A Proofpoint survey of 1,600 chief information security officers (CISOs) finds that rapid enterprise adoption of AI is creating concentrated expectations for security leaders. The survey places AI use, especially AI assistants, copilots and automation, near the top of CISOs' priorities while exposing gaps in resourcing, incident readiness and employee practices.
- 85% of surveyed CISOs said ensuring the safe use of AI tools is a top priority for the next two years.
- Roughly eight in ten CISOs report they are expected to manage AI-related risks without receiving a proportional increase in resources or expertise.
- More than 75% worry employees are using AI in ways that could expose sensitive company data.
- For organisations that experienced material data loss in the past year, about 46% attributed the loss to a malicious or criminal insider.
Patrick Joyce, global resident CISO at Proofpoint, summed up the tension: CISOs have a significant role in securing AI adoption, but they cannot own the risk alone. He highlighted that AI is being adopted across businesses often faster than traditional governance models can keep up.
The survey points to three practical pressures for security leaders:
1) Resourcing gap. Many CISOs must secure AI while budgets, staffing or specialised AI security skills lag behind business adoption. Expect requests for targeted investment in AI governance, monitoring and incident response.
2) Data exposure through employee use. High concern about employees sharing or processing sensitive information with generative AI suggests a need for clearer policies, training, and technical controls that limit sensitive data flow to external AI services.
3) Governance and board communication. Alignment with boards has improved, but board pressure remains high. CISOs need concise, commercially framed reporting that ties AI security posture to operational and reputational risk.
- Define where AI is allowed and where it is not: implement usage policies per system, data classification and role.
- Apply least-privilege and data minimisation to AI integrations so models only see what they must to operate.
- Run AI-specific incident response exercises and tabletop scenarios to close the incident readiness gap.
- Combine technical controls (DLP, API controls, model access logs) with targeted training on acceptable AI use.
- Report AI risk and remediation status to the board in business terms: likely impact, required investment, and residual risk.