If you asked 100 enterprise CISOs how confident they are in their AI security and then asked them to report to their CEO tomorrow, what would they say?

Pentera asked exactly this question across 300 US enterprises. The answer is striking in its honesty. Zero percent said they have no concern — AI security is universally recognized as a real issue. Just 1% described themselves as very confident and well-prepared. 21% expressed low confidence, citing gaps in their current defensive capabilities. The remaining 78% landed on "somewhat confident" — the qualifier being that while steps are being taken, gaps remain.

In other words: every CISO knows AI security is a problem. Almost none of them feel fully prepared for it. And the gap between knowing and being prepared is where the real story lives.

What's Driving the Confidence Gap

The survey asked CISOs directly what their biggest barriers to securing their AI ecosystem are. The answers reframe the problem in a way that most security conversations miss.

Lack of internal expertise was cited by 50% of CISOs as their primary barrier — the single largest response. Limited visibility into AI usage across the organization followed at 48%. The absence of dedicated AI security tools came in at 36%. Budget constraints, the factor most people assume is the binding constraint, was cited by only 17%.

This is a significant finding. The AI security gap is not primarily a resource problem. It is a knowledge and visibility problem. Organizations have the budget. They do not have the expertise to apply it effectively, or the visibility to know what they are trying to protect.

50%
cite lack of internal expertise as their #1 barrier to AI security
17%
cite budget as a primary barrier — far less than expertise or visibility
67%
of CISOs have limited visibility into how AI is operating across their environment

The Shadow AI Problem

The visibility finding deserves its own attention. No CISO in the survey reported full visibility into their AI systems without any Shadow AI present. 67% reported limited visibility. 33% reported good visibility but still expected some level of unmanaged or unauthorized AI activity in their environment. 1% admitted to having no visibility at all.

This means that every enterprise in the survey is operating with some degree of AI activity they cannot fully see or govern. The attack surface is larger than the security team's map of it. And you cannot validate what you cannot see.

SailPoint's research on AI agents reinforces this: only 54% of security professionals report full awareness of the data their AI agents can access — highlighting how data-level exposure remains opaque even when the AI systems themselves are known. As AI adoption expands across teams, functions, and workflows, the AI attack surface is growing faster than it can be inventoried, governed, or validated from a security perspective.

The Testing-Confidence Link

The most actionable finding in the dataset is the relationship between testing frequency and security confidence. It is direct, consistent, and significant.

Among enterprises that conduct quarterly penetration testing, 80% report being somewhat or very confident in their AI security. Among those testing annually, that figure falls to 71%. The difference is not enormous in absolute terms — but the direction is unambiguous. The more frequently organizations validate their security posture against real adversarial scenarios, the more confident they are in it.

This correlation has a straightforward interpretation: confidence grounded in testing is different from confidence grounded in assumption. When a CISO says they are "somewhat confident but have gaps," what they are often describing is a posture they believe is adequate but have not fully tested. When testing happens regularly, the gaps get found before an attacker finds them — and closing known gaps is a fundamentally more confident position than assuming unknown gaps don't exist.

The validation gradient: Quarterly testers — 80% confident. Annual testers — 71% confident. The 9-point gap reflects the difference between knowing your posture and assuming it. As AI attack surfaces grow faster than governance frameworks, the cadence of validation becomes the primary driver of defensible confidence.

Why AI Security Is Different

The confidence crisis around AI security is more acute than the general security confidence picture for a specific reason: AI systems introduce new attack surfaces that do not map cleanly onto existing security frameworks, tools, or expertise.

75% of enterprises currently rely on existing endpoint, cloud, application, or API security tools to protect their AI systems — controls designed for other purposes, extended to cover AI infrastructure. Only 11% have dedicated AI security tools in place. 64% are actively evaluating AI-specific security options, which suggests awareness that the current approach is provisional rather than mature.

The practical implication is that most enterprises are protecting AI systems with tools that were not built to understand how those systems can be abused — prompt injection, model manipulation, overpermissioned AI identities, and the data exposure patterns unique to large language model deployments. The expertise gap cited by 50% of CISOs is partly a gap in understanding these attack vectors specifically, not just security in general.

What Closing the Gap Actually Requires

Pentera's own conclusion from the data is worth noting directly: the path forward is less about chasing AI-specific tools and more about strengthening foundational practices so they hold up in an AI-driven environment. That means upskilling teams, clarifying testing methodologies, and strengthening validation practices before layering in additional point solutions.

The confidence data supports this. The CISOs who are most confident are not necessarily the ones with the most AI-specific tools. They are the ones who validate most frequently — who have built a practice of testing their environment against realistic adversarial scenarios on a cadence that matches how quickly the environment changes.

For the 99% of CISOs who are not yet very confident: the gap is closable. But it closes through validation, not assumption. Through testing, not tooling. Through knowing what your AI systems can access, what they expose, and what an attacker could do with them — before that attacker does it first.

Source: Pentera AI Security & Exposure Benchmark 2026. Survey of 300 US CISOs and senior security executives, conducted December 2025 by Global Surveyz Research. SailPoint AI agents attack surface research, 2026. ISC2 Cybersecurity Workforce Study 2025.

See what continuous testing finds in your environment.

Tadpole deploys autonomous agents that simulate real adversaries — 24/7, across your entire attack surface.

Request early access →