Logo Sharpen CISO

 

 

AI Governance in Cybersecurity: The Gap Between Perceived Risk and Reality

One number sets the scene. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 87% of cybersecurity professionals now see AI-related risk as growing fast. That’s more than phishing. More than ransomware. More than classic software flaws. And it’s exposing a widening AI governance gap inside most organizations.

Yet another number tells a different story. Only 64% of organizations assess the security of an AI tool before deploying it. That share is improving. It stood at just 37% in 2025. But it still leaves more than a third of companies exposed to tools they’ve never truly vetted.

This gap isn’t a statistical footnote. It’s the new terrain CISOs must navigate in 2026, and it’s why AI governance is becoming a board-level topic.

The nature of the risk has shifted

A year ago, the dominant fear centered on AI’s offensive capabilities. Deepfakes, auto-generated malware, hyper-personalized phishing: it was the attacker who worried people most. In 2025, 47% of leaders named these adversarial capabilities as their top generative AI concern.

In 2026, that trend has flipped. The figure has dropped to 29%. Data leaks tied to generative AI now lead instead, cited by 34% of respondents, up from 22% the year before.

In other words, the fear no longer comes only from outside. It also comes from within. An employee pasting sensitive data into a public chatbot. An AI agent connected to a critical system, unsupervised. An internal model poorly segmented. The WEF confirms it: the “AI arms race” between attackers and defenders keeps intensifying. But attention is now shifting toward the unintended exposure of data.

A booming market, an AI governance lag

Gartner’s Hype Cycle for Cyber-Risk Management 2026 adds a complementary lens, this time from the market side. The AI-security tooling sector is expected to grow from $1.5 billion in 2025 to $16.5 billion by 2030. A staggering pace, and a clear sign of shared urgency.

But Gartner also flags a blind spot: shadow AI. Generative and agentic assistants are rolling out faster than the governance frameworks meant to contain them. The result is an attack surface expanding quietly, often off the CISO’s radar.

Another telling signal: data security governance is going through what Gartner calls a “trough of disillusionment.” Organizations struggle to deploy it. The culprits are fragmented data silos and underestimated operational complexity. Technology is outpacing the processes meant to keep it in check.

This shift shows up in the budgets too. By 2030, AI-enhanced security solutions are expected to account for more than half of the entire cybersecurity market, itself projected at $353 billion. Investment is following the threat. The question is whether governance can keep the same pace.

France adds its own layer of urgency: sovereignty

This global picture takes on a distinct tone in France. The CESIN cybersecurity barometer (wave 11, January 2026) is unambiguous on this point. 63% of French companies now say they’re concerned about digital sovereignty and trusted cloud. That’s up 11 points in a single year.

This shift matters. Securing AI isn’t just about picking the right tool. It also means knowing where data is hosted, under which jurisdiction, and with what real level of control. For French and European companies, sovereignty and AI governance are becoming inseparable — and a growing number are folding sovereignty checks directly into their ISO 27001 risk assessment process.

The same barometer points to confidence that remains fragile. 67% of respondents say they’re worried about their company’s ability to face cyber risk going forward, up from 63% in the previous wave. Vigilance is rising faster than reassurance.

Geopolitics is adding to the pressure

AI isn’t the only factor complicating the picture. The WEF finds that geopolitics remains, in 2026, the top factor shaping cyber risk strategies. 64% of organizations now factor in geopolitically motivated attacks: disruption of critical infrastructure, espionage.

This climate is also eroding executive confidence. Fewer than 45% of private-sector CEOs trust their country’s ability to respond to a major cyberattack. That uncertainty feeds, once again, the growing interest in digital sovereignty.

For French companies, geopolitics and cloud sovereignty are no longer separate topics. They reinforce each other. And together they fuel the same demand: regaining control over data, and over who handles it.

Why checklists aren’t enough for AI governance

Faced with this acceleration, the instinct is to respond with more controls. More policies, more committees, more manual sign-offs. The WEF warns against exactly this trap. Too many controls create friction. Teams end up working around the rules instead of following them.

The challenge, then, isn’t stacking up constraints. Effective AI governance keeps pace with the business instead of slowing it down. That calls for three things:

  • guardrails built in by design (security-by-design), rather than bolted on afterward;
  • continuous human oversight, especially for high-impact decisions;
  • near real-time monitoring, rather than periodic, backward-looking audits.

This is exactly the philosophy behind the “AI proposes, the CISO decides” approach. Artificial intelligence speeds up detection. It prioritizes risk. It automates repetitive compliance work. But the final call stays in human hands, especially when it touches a business risk or a regulatory obligation.

The link to the EU AI Act

This governance shift isn’t happening in a regulatory vacuum. The EU AI Act already imposes obligations on AI systems classified as high-risk: technical documentation, risk management, human oversight, decision traceability.

For a CISO, there’s good news here too. The AI Act’s requirements largely overlap with ISO 27001 and NIS2. They demand the same discipline: identify risks, document controls, prove compliance over time. Treating AI as an isolated compliance track means duplicating work already under way elsewhere.

The more effective approach is folding the AI Act into the same control mapping as other frameworks. One control plan, several regulations covered. That’s also what keeps a compliance team lean, even as regulatory requirements keep piling up.

AI governance that builds on what already exists

Good news for CISOs already running an ISO 27001 or NIS2 program: there’s no need to start from scratch. AI governance fits naturally into existing GRC processes.

An information security management system (ISMS) already covers most of the groundwork. Asset mapping, risk management, access control, vendor management: these building blocks already exist. It’s simply a matter of extending them to AI tools and their data pipelines, rather than building a parallel silo.

This continuity has a direct payoff. It avoids compliance fatigue. Teams work from a single map, where ISO 27001, NIS2, DORA, and the AI Act overlap and reinforce each other.

Where to start, concretely

A few priorities stand out from the 2026 data, for any CISO looking to structure a response now:

  • Map real AI usage, including tools not officially declared by business teams (shadow AI).
  • Extend vendor risk assessments to AI solution providers, with close attention to data location.
  • Document a pre-deployment validation process, even a lightweight one. The goal: close the gap between perceived risk (87%) and actual coverage (64%).
  • Prioritize human oversight on use cases with high business or regulatory impact.
  • Reassess the cloud supply chain in light of sovereignty concerns, now a priority for two-thirds of French companies.

None of these steps require an organizational big bang. They build on GRC fundamentals most companies already apply elsewhere — the same ones covered in our GRC practices checklist.

In summary: closing the AI governance gap

AI risk is no longer just a sophisticated external threat. It also lives in the everyday, often invisible uses of generative AI at work. The 2026 data leaves little doubt: perceived risk is rising faster than the AI governance meant to contain it.

Closing that gap doesn’t mean slowing AI adoption. It means applying the same rigor already used for information security. Mapping, risk assessment, continuous oversight. And a human decision that keeps the final word.

Want to assess how mature your organization’s AI governance really is? Talk to us about your specific context.


Sources cited: World Economic Forum; Gartner ; CESIN.

While many organizations were still waiting for France’s transposition of NIS2, ANSSI published the ReCyF — Référentiel Cyber France (v2.5) in March 2026. This working document is now the regulatory backbone of what’s coming, well before the formal decree lands.

Here’s what you actually need to understand.

1. This is no longer an IT topic — it’s a leadership topic

The ReCyF is explicit about this: digital security governance now falls under the personal responsibility of the executive in charge. They approve the security policy. They answer for any gaps.

Concretely, that governance framework has to include four things: a defined organization, clear roles and responsibilities for digital security, a process for managing compliance, and a formal information security policy (PSSI). That PSSI isn’t a one-off document, either. Your organization has to review it at least once a year, and it must cover, at minimum, encryption use, physical and logical access control, and the review of security measures already in place.

Cybersecurity has moved up to the executive committee. This time, it’s staying there.

2. Are you an “Entité Importante” (EI) or an “Entité Essentielle” (EE)?

This isn’t just a vocabulary question. The first 15 security objectives apply to both categories equally. Objectives 16 through 20 — formal risk analysis, information system audits, dedicated administration, and security supervision — apply only to EEs.

There’s another distinction worth knowing: only essential entities (EE) must designate a named point of contact for ANSSI, responsible for security incidents and all related communications. Important entities (EI) face no such obligation. In short, your EI/EE status doesn’t just affect your paperwork — it directly determines your compliance workload.

3. The structure of the obligations: What vs. How

The ReCyF separates two levels, and the distinction matters:

  • Security objectives: mandatory. They define what you must achieve.
  • Acceptable means of compliance: recommended by ANSSI, not mandatory on their own. They define how you can demonstrate that achievement during a control.

Among those means, a valid ISO 27001:2022 certification can demonstrate several objectives at once — governance chief among them. But it only counts for the systems actually covered by the certification’s scope. A certification that covers one business unit doesn’t automatically cover the rest of the organization.

4. The 4 concrete pillars to address

The framework rests on four clear pillars:

  • Governance: mapping your information systems, defining your security policy, and controlling your supplier ecosystem.
  • Protection: physical access, architecture, identity management, encryption.
  • Defense: detecting and responding to incidents.
  • Resilience: business continuity and disaster recovery plans, crisis management, and regular exercises.

Each pillar maps to a specific set of the ReCyF’s 20 security objectives, and each objective ties back to an article of the NIS2 directive itself. Nothing here is arbitrary — it’s European law translated into operational requirements.

What this actually changes

Many organizations assumed they could wait. The ReCyF closes that option. It sets a precise framework, with requirements that differ by EI/EE status, ANSSI controls that can happen at any time, and named accountability for the executive in charge.

The question is no longer “do we need to comply?” It’s “where do we start?”

Evaluate your maturity in 15 minutes

Want to assess your maturity against the ReCyF ahead of NIS2? SharpenCISO automates multi-framework pre-audits. You get your report and a preliminary action plan in 15 minutes, not weeks.

🌐 www.sharpenciso.com ✉️ contact@sharpenciso.com

#SharpenCISO #GRC #Cybersecurity #Founders #CISO #RSSI #NIS2 #DORA #ISO27001 #NIST #Compliance #SecurityByDesign