GenAI Security Risks: CISOs Face Resource Gaps in 2026

- Global cyber resilience is improving, with fewer CISOs expecting significant attacks compared to 2025.
- Human error remains the top vulnerability, cited by 79% of security leaders globally.
- 78% of CISOs expect to manage AI risks over the next two years without additional budget or staff.
- In Spain, 77% of CISOs view generative AI as a security risk, leading to widespread usage restrictions.
The integration of generative AI into the corporate bloodstream has created a paradoxical environment for Chief Information Security Officers (CISOs). While overall cyber resilience is showing signs of improvement, the specific risks associated with AI are escalating rapidly, often without a corresponding increase in the resources needed to mitigate them. According to the Voice of the CISO 2026 report by Proofpoint, the role of the security leader is shifting from a purely defensive posture to a complex balancing act between innovation and protection.
A global trend toward cyber resilience
Data from 1,600 security leaders across 16 countries suggests that the industry is becoming more robust against traditional threats. The percentage of CISOs globally who anticipate a cyberattack of significant impact has dropped to 61%, a notable decrease from the 76% recorded in 2025. Similarly, the perceived risk of large-scale data loss has fallen from 66% to 53%.
These figures indicate that foundational security measures and infrastructure are maturing. However, this general optimism is tempered by the emergence of new, more nuanced attack vectors. The threat landscape is not necessarily shrinking; rather, it is evolving. The focus of vulnerability has shifted away from perimeter defenses and toward the internal mechanisms of the modern enterprise: the people, the data, and the AI systems that now power daily operations.
The human element as the primary weakness
Despite the sophistication of modern security software, the human factor remains the most volatile variable in the security equation. The Proofpoint study highlights a sharp increase in this vulnerability, with 79% of CISOs identifying human behavior as the primary risk to their organization, up from 66% the previous year.
This trend is particularly evident when intersecting with AI adoption. As employees integrate AI assistants and copilots into their workflows, the risk of accidental data exposure grows. The ease of use provided by generative AI often bypasses traditional security checkpoints, leading to a scenario where employees may inadvertently feed proprietary code, client lists, or strategic plans into public AI models to increase their personal productivity.
Resource gaps in the age of AI
Perhaps the most alarming finding for business leaders is the disconnect between the responsibility assigned to CISOs and the resources provided to them. A staggering 78% of surveyed security leaders expect to manage the risks associated with AI over the next two years without any increase in budget or specialized personnel.
Patrick Joyce, Global Resident CISO at Proofpoint, notes that security leaders are now tasked with a dual mandate. They must protect the company from technological threats while simultaneously acting as enablers for the rapid adoption of transformative technologies. This puts CISOs in a precarious position: they are expected to drive innovation and ensure the safe deployment of AI agents and automation, yet they are doing so with stagnant budgets.
Spanish market insights: A surge in GenAI anxiety
The data from Spain provides a vivid example of how these global trends manifest in specific markets. In the Spanish corporate sector, concerns regarding the security of generative AI have spiked by 39 percentage points year-over-year, with 77% of Spanish CISOs now viewing GenAI as a significant risk. This anxiety is rooted in the practical realities of the workplace.
While 90% of Spanish security leaders believe their current controls can mitigate AI risks, there is a deep-seated fear regarding employee behavior. Specifically, 78% of these professionals fear that employees will expose sensitive data through AI tools, and 74% are concerned about the leakage of client information via public generative AI solutions. This has led to a restrictive approach, with 79% of Spanish organizations implementing direct restrictions on the use of these applications in the work environment.
The specific technologies causing the most concern in Spain include:
- Public generative AI tools (38%)
- Autonomous agents and assistants (34%)
- Cloud storage (31%)
Furthermore, while the expectation of a significant attack in Spain saw a marginal dip from 59% in 2025 to 58% in 2026, the feeling of unpreparedness remains high. Approximately 60% of Spanish CISOs admit their organizations are not properly equipped to handle a targeted attack, and the percentage of companies reporting significant data losses has actually risen from 33% to 42%.
The strategic priority of secure AI adoption
Despite the risks, there is no intention of retreating from AI. In Spain, 93% of security directors view the facilitation of safe AI assistants and automation tools as a strategic priority for the near future. The goal is no longer to block AI, but to create a framework where it can be used without compromising the corporate perimeter.
This shift requires a move toward people-centric security. Since the human factor is the weakest link, the solution lies in combining technical guardrails with intensive training and clear governance policies. The challenge for the modern CISO is to transform the employee from a liability into a first line of defense.
Global implications for US and UK enterprises
For entrepreneurs and executives in the USA and UK, the findings of the Voice of the CISO 2026 report serve as a critical warning. The trend of expecting security teams to absorb AI risks without additional funding is a recipe for systemic failure. In the US market, where AI adoption is often aggressive and fast-paced, the gap between deployment and security governance can create massive liabilities.
From a regulatory perspective, UK and US firms must navigate a fragmented landscape. While the EU's AI Act introduces strict compliance requirements that may affect any global company operating within Europe, US firms are largely dealing with a patchwork of state-level regulations and federal guidelines. The lack of a unified federal AI law in the US places more pressure on the CISO to establish internal standards that can withstand future legal scrutiny.
The core lesson for global business leaders is that AI security cannot be treated as a subset of existing IT security. It requires a dedicated strategy that addresses the unique ways GenAI handles data and the specific ways humans interact with these tools. Investing in specialized AI security talent and updating budget allocations is no longer optional; it is a prerequisite for sustainable digital transformation.
FAQ
What is the main security concern for CISOs regarding generative AI?
The primary concern is the human factor, specifically the risk of employees exposing sensitive corporate or client data when using public AI tools and assistants.
Is overall cyber resilience improving according to the report?
Yes, globally, the percentage of CISOs expecting a significant cyberattack has dropped from 76% in 2025 to 61% in 2026.
How are Spanish companies reacting to GenAI risks?
77% of Spanish CISOs see GenAI as a risk, and 79% have implemented direct restrictions on the use of these applications in the workplace.
Are budgets increasing to match the new AI security challenges?
No, 78% of CISOs expect to manage AI-related risks over the next two years without any increase in budget or specialized staff.
Sources: Computing, Lasnoticiasdelaia, Infonegocios ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email






