78% of Organizations Can't Answer the One Question AI Regulators Will Ask First
CIOREVIEW >> Compliance >> NEWS

This article is part of CIOReview's Innovation Insights series featuring expert contributions nominated by our subscribers and reviewed by our editorial team.

78% of Organizations Can't Answer the One Question AI Regulators Will Ask First

Tim Freestone, Chief Strategy Officer, Kiteworks

Data Governance Strategist

Editor’s Note: Enterprise leaders can no longer treat AI governance as a policy exercise when regulators, insurers and auditors increasingly expect technical proof of data control.This perspective underlines why the next phase of AI readiness will be won at the data layer, where access, provenance and auditability determine whether organizations can defend their AI systems.

Colorado's AI Act takes effect June 30, 2026. California's full Automated Decision-Making Technology provisions begin enforcement January 1, 2027. Both require organizations to produce documented risk assessments, transparency disclosures, and evidence of technical controls for AI systems making consequential decisions.

Here is the question neither law asks directly, but both implicitly demand: How do you know there's no personal data in your model?

According to research we conducted across hundreds of organizations, 78% cannot answer it. They cannot validate data before it enters training pipelines. They cannot prove to a regulator — or an auditor, or an insurer — that the data feeding their AI systems meets quality, legality, or consent requirements.

That number alone should reframe how every CISO and security leader thinks about AI governance in the second half of 2026.

The Training Data Readiness Gap Is Worse Than You Think

The 78% validation failure is just the entry point. The same research found that 77% of organizations cannot trace where their training data came from — making provenance questions from regulators functionally unanswerable. Sixty-five percent lack dataset access controls. Sixty-two percent cannot demonstrate data minimization practices for AI. Fifty-nine percent do not encrypt training data. And 53% cannot recover training data after an incident.

That last number deserves emphasis. When a model is compromised, poisoned, or found to contain unauthorized personal data, 53% of organizations have no mechanism to remediate. Their incident response stops at containment. There is no path to fixing the model that does not involve retraining from scratch — a process that is expensive, time-consuming, and often impractical for models already in production.

This is not an AI problem. It is a data governance problem that AI made visible.

Shadow AI Is Outrunning Governance 7-to-1

The gap between AI adoption and AI governance is not narrowing. The DTEX/Ponemon 2026 Insider Threat Report found that 92% of organizations say generative AI has fundamentally changed how employees access and share information. But only 13% have formally integrated AI into their business strategies.

  ​You cannot govern what you cannot see, and shadow AI is already the top driver of negligent insider incidents. 

That is a 7-to-1 ratio between disruption and governance. And it has real financial consequences. Shadow AI — unapproved AI tools embedded in daily workflows — is now the top driver of negligent insider incidents, according to DTEX. Negligent insiders account for 53% of total insider risk cost at $10.3 million annually, up 17% year over year.

The 2026 Thales Data Threat Report adds context: AI security has risen to the number two spending priority, behind only cloud security. Organizations are allocating budgets. But budgets are flowing toward model-level guardrails and prompt filtering — not toward the data-layer controls that determine what information AI systems can access in the first place.

That is the wrong layer.

Why Model-Level Guardrails Are Not Governance

There is a seductive logic to putting guardrails on the model: if the AI cannot say harmful things, the problem is solved. The research tells a different story.

The CrowdStrike 2026 Global Threat Report documented an 89% increase in AI-enabled adversary attacks year over year. Attackers are not trying to make AI say harmful things. They are targeting AI systems to access data — through prompt injection into legitimate AI tools, abuse of AI-driven workflows, and expansion of the attack surface into data pipelines and decision systems.

Model-level guardrails do not address this threat. An AI agent with broad access to a data lake will follow its access permissions regardless of what prompt filtering sits between the user and the model. If the permissions are too broad — and in most organizations, they are — the guardrail is irrelevant. The data is already exposed.

The governance question is not "What can the AI say?" It is "What data can the AI reach, under what conditions, and with what audit trail?" That is a data-layer question, not a model-layer question.

Regulators, Insurers, and the SEC Are Converging on the Same Answer

What makes 2026 distinctive is not any single regulation. It is the convergence.

The SEC has flagged AI-driven threats to data integrity as a 2026 examination priority and is considering enhanced disclosure requirements around AI governance. Cyber insurers, according to OneTrust's global AI regulation analysis, are beginning to demand AI-specific security practices as conditions for coverage — adversarial red-teaming, model-level risk assessments, and alignment with frameworks like the NIST AI Risk Management Framework.

The EU AI Act's phased timeline brings general-purpose AI model obligations into force now, with high-risk AI system requirements following in 2026–2027. The requirements — technical documentation, risk management, transparency, human oversight — are modeled on GDPR-style accountability structures. The World Economic Forum 2026 Global Cybersecurity Outlook found that 31% of large organizations already cite regulatory complexity as a top barrier to cyber resilience.

Every one of these bodies is asking the same fundamental question: can you prove what data your AI systems access, who authorized that access, and what happened when the access occurred? The organizations that can answer that question with technical evidence — not policy documents — will navigate this convergence. The rest will discover, one enforcement action at a time, that AI governance was always a data governance problem.

What Needs to Change Before Enforcement Deadlines Arrive

The strategic shift is not complicated. It is a change in layer.

Organizations need to move AI governance from the model layer to the data layer. That means technical controls — not policies — that determine what data AI systems can access based on content sensitivity, user authorization, regulatory jurisdiction, and purpose. It means every AI data access event captured in an audit trail that is complete, tamper-evident, and exportable to the systems regulators and insurers will inspect. And it means the same governance framework that covers email, file sharing, and managed file transfer extending into AI integrations — because regulators will not accept a governance gap between how an organization protects a file shared via SFTP and how it protects the same file accessed by an AI agent.

Three priorities for the next 90 days. First, inventory every AI tool and integration in use — sanctioned and unsanctioned. You cannot govern what you cannot see, and shadow AI is already the top driver of negligent insider incidents. Second, deploy data-layer access controls for AI integrations with the same rigor applied to human access. If a human analyst needs role-based authorization to access regulated data, so does the AI agent querying that data. Third, start building training data documentation now — provenance, legal basis, consent status, retention periods. With 77% of organizations unable to trace training data origins, starting imperfectly still puts you ahead of the enforcement curve.

The deadlines are not abstract. Colorado's AI Act takes effect in fewer than three months. The organizations that treat these dates as action triggers will be the ones that can answer the question regulators are about to ask.

Tim Freestone is Chief Strategy Officer at Kiteworks, where he leads go-to-market strategy for the company’s Private Data Network platform. He writes about the intersection of data governance, regulatory compliance, and enterprise technology adoption.

MORE FROM INNOVATION INSIGHTS

Connecting Data, Context, and Trust in the Age of Semantic AI
Zenia Graph
Aurelije Zovko, Co-founder and CTO, Zenia Graph, and Nina Mladenovski, Co-founder and COO
Stop Automating Broken Processes: The Next Era of Business Workflow Automation
Herbert Insights & Innovations
Martin J. Herbert IV, President/CEO

EXPLORE OUR KNOWLEDGE NETWORK



The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.