fragmented exchange channels so a single policy and log plane can cover human and agent traffic alike.

Investment intent is already turning. Forty-three percent of respondents name AI security and governance their top priority for the next 12 months. Intent alone has not closed the gap. The organizations that treat the current 35-out-of-100 score as an operational emergency rather than a future project are the ones most likely to avoid the next wave of incidents.

Freestone and Artiga-Purcell will walk conference attendees through exactly that math. The report numbers are public. The legal and operational consequences are already visible in the 80 percent incident rate. The remaining question is how many organizations will still be operating with one-third of the needed controls when the next autonomous agent reaches for data it should never see.

For deeper regulatory context, the firm’s own analysis notes that 78% cannot validate data before AI training pipelines receive it, a figure that maps directly onto emerging “right to be forgotten” and provenance duties under the EU AI Act and related regimes.

Leave a Reply

Your email address will not be published. Required fields are marked *