09/26/2026, 14.42
Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp

GenAI Security Risks: CISOs Face Resource Gaps in 2026

Proofpoint's Voice of the CISO 2026 report reveals a surge in GenAI security fears and a critical lack of budget to manage AI-driven vulnerabilities.
GenAI Security Risks: CISOs Face Resource Gaps in 2026
Key points
  • Global cyber resilience is improving, with fewer CISOs expecting significant attacks compared to 2025.
  • Human error remains the top vulnerability, cited by 79% of security leaders globally.
  • 78% of CISOs expect to manage AI risks over the next two years without additional budget or staff.
  • In Spain, 77% of CISOs view generative AI as a security risk, leading to widespread usage restrictions.

The integration of generative AI into the corporate bloodstream has created a paradoxical environment for Chief Information Security Officers (CISOs). While overall cyber resilience is showing signs of improvement, the specific risks associated with AI are escalating rapidly, often without a corresponding increase in the resources needed to mitigate them. According to the Voice of the CISO 2026 report by Proofpoint, the role of the security leader is shifting from a purely defensive posture to a complex balancing act between innovation and protection.

A global trend toward cyber resilience

Data from 1,600 security leaders across 16 countries suggests that the industry is becoming more robust against traditional threats. The percentage of CISOs globally who anticipate a cyberattack of significant impact has dropped to 61%, a notable decrease from the 76% recorded in 2025. Similarly, the perceived risk of large-scale data loss has fallen from 66% to 53%.

These figures indicate that foundational security measures and infrastructure are maturing. However, this general optimism is tempered by the emergence of new, more nuanced attack vectors. The threat landscape is not necessarily shrinking; rather, it is evolving. The focus of vulnerability has shifted away from perimeter defenses and toward the internal mechanisms of the modern enterprise: the people, the data, and the AI systems that now power daily operations.

The human element as the primary weakness

Despite the sophistication of modern security software, the human factor remains the most volatile variable in the security equation. The Proofpoint study highlights a sharp increase in this vulnerability, with 79% of CISOs identifying human behavior as the primary risk to their organization, up from 66% the previous year.

This trend is particularly evident when intersecting with AI adoption. As employees integrate AI assistants and copilots into their workflows, the risk of accidental data exposure grows. The ease of use provided by generative AI often bypasses traditional security checkpoints, leading to a scenario where employees may inadvertently feed proprietary code, client lists, or strategic plans into public AI models to increase their personal productivity.

Resource gaps in the age of AI

Perhaps the most alarming finding for business leaders is the disconnect between the responsibility assigned to CISOs and the resources provided to them. A staggering 78% of surveyed security leaders expect to manage the risks associated with AI over the next two years without any increase in budget or specialized personnel.

Patrick Joyce, Global Resident CISO at Proofpoint, notes that security leaders are now tasked with a dual mandate. They must protect the company from technological threats while simultaneously acting as enablers for the rapid adoption of transformative technologies. This puts CISOs in a precarious position: they are expected to drive innovation and ensure the safe deployment of AI agents and automation, yet they are doing so with stagnant budgets.

Spanish market insights: A surge in GenAI anxiety

The data from Spain provides a vivid example of how these global trends manifest in specific markets. In the Spanish corporate sector, concerns regarding the security of generative AI have spiked by 39 percentage points year-over-year, with 77% of Spanish CISOs now viewing GenAI as a significant risk. This anxiety is rooted in the practical realities of the workplace.

While 90% of Spanish security leaders believe their current controls can mitigate AI risks, there is a deep-seated fear regarding employee behavior. Specifically, 78% of these professionals fear that employees will expose sensitive data through AI tools, and 74% are concerned about the leakage of client information via public generative AI solutions. This has led to a restrictive approach, with 79% of Spanish organizations implementing direct restrictions on the use of these applications in the work environment.

The specific technologies causing the most concern in Spain include:

  • Public generative AI tools (38%)
  • Autonomous agents and assistants (34%)
  • Cloud storage (31%)

Furthermore, while the expectation of a significant attack in Spain saw a marginal dip from 59% in 2025 to 58% in 2026, the feeling of unpreparedness remains high. Approximately 60% of Spanish CISOs admit their organizations are not properly equipped to handle a targeted attack, and the percentage of companies reporting significant data losses has actually risen from 33% to 42%.

The strategic priority of secure AI adoption

Despite the risks, there is no intention of retreating from AI. In Spain, 93% of security directors view the facilitation of safe AI assistants and automation tools as a strategic priority for the near future. The goal is no longer to block AI, but to create a framework where it can be used without compromising the corporate perimeter.

This shift requires a move toward people-centric security. Since the human factor is the weakest link, the solution lies in combining technical guardrails with intensive training and clear governance policies. The challenge for the modern CISO is to transform the employee from a liability into a first line of defense.

Global implications for US and UK enterprises

For entrepreneurs and executives in the USA and UK, the findings of the Voice of the CISO 2026 report serve as a critical warning. The trend of expecting security teams to absorb AI risks without additional funding is a recipe for systemic failure. In the US market, where AI adoption is often aggressive and fast-paced, the gap between deployment and security governance can create massive liabilities.

From a regulatory perspective, UK and US firms must navigate a fragmented landscape. While the EU's AI Act introduces strict compliance requirements that may affect any global company operating within Europe, US firms are largely dealing with a patchwork of state-level regulations and federal guidelines. The lack of a unified federal AI law in the US places more pressure on the CISO to establish internal standards that can withstand future legal scrutiny.

The core lesson for global business leaders is that AI security cannot be treated as a subset of existing IT security. It requires a dedicated strategy that addresses the unique ways GenAI handles data and the specific ways humans interact with these tools. Investing in specialized AI security talent and updating budget allocations is no longer optional; it is a prerequisite for sustainable digital transformation.

FAQ

What is the main security concern for CISOs regarding generative AI?

The primary concern is the human factor, specifically the risk of employees exposing sensitive corporate or client data when using public AI tools and assistants.

Is overall cyber resilience improving according to the report?

Yes, globally, the percentage of CISOs expecting a significant cyberattack has dropped from 76% in 2025 to 61% in 2026.

How are Spanish companies reacting to GenAI risks?

77% of Spanish CISOs see GenAI as a risk, and 79% have implemented direct restrictions on the use of these applications in the workplace.

Are budgets increasing to match the new AI security challenges?

No, 78% of CISOs expect to manage AI-related risks over the next two years without any increase in budget or specialized staff.


Sources: Computing, Lasnoticiasdelaia, Infonegocios ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Condividi su Facebook Condividi su Twitter Condividi su Pinterest Condividi su Telegram Condividi su WhatsApp
Printable version
CLOSE X
Share this story
See also
Canva London Event Disrupted by Pull The Plug AI Activists
Anti-AI group Pull The Plug disrupts Canva's London showcase, demanding a moratorium on data centers and binding Citizens' Assemblies for AI regulatio…
26/09/2026 12:48
AI Compliance Certification: ASCOM Launches AICOM Standard
ASCOM introduces AICOM, a professional certification for AI compliance to help organizations meet EU AI Act literacy requirements and manage systemic …
26/09/2026 02:27
AI Content Labeling and Algorithmic Shifts: New Global Rules
EU AI Act transparency mandates and Australia's Digital Duty of Care draft laws are redefining how businesses deploy AI and manage social media reach.
25/09/2026 14:22
US Battery Storage Hits Record Highs as Grid-Scale Tech Surges
US battery installations hit a record 20.2 GWh in Q2 2026. While utility-scale and data center storage thrive, residential systems face a sharp declin…
24/09/2026 14:41
Securing Siemens S7 PLCs: CISA Warns Against AI-Driven Threats
CISA and federal agencies warn of active threats to Siemens S7 PLCs. Learn why AI-assisted scripts make industrial hardening a complex, high-stakes ta…
24/09/2026 12:23


Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now