Sharpen CISO Logo

AI Cyber Risk Management: Why Your GRC Program Must Evolve

AI spending is about to explode, and most programs aren’t ready for what that means for AI cyber risk management. Your governance model may not survive the pace.

Gartner forecasts AI spending will grow 44% in 2026 alone. By 2029, total AI spending across infrastructure, products, and services will reach $4.7 trillion. Yet, only 15% of organizations report having comprehensive AI governance in place.

That gap is the real risk. Specifically, it’s a governance problem before it’s a technology problem. This article breaks down why, and what Gartner recommends CISOs and security leaders do about it.

The Fragmentation Trap in AI Risk Governance

Here’s the common mistake. As AI adoption accelerates, many security teams respond by building something new. Specifically, they create separate policies, workflows, and tools just for AI risk.

At first, it feels logical. In practice, though, it backfires.

Because these frameworks run in parallel, they fragment cyber-risk management before it even starts. As a result, they slow down risk-informed decisions. Worse, they make it harder for executives to compare AI risks against everything else on the risk register.

So, Gartner’s guidance is clear. Don’t build a second system for AI. Instead, evolve the one you already have.

This mirrors a governance gap boards are already facing elsewhere. The World Economic Forum’s Global Cybersecurity Outlook 2026 found a similar pattern in supply chain oversight: fragmented visibility, not a lack of tools, is usually the real problem.

Six Ways to Evolve AI Cyber Risk Management

Gartner outlines six specific actions across methodology, people, and technology. Together, they keep AI risk inside your existing governance structure, rather than bolted on beside it.

1. Drive AI cyber-risk accountability. Security teams often become the default owner of every AI-related risk. That’s a problem, since business units that deploy AI tools need to own the risks those tools introduce.

In practice, this means updating your cybersecurity charter. It also means requiring business sponsors to formally acknowledge and accept AI risk before deployment, not after.

2. Keep a unified cyber-risk register. Resist the urge to build a separate register for AI risks. Instead, evaluate AI threats with the same methodology you use for everything else.

Why does this matter? Because a single register forces consistent prioritization across the board. As a result, it stops AI from becoming its own isolated conversation, disconnected from broader risk decisions.

3. Adopt a threat-informed approach. Traditional risk registers often list compliance gaps and isolated vulnerabilities. That approach, however, doesn’t scale well against AI-specific threats like prompt injection or model data leakage.

Instead, ground your risk assessments in real adversary behavior. For example, draft AI-specific scenarios, but score them using the same criteria as every other cyber risk.

4. Normalize AI governance in existing policies. Avoid writing a brand-new “AI policy” for every situation. Instead, most AI risks fit naturally into policies you already maintain, like identity and access management.

Create new, AI-specific standards only when nothing existing applies. For instance, model integrity validation is a good example of a case that may need one.

5. Upskill for AI security. You likely don’t need new job titles. Instead, your current GRC professionals are already well-positioned to manage AI risk, with the right training.

So, invest in upskilling. First, partner with HR to fund AI security certifications. Then, add AI-generated attack scenarios to your existing tabletop exercises.

6. Use technology to strengthen, not fragment, your program. New tools supporting AI governance can add real value. However, adding more disconnected tools won’t automatically fix anything.

Before buying something new, therefore, understand what your existing platforms already do. In short, consolidation, not proliferation, is the goal.

Why AI Cyber Risk Management Matters Now

Some 302 cybersecurity leaders were surveyed for Gartner’s 2025 AI Risk Management research. The result was telling: most said their organizations need significant, if not comprehensive, changes to manage emerging AI cybersecurity risks.

Clearly, that’s not a distant problem for AI cyber risk management. Rather, it’s happening right now, as generative AI tools, custom AI applications, and embedded AI features move into production.

Still, technology alone won’t close this gap. That’s because cyber-risk management depends on expert human judgment. Instead, what AI does is help teams process more signals, faster, so people can focus on the decisions that matter most.

For a look at how this plays out for smaller organizations specifically, see how AI is reshaping cyber risk for growing businesses.

The Bottom Line on AI Cyber Risk Management

AI isn’t a side project anymore. Rather, it’s woven into how organizations already operate.

Because of that, your cyber GRC program can’t treat AI as an exception. Instead, it needs to absorb AI risk into the same structure, register, and accountability model you already trust.

So, organizations that evolve their existing governance, rather than duplicate it, will scale far more effectively. In an AI-driven environment, that’s not just good practice. In fact, it’s the only practice that keeps pace.

Source: Gartner, “Cyber GRC Practices Must Evolve to Manage AI Risk,” 27 April 2026 (ID G00846514).

The DORA Register of Information: A Practical Guide

If your organization is a financial entity operating in the EU, the DORA register of information isn’t optional paperwork. It’s a legal requirement, and it’s already in force. The Digital Operational Resilience Act, or DORA, became applicable on 17 January 2025. From that date, in-scope firms need a complete, current register of every contractual arrangement they hold with ICT third-party service providers.

That sounds simple on paper. In practice, it’s turned out to be one of the more demanding reporting obligations financial entities have faced in years. The European Banking Authority, or EBA, ran a dry run exercise in 2024 specifically to catch problems before official reporting began. Even so, the issues it found were still showing up in testing well into 2025.

This post walks through what the DORA register of information actually requires. It covers why regulators built it this way, and what the EBA’s own data quality findings suggest your team should double-check before filing.

What Is the DORA Register of Information?

The DORA register of information is a structured inventory of a financial entity’s ICT third-party relationships. It has to be maintained at three levels: entity, sub-consolidated, and consolidated. A standalone firm reports differently than a banking group with multiple subsidiaries. Either way, both need the register ready and accurate.

This isn’t a one-time filing, either. Financial entities must keep the register current on an ongoing basis. From there, they submit it to their competent authority on request. That competent authority then passes the collected registers up to the European Supervisory Authorities, known as the ESAs, for further use.

Scope matters here too. DORA applies broadly across the EU financial sector. It covers banks, insurers, and investment firms. Payment institutions and a long list of other regulated entities fall under it as well. If your organization falls under DORA at all, the register of information obligation almost certainly applies to you.

Why the DORA Register of Information Exists

Regulators didn’t build this reporting requirement just to generate paperwork. Instead, the DORA register of information serves three distinct purposes. Each one shapes what the data actually needs to look like.

First, it lets financial entities monitor their own ICT third-party risk. A complete register makes concentration risk visible. Say five critical business functions all depend on the same cloud provider. That pattern shows up clearly in the data, instead of staying hidden across five separate contract files.

Second, it gives EU competent authorities a supervisory tool. Regulators can review how firms manage ICT and third-party risk without waiting for an incident to surface the gaps.

Third, and perhaps most consequentially, the ESAs use the aggregated registers to designate critical ICT third-party providers. These are often shortened to CTPPs. Once a provider earns that designation, it becomes subject to direct EU-level oversight. In other words, the register of information isn’t just about your firm’s own compliance. It’s also the mechanism that identifies which cloud and tech vendors are systemically important to the entire European financial sector.

What the 2024 Dry Run Revealed

Before official reporting began, the ESAs ran a dry run exercise throughout 2024. Financial entities across the EU submitted test registers as part of it. That gave regulators, and the firms themselves, a chance to find problems before the requirement carried real legal weight.

The dry run wasn’t a minor pilot, either. It included industry workshops, a dedicated reporting template, and a draft taxonomy. It also came with its own data quality checks. The EBA published a summary report afterward, along with a factsheet explaining what the exercise was meant to accomplish.

That preparation mattered, because it surfaced structural issues early. Following the 2024 exercise, the EBA published observations from testing official RoI submissions. The findings described key common issues identified across the industry. In practice, this means firms weren’t just getting individual data points wrong. They were running into recurring, systemic problems with how they structured and validated their registers in the first place.

The Technical Side of the DORA Register of Information

Filing the DORA register of information isn’t a matter of filling in a spreadsheet freely. Instead, the reporting format is tightly specified through a formal technical package.

At the center sits the Implementing Technical Standards, or ITS, on the register of information. These were adopted and published in the EU’s Official Journal. From there, the EBA maintains a full Data Model. That includes a Data Point Model dictionary and an annotated table layout defining every field a firm might need to populate.

Submissions ultimately need to conform to a taxonomy built on XBRL-CSV architecture. Sample files and a full taxonomy package are both available for firms to test against before filing for real. On top of that, the EBA publishes validation rules. It also provides a detailed overview of the technical and business checks it applies to every submission. There’s even a plain CSV reporting package for firms that want a simpler path than full XBRL tooling, along with a conversion tool to move between formats.

This level of technical specification exists for a reason. Registers arrive from hundreds of financial entities, spread across different countries and different internal systems. All of that still has to aggregate into one consistent dataset the ESAs can actually analyze.

Common Pitfalls in DORA Register of Information Reporting

Given how technical the format is, it’s no surprise that data quality has been a recurring theme. The EBA has published explanatory material on the data quality feedback firms receive from validation checks. It also shares sample data quality responses, so firms can see what an actual error report looks like before they get one of their own.

A few patterns stand out from that material. Firms sometimes struggle with correctly categorizing licensed activities, which draws on a dedicated annex listing possible values. Others run into trouble with how sub-consolidated and consolidated registers relate to each other. Group-level reporting introduces dependencies that a single-entity register simply doesn’t have to handle.

The EBA also maintains a running FAQ on register of information reporting, updated as new questions surface. That FAQ is worth treating as a living document rather than a one-time read. It reflects issues the EBA is actually seeing in submitted data, not hypothetical edge cases.

How to Prepare for DORA Register of Information Reporting

If your organization hasn’t yet built a repeatable process for this, a few priorities make the biggest difference.

Start by mapping every ICT third-party contract your organization holds, not just the obvious cloud vendors. DORA’s definition of ICT third-party services is broad. Gaps in your contract inventory become gaps in your register, and those gaps are exactly what supervisors are trained to look for. Next, assign clear ownership for keeping that inventory current. The register isn’t a point-in-time exercise. Contracts change and vendors get replaced, so the register needs to reflect that in near real time.

From there, test early against the EBA’s published validation rules. Don’t wait until a filing deadline to discover a formatting issue you could have caught months earlier. The dry run exercise and the subsequent common-issues report both exist specifically so firms can learn from other people’s mistakes instead of their own. Finally, if your organization already runs other EU compliance programs, look for overlap. The vendor risk assessment work behind ISO 27001 or NIS2 compliance often maps closely onto the third-party data DORA now requires, just in a more structured, reportable format.

The Takeaway

The DORA register of information has moved past the planning stage. It’s a live, binding obligation now, backed by a detailed technical reporting package and a body of real-world data quality findings from the EBA’s own testing. The firms handling it well aren’t the ones treating it as an annual scramble. They’re the ones maintaining an accurate, continuously updated inventory of ICT third-party relationships, validated against the EBA’s published rules well before any filing deadline arrives.

If you haven’t tested your register against the EBA’s validation rules yet, that’s the most useful next step. Everything else in this process builds outward from having that data structured correctly from the start.

For related reading, see your Cyber Resilience Act compliance guide, your NIS2 requirements overview, and your ISO 27001 documentation checklist.


Sources: European Banking Authority — Preparations for reporting of DORA registers of information

 

Supply Chain Cyber Risk: What Boards Must Know in 2026

One weak vendor can now shut down an entire company. That’s not a warning anymore. It’s already happened, more than once.

The World Economic Forum’s Global Cybersecurity Outlook 2026 confirms it. Supply chain risk has become the single biggest cybersecurity challenge for large organizations. For boards, this is no longer a topic to delegate. It’s a governance issue.

This article explains why the risk has grown so fast. It also outlines what directors and executives should be asking their teams right now.

The Numbers Behind the Shift

According to the report, 65% of large companies now name supply chain vulnerabilities as their greatest barrier to cyber resilience. That’s up sharply from 54% just a year earlier.

Why the jump? Because today’s digital supply chains are deeply interconnected. A breach at one supplier can cascade through an entire ecosystem. It can hit production, operations, and even other customers, all at once.

Clearly, this isn’t a hypothetical risk. In fact, it’s already playing out in boardrooms around the world.

Real Incidents, Real Costs

Consider Jaguar Land Rover. In 2025, a single cyberattack halted production for five weeks. In fact, the attack disrupted more than 5,000 suppliers at once.

The direct financial impact was severe: £196 million in cyber-related costs, and a nearly 25% drop in quarterly revenue. The wider UK economy absorbed an estimated £1.9 billion in losses. The government even stepped in with a £1.5 billion loan guarantee to stabilize the supply chain.

Or take Asahi, the Japanese beverage maker. A cyberattack in late 2025 knocked out core IT systems. As a result, staff had to revert to pen and paper just to track inventory.

Similarly, in Europe, a relatively small breach at an airport check-in vendor caused widespread flight delays and cancellations. The technical fix was simple. Still, the business disruption was not.

Together, these cases send a clear message to leadership. A vendor’s weakness quickly becomes your company’s crisis.

Why Trust in Vendors Is Breaking Down

At the heart of this problem is a simple, uncomfortable truth. Most companies can’t fully verify the security of the vendors they depend on.

The WEF report calls this “inheritance risk.” In plain terms, it means inheriting a vendor’s vulnerabilities without knowing they exist. It now ranks as the top supply chain concern in the survey.

Close behind is a lack of visibility. Many organizations simply don’t have a clear map of their extended supply chain. As a result, they can’t manage risks they can’t see.

Finally, there’s concentration risk. Businesses increasingly depend on a small number of critical providers, like major cloud platforms. So, if one of those providers fails, the damage can spread across thousands of companies overnight.

What the Most Resilient Companies Do Differently

The report draws a clear line between resilient organizations and the rest. The difference comes down to specific, board-visible practices.

Highly resilient companies involve their security teams in procurement decisions 76% of the time. Less resilient companies do this only 53% of the time. In other words, security earns a seat at the table before you sign contracts, not after a breach.

Similarly, 74% of resilient companies formally assess their suppliers’ security maturity. Only 48% of less resilient companies do the same.

Resilient companies also rehearse for failure. As a result, 44% run joint incident simulations with their supply chain partners, compared to just 16% of less resilient peers. That preparation pays off: only 15% of highly resilient companies report weak incident response planning, versus 37% of the rest.

The Board’s Role Is No Longer Optional

Board engagement now separates resilient companies from vulnerable ones. The data on this point is striking.

Among highly resilient organizations, 99% report active board involvement in cybersecurity. Just over half receive regular updates on cyber risks. Nearly half say their board has a clearly defined oversight role.

By contrast, boards at less resilient companies disengage far more often. That gap in oversight directly tracks the gap in outcomes.

For directors, the takeaway is simple. Cybersecurity oversight isn’t a technical checkbox. Instead, it’s a core part of enterprise risk management, alongside financial and operational risk.

Questions Every Board Should Be Asking

Given all this, what should leadership actually do? A few focused questions can drive real change.

First, ask how security teams take part in vendor selection. If procurement moves forward without a security review, that’s a governance gap worth closing.

Second, ask for a map of critical dependencies. Specifically, leadership should know which vendors, if breached, would cause the most damage.

Third, ask whether the company has tested its response with key partners. Because a plan nobody has rehearsed often fails when it matters most.

Finally, ask how the company manages concentration risk. After all, relying on a single critical provider, without a backup plan, is a strategic vulnerability, not just a technical one.

The Bottom Line

Supply chain risk has moved from the server room to the boardroom. The WEF’s 2026 findings make that shift impossible to ignore.

However, the path forward is well defined. Companies that involve security early, map their dependencies, and rehearse their response are measurably more resilient.

For boards, the message is direct. Ask the hard questions now, before a vendor’s weakness becomes your headline.

Source: World Economic Forum, Global Cybersecurity Outlook 2026, January 2026.

Small Business Cybersecurity: The Warning Signs in WEF’s 2025 Report

Cybercrime is no longer a big-company problem. In fact, small and mid-sized businesses are now the weakest link in the chain.

That’s the clear message from the World Economic Forum’s Global Cybersecurity Outlook 2025. The report surveyed hundreds of business and security leaders worldwide. Its findings paint a worrying picture for smaller businesses.

This article breaks down what the report found. It also explains what small business owners and managers can do about it, starting today.

The Gap Between Small and Large Businesses Is Widening

According to the WEF report, 35% of small businesses now say their cyber defenses fall short. That figure has grown sevenfold since 2022, when it stood at just 5%.

Large companies, meanwhile, are moving the other way. By comparison, only 7% of large companies now report weak defenses, down from 13% a few years ago.

In other words, big companies are getting stronger. Small companies are falling further behind. And because supply chains link small vendors to large enterprises, this gap puts everyone at risk.

The report is blunt about it. At the WEF’s 2024 Annual Meeting on Cybersecurity, 71% of cyber leaders agreed on one point. Small businesses, they said, have already reached a tipping point. Many can no longer defend themselves against today’s threats.

Why Smaller Companies Struggle to Keep Up

Several factors explain this widening gap. Understanding them is the first step toward closing it.

A shortage of skilled people. The report identifies a global shortfall of 2.8 million to 4.8 million cybersecurity workers. Small businesses feel this shortage the hardest. That’s because they rarely compete with large firms on salary or perks.

Only 14% of businesses say they have the talent they need. For small businesses, the skills gap ranks second on their list of barriers. Only the sheer complexity of today’s threats ranks higher.

Limited budgets and resources. Larger companies can afford dedicated security teams, advanced tools, and outside consultants. Smaller businesses typically can’t. That means fewer defenses are in place when an attack happens.

Growing complexity everywhere. World tensions, new rules, and fast-moving tech are all adding pressure. Nearly 60% of businesses say world tensions have already reshaped their security plans. Small teams simply have less time to track every new development.

The Threats Small Businesses Should Watch Closely

In practice, not every cyberthreat affects every business equally. The WEF report highlights a few that matter most right now.

Ransomware still tops the list. Across all business sizes, 45% of respondents rank ransomware as their top cyber risk. Attackers increasingly rent out ransomware tools to less skilled criminals. As a result, there are more attackers, more often.

Fraud and phishing are close behind. Roughly one in five respondents named cyber-enabled fraud, including phishing and fake payment requests, as their top worry. These attacks often target smaller businesses. Why? Because staff may not get the same security training larger firms provide.

AI-made deepfakes are an emerging risk. Criminals now use generative AI to convincingly fake the voice and video of executives. In fact, research cited in the report found a 223% jump in deepfake tools traded on the dark web. That happened within a single year. More than half of surveyed security leaders now see deepfakes as a real threat.

Third-party and supply chain risk is real, even if it doesn’t feel that way. Large companies rank supply chain risk as their top concern. That’s largely because they depend on smaller vendors like you. If your systems get compromised, the damage can spread to every partner you work with.

What Small Businesses Can Do Right Now

Still, the report isn’t just a warning. It also points to practical steps that make a measurable difference, even without a large security budget.

First, invest in your people. The WEF report found that 76% of businesses are closing the skills gap by training current staff. Fewer rely only on hiring new specialists. So, basic security training for your whole team, not just IT staff, goes a long way toward preventing phishing and fraud.

Second, get leadership involved. The report found that 62% of highly resilient businesses give leaders regular updates on cyber risks. Only 29% of less resilient businesses do the same. In short, cybersecurity works best as a business priority, not just a technical one.

Third, prepare for ransomware directly. Because it remains the top risk, don’t leave it to chance. Keep offline backups. Test your response plan. And make sure everyone knows their role during an attack.

Fourth, verify unusual requests. AI-made deepfakes and impersonation scams are rising fast. So, train employees to double-check unusual payment requests or executive instructions. A quick phone call before acting can stop a scam cold.

Finally, ask questions of your vendors and partners. If you supply larger companies, for example, expect them to ask about your security practices. Getting ahead of those questions builds trust and protects your business relationships.

The Bottom Line

The WEF’s 2025 report makes one thing clear. Strong cyber defenses are no longer optional for small businesses. The gap between large and small companies is real, and it’s growing.

However, the report also shows that real progress doesn’t need a big budget. Training your team, involving leadership, and preparing for common threats can go a long way.

Cybersecurity may feel like a big-company problem. But as this year’s report shows, small businesses can no longer afford to think that way.

Source: World Economic Forum, Global Cybersecurity Outlook 2025, January 2025.

Is cyber risk data reliable enough for executive committee decisions?

Cyber risk now sits on nearly every board agenda. But does the data behind those conversations actually reflect what’s happening inside the information system? That’s the question every CISO eventually has to answer in front of their ExCo or board.

Three figures from the latest OpinionWay barometer for CESIN caught our attention:

  • 92% of companies rank cyber risk among their top 5 business risks.
  • 29% review it only once a year, at ExCo or board level.
  • 61% review it several times a year, at the same level.

So cyber risk has clearly become a strategic business risk, not just a technical one. And that status comes with a consequence: CISOs are now expected to support real strategic decisions in the boardroom, not just report on past incidents.

Cyber risk earned its seat at the table — the data hasn’t caught up

Financial data reaching the board goes through audits, standardized formats, and controls built over decades. Cyber risk data, in most organizations, still doesn’t.

This gap isn’t just a reporting habit. It shows up in the decisions that follow, too. For the first time in three years, the share of French companies allocating 5% or more of their IT budget to security actually fell in 2025, down from 48% to 42% (CESIN, 2026). When the data behind that decision is a stale snapshot, the budget that follows gets calibrated on old information — not on the risk as it stands today.

A question that keeps coming up with CISOs

Here’s what we keep hearing in our conversations with CISOs: does data consolidated at a few key moments in the year actually reflect the operational reality of the information system? And is that data reliable enough to inform a CISO’s strategic decisions at ExCo or board level?

In many organizations, teams still pull that data together manually, from scattered tools, just before the meeting. By the time it reaches the board, it’s already a snapshot of where things stood weeks earlier — not where they stand today.

At SharpenCISO, we’re convinced the real issue isn’t measuring more often. It’s building on more reliable data in the first place. Reporting frequency without data quality just means reporting the wrong picture, more often.

What “reliable” actually means here

Reliable doesn’t just mean accurate at the moment of collection. It means current when it reaches the decision-maker.

Take third-party risk as an example. Only 23% of French companies monitor their attack surface continuously — most still rely on a contract clause, reviewed once and rarely revisited. That’s a governance choice as much as a technical one, and it’s exactly the kind of gap that a single point-in-time report can hide.

The same shift is already happening elsewhere in security. The share of organizations that assess their AI tools before deployment nearly doubled in a year, from 37% to 64% (WEF, 2026). Continuous verification is becoming the norm for AI risk. Cyber GRC reporting for the board needs to make the same move — from a periodic snapshot to a live picture.

So, what’s your confidence level?

We’re curious: how much confidence does your organization place in its cyber GRC data when it’s time to make a decision at ExCo or board level?

CISOs, does the data you present match what’s really happening on the ground? And board members, do you feel you’re deciding on today’s risk, or on last quarter’s? Tell us in the comments — we’d like to hear how this looks from where you sit.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

Cybersecurity is becoming a governance issue. It’s now a matter of resilience and risk control, not just technical defense. The latest OpinionWay barometer for CESIN confirms this shift: three regulatory frameworks now dominate corporate priorities in France.

Overall, 59% of French companies say they’re in scope for NIS2, 32% for DORA, and 30% for the CRA (CESIN, 2026). But those averages hide a sharp divide by company size. That divide is where the real story is.

1. NIS2: the new center of gravity

70% of large enterprises rank NIS2 as a top priority. Among small and mid-sized businesses (TPE/PME), that figure drops to just 44%.

The gap makes sense. Large groups already went through NIS1, so they know the drill: risk management, incident notification, board-level accountability. Smaller structures, on the other hand, are still discovering the real scope of the requirements — including obligations that reach into their supply chain, not just their own systems.

2. DORA: operational resilience at the heart of finance

DORA remains a strong priority for large enterprises, at 38%. That number reflects its scope: financial institutions and their critical ICT providers.

Resilience testing, third-party risk management, governance: DORA demands a rigorous discipline. And because it reaches ICT providers as well as financial firms directly, its impact spreads well beyond the finance sector itself.

3. The CRA: securing products by design

With the CRA, the logic shifts. Security has to be built in from the start, not bolted on later. That’s the core of Secure by Design and Secure by Default.

Large enterprises are ahead here too: 37% are already anticipating the CRA, compared to just 23% of mid-sized companies (ETI). That 14-point gap matters, because the CRA’s core requirements — software bills of materials (SBOM) and patch management — take real time to operationalize. Waiting until the deadline isn’t really an option.

What sets the top-performing organizations apart

We’re convinced the organizations that progress fastest will share three habits:

  • They pool controls and reference frameworks across regulations, instead of running separate compliance programs for NIS2, DORA, and the CRA side by side.
  • They prioritize action by actual risk level, not by how easy it is to produce evidence. The easiest compliance box to tick isn’t always the risk that matters most.
  • They give cyber GRC teams the tools to industrialize assessments, produce reliable evidence, and manage several regulations at once — without multiplying the effort every time.

This isn’t a small opportunity. As we discussed in an earlier post, 76% of CISOs already say that managing multiple frameworks in parallel hurts their ability to stay compliant. Convergence isn’t a nice-to-have; it’s how compliance stays sustainable.

Turning compliance into a lever, not an obligation

That’s precisely the approach we’re building with SharpenCISO, our AI-native GRC platform, automated in real time.

Our goal is simple: turn compliance into a genuine lever for managing cyber risk — one that durably strengthens security posture — instead of a string of regulatory obligations to tick off, one framework at a time.

So, what have you put in place?

We’re curious: what have you put in place to improve the performance and impact of your cyber GRC teams?

Are you still running NIS2, DORA, and the CRA as separate tracks, or have you already started pooling the effort? Let us know in the comments.

#SharpenCISO #CISO #RSSI #GRC #Cybersecurity #ISO27001 #ISO27005 #EBIOS #NIS2 #DORA #NIST #Compliance #SecurityByDesign #CRA

 

 

AI Governance in Cybersecurity: The Gap Between Perceived Risk and Reality

One number sets the scene. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 87% of cybersecurity professionals now see AI-related risk as growing fast. That’s more than phishing. More than ransomware. More than classic software flaws. And it’s exposing a widening AI governance gap inside most organizations.

Yet another number tells a different story. Only 64% of organizations assess the security of an AI tool before deploying it. That share is improving. It stood at just 37% in 2025. But it still leaves more than a third of companies exposed to tools they’ve never truly vetted.

This gap isn’t a statistical footnote. It’s the new terrain CISOs must navigate in 2026, and it’s why AI governance is becoming a board-level topic.

The nature of the risk has shifted

A year ago, the dominant fear centered on AI’s offensive capabilities. Deepfakes, auto-generated malware, hyper-personalized phishing: it was the attacker who worried people most. In 2025, 47% of leaders named these adversarial capabilities as their top generative AI concern.

In 2026, that trend has flipped. The figure has dropped to 29%. Data leaks tied to generative AI now lead instead, cited by 34% of respondents, up from 22% the year before.

In other words, the fear no longer comes only from outside. It also comes from within. An employee pasting sensitive data into a public chatbot. An AI agent connected to a critical system, unsupervised. An internal model poorly segmented. The WEF confirms it: the “AI arms race” between attackers and defenders keeps intensifying. But attention is now shifting toward the unintended exposure of data.

A booming market, an AI governance lag

Gartner’s Hype Cycle for Cyber-Risk Management 2026 adds a complementary lens, this time from the market side. The AI-security tooling sector is expected to grow from $1.5 billion in 2025 to $16.5 billion by 2030. A staggering pace, and a clear sign of shared urgency.

But Gartner also flags a blind spot: shadow AI. Generative and agentic assistants are rolling out faster than the governance frameworks meant to contain them. The result is an attack surface expanding quietly, often off the CISO’s radar.

Another telling signal: data security governance is going through what Gartner calls a “trough of disillusionment.” Organizations struggle to deploy it. The culprits are fragmented data silos and underestimated operational complexity. Technology is outpacing the processes meant to keep it in check.

This shift shows up in the budgets too. By 2030, AI-enhanced security solutions are expected to account for more than half of the entire cybersecurity market, itself projected at $353 billion. Investment is following the threat. The question is whether governance can keep the same pace.

France adds its own layer of urgency: sovereignty

This global picture takes on a distinct tone in France. The CESIN cybersecurity barometer (wave 11, January 2026) is unambiguous on this point. 63% of French companies now say they’re concerned about digital sovereignty and trusted cloud. That’s up 11 points in a single year.

This shift matters. Securing AI isn’t just about picking the right tool. It also means knowing where data is hosted, under which jurisdiction, and with what real level of control. For French and European companies, sovereignty and AI governance are becoming inseparable — and a growing number are folding sovereignty checks directly into their ISO 27001 risk assessment process.

The same barometer points to confidence that remains fragile. 67% of respondents say they’re worried about their company’s ability to face cyber risk going forward, up from 63% in the previous wave. Vigilance is rising faster than reassurance.

Geopolitics is adding to the pressure

AI isn’t the only factor complicating the picture. The WEF finds that geopolitics remains, in 2026, the top factor shaping cyber risk strategies. 64% of organizations now factor in geopolitically motivated attacks: disruption of critical infrastructure, espionage.

This climate is also eroding executive confidence. Fewer than 45% of private-sector CEOs trust their country’s ability to respond to a major cyberattack. That uncertainty feeds, once again, the growing interest in digital sovereignty.

For French companies, geopolitics and cloud sovereignty are no longer separate topics. They reinforce each other. And together they fuel the same demand: regaining control over data, and over who handles it.

Why checklists aren’t enough for AI governance

Faced with this acceleration, the instinct is to respond with more controls. More policies, more committees, more manual sign-offs. The WEF warns against exactly this trap. Too many controls create friction. Teams end up working around the rules instead of following them.

The challenge, then, isn’t stacking up constraints. Effective AI governance keeps pace with the business instead of slowing it down. That calls for three things:

  • guardrails built in by design (security-by-design), rather than bolted on afterward;
  • continuous human oversight, especially for high-impact decisions;
  • near real-time monitoring, rather than periodic, backward-looking audits.

This is exactly the philosophy behind the “AI proposes, the CISO decides” approach. Artificial intelligence speeds up detection. It prioritizes risk. It automates repetitive compliance work. But the final call stays in human hands, especially when it touches a business risk or a regulatory obligation.

The link to the EU AI Act

This governance shift isn’t happening in a regulatory vacuum. The EU AI Act already imposes obligations on AI systems classified as high-risk: technical documentation, risk management, human oversight, decision traceability.

For a CISO, there’s good news here too. The AI Act’s requirements largely overlap with ISO 27001 and NIS2. They demand the same discipline: identify risks, document controls, prove compliance over time. Treating AI as an isolated compliance track means duplicating work already under way elsewhere.

The more effective approach is folding the AI Act into the same control mapping as other frameworks. One control plan, several regulations covered. That’s also what keeps a compliance team lean, even as regulatory requirements keep piling up.

AI governance that builds on what already exists

Good news for CISOs already running an ISO 27001 or NIS2 program: there’s no need to start from scratch. AI governance fits naturally into existing GRC processes.

An information security management system (ISMS) already covers most of the groundwork. Asset mapping, risk management, access control, vendor management: these building blocks already exist. It’s simply a matter of extending them to AI tools and their data pipelines, rather than building a parallel silo.

This continuity has a direct payoff. It avoids compliance fatigue. Teams work from a single map, where ISO 27001, NIS2, DORA, and the AI Act overlap and reinforce each other.

Where to start, concretely

A few priorities stand out from the 2026 data, for any CISO looking to structure a response now:

  • Map real AI usage, including tools not officially declared by business teams (shadow AI).
  • Extend vendor risk assessments to AI solution providers, with close attention to data location.
  • Document a pre-deployment validation process, even a lightweight one. The goal: close the gap between perceived risk (87%) and actual coverage (64%).
  • Prioritize human oversight on use cases with high business or regulatory impact.
  • Reassess the cloud supply chain in light of sovereignty concerns, now a priority for two-thirds of French companies.

None of these steps require an organizational big bang. They build on GRC fundamentals most companies already apply elsewhere — the same ones covered in our GRC practices checklist.

In summary: closing the AI governance gap

AI risk is no longer just a sophisticated external threat. It also lives in the everyday, often invisible uses of generative AI at work. The 2026 data leaves little doubt: perceived risk is rising faster than the AI governance meant to contain it.

Closing that gap doesn’t mean slowing AI adoption. It means applying the same rigor already used for information security. Mapping, risk assessment, continuous oversight. And a human decision that keeps the final word.

Want to assess how mature your organization’s AI governance really is? Talk to us about your specific context.


Sources cited: World Economic Forum; Gartner ; CESIN.