Technology Risk Jumped 40 Points. AI Governance Didn’t.
700 board members say risk is spiking. 225 security leaders say they can’t shut off a misbehaving AI agent in under five minutes. Same gap, two different rooms.
Something strange showed up in Clyde & Co’s newest boardroom survey. The same executives who spent the last two years building out AI governance committees are now telling researchers, anonymously, that the risk outran the committee. Clyde & Co’s Corporate Risk Radar 2026 polled 700 board members, C-suite executives, and General Counsel across ten sectors and eight regions, and the technology risk number didn’t inch up this year. It jumped from 46% to 86% rating it high impact, in twelve months. Forty points. Read that again. That’s not a trend line. That’s a category getting re-priced in real time.
The confidence number and the capability number don’t match
Here’s the part that should bother a skeptical CISO more than the 40-point jump itself. Seventy-six percent of Clyde & Co’s respondents say AI, data privacy, and cybersecurity regulation is evolving faster than their organization can absorb. Only 68% say they have a mature AI governance framework in place. And yet 88% say they feel prepared to mitigate technology risk overall.
Sit with that math for a second. Confidence: 88%. Regulatory pace outrunning capability: 76%. Actual governance maturity: 68%. Those numbers describe three different organizations, except they’re the same organization, answering three different questions on the same survey. Clyde & Co’s own researchers called it out directly, noting the 88% figure “may suggest confidence is running ahead of maturity.” That’s the polite version.
This isn’t one survey’s anomaly
Here’s where it gets uncomfortable. Kiteworks ran its own survey of 225 security, IT, and risk leaders for the 2026 Data Security Forecast, published five months before Clyde & Co’s, across a completely different sample. It found the same gap, gave it a name, and the name is worse than “governance maturity.” Call it the containment gap. Sixty-three percent of organizations cannot enforce purpose limitations on their own AI agents. Sixty percent cannot quickly terminate an agent that’s misbehaving. Fifty-five percent cannot isolate an AI system from the broader network once something goes wrong. Organizations are watching their AI systems closely. Watching is not the same as stopping.
The timing makes it worse. CrowdStrike’s 2026 Global Threat Report found AI-enabled adversary operations increased 89% year over year, and average breakout time, the window between initial access and lateral movement, fell to 29 minutes, with the fastest observed intrusion completing in 27 seconds. A governance model built around quarterly reviews and after-the-fact log analysis was already slow. Against a 29-minute breakout window, it isn’t a governance model. It’s a postmortem.
Why the math got worse this year
Three things compounded at once, and none of them are going to reverse.
Start with dependency. It concentrated. Clyde & Co found that as AI adoption accelerated, organizations became more reliant on a smaller pool of third-party technology providers and more exposed at the integration points between systems. Verizon’s 2025 Data Breach Investigations Report shows exactly where that leads: third-party involvement in breaches doubled year over year, to 30% of all incidents analyzed. Fewer vendors, more blast radius per vendor.
Then there’s geopolitics. It stopped being background noise. Clyde & Co found geopolitical risk’s direct commercial impact rose from 49% to 72% in a single year, and the World Economic Forum’s Global Risks Report 2026 puts geoeconomic confrontation at the top of its global risk list, with half of the 1,300-plus experts it surveyed expecting a turbulent world over the next two years, up 14 points from last year. Hostile actors use instability as cover. Instability is no longer occasional.
The piece that actually ties the first two together is audit trails, the thing that would let a security team prove what happened and shut it down fast, and they’re the weakest link in most environments. Kiteworks’ Forecast Report found 33% of organizations lack evidence-quality audit trails entirely, and another 61% have logs fragmented across systems, present but not aggregated, normalized, or usable in a timeframe that matters. Organizations without evidence-quality audit trails trail by 20 to 32 points on every AI governance metric measured, more than industry, region, or budget explains on its own.
The architectural question
None of this gets fixed by buying another monitoring dashboard. Monitoring is precisely the capability everyone already has. Sixty-three percent purpose-limitation failure and 60% containment failure exist alongside heavy investment in visibility tools, not because of their absence. The gap isn’t seeing the problem. It’s stopping it before the 29-minute window closes.
That reframes the actual question. Not “how do we watch AI systems more closely,” but “where does the decision to allow or block a specific data access get made, and how fast can it execute.” An architecture that enforces access, encryption, and audit logging at the point where data actually moves, rather than reconstructing it later from five different systems, closes exactly the gap both surveys describe. Kiteworks is one example of a platform built on that premise: a single-tenant hardened virtual appliance with one policy engine governing email, managed file transfer, SFTP, web forms, and APIs, generating one evidence-quality audit log instead of the fragmented version 61% of organizations are stuck reconciling. It’s not the only way to build this. It is the property the containment gap is actually asking for.
What to do Monday morning
• Pull your AI agent inventory. For each one, ask: can you terminate its access in under five minutes, without a change ticket? If the answer isn’t yes across the board, that’s a containment problem, not a monitoring problem.
• Check whether your audit logs are aggregated or just accumulated. Five systems logging separately isn’t an audit trail. It’s a filing cabinet you’ll open after the damage is done.
• Get AI governance onto the board’s top-five list this quarter. Boards that already prioritize it run 26 to 28 points ahead on every maturity metric measured – the biggest single lever in either survey.
• Map your third-party AI and data providers the way you’d map a single point of failure. A 30% third-party breach rate says that’s what they are.
The organizations that get hit hardest in 2026 won’t be the ones with the smallest security budget. They’ll be the ones whose board minutes never mentioned AI governance until the incident report did.


