Heimdal finds executives far more confident on AI risk than practitioners
Heimdal’s 2026 survey of 1,000 IT professionals in the U.S. and U.K. finds a sharp confidence gap on AI risk inside the same organizations. The report says AI adoption has outpaced security controls, leaving frontline teams more worried than the executives overseeing them.
Why it matters: - The survey points to a leadership blind spot in AI security, with executives more likely than frontline teams to believe risk is under control. - That gap matters because AI is already embedded across most IT environments, but security controls have not kept up. - Heimdal says organizations that treat AI as a core IT asset will be better positioned to limit data leakage, misuse and operational exposure.
What happened: - Heimdal published The State of AI Risk Management in 2026, based on a survey of 1,000 IT professionals in the United Kingdom and the United States. - In the U.S., 29% of C-suite and VP respondents said their organization has AI risk under control, compared with 7% of mid-level practitioners. - In the U.K., 18% of executives said AI risk is under control, compared with 11% of practitioners. - Heimdal said both gaps are statistically significant.
The details: - ChatGPT is present in 72% of U.K. IT environments and 69% of U.S. environments. - Microsoft Copilot is present in 68% of U.K. environments and 59% of U.S. environments. - Across both markets, AI adoption has outpaced security controls by roughly 2-to-1. - Only around 4 in 10 teams said their security stack is ready for AI-related risk. - Among U.K. teams with full visibility into AI use, 56% named data leakage as a top concern, compared with 27% of teams with no visibility. - In the U.S., 59% of teams with full visibility named data leakage as a top concern. - Nearly three-quarters of IT and security teams spend at least a quarter of their week on repetitive, low-value work. - Around one-third spend more than half their week on that work. - 59% of the most overloaded U.S. teams expect AI to ease the load. - 55% of the most overloaded U.K. teams expect AI to ease the load. - The report cites a January 2026 disclosure involving the acting director of CISA, who uploaded documents marked “For Official Use Only” to public ChatGPT in mid-2025. - CISA’s monitoring flagged the activity within a week, but the use policy did not prevent it. - The full report is available here.
Between the lines: - The findings suggest visibility into AI use increases concern rather than comfort. - Heimdal frames visibility as a diagnosis, not a fix, because seeing more of the problem does not automatically reduce the risk. - Adam Pilton, cybersecurity advisor at Heimdal, said executives are more confident than the evidence supports and that the bigger question is how AI can be turned against the business. - Rafay Baloch, CEO and founder of REDSECLABS, said the biggest risk is the blind spots created when teams use AI tools without clear oversight. - Baloch added that policies alone do not create visibility and that stronger outcomes come from guardrails plus responsible employee use.
What’s next: - Heimdal says companies should manage AI like any other critical supplier by adding procurement review, contractual data-handling terms and a current inventory of sanctioned and unsanctioned AI tools. - The report also calls for technical controls over access, execution, action chains and privilege. - The research used Pollfish to survey 1,000 IT professionals from May 1 to May 8, 2026, split evenly between the U.K. and the U.S. - The sample covered six seniority tiers, from entry level through C-suite and VP.
The bottom line: - AI is already in the stack. The bigger gap now is between how safe leaders feel and how exposed the teams running AI believe they are.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The UK Consumer
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.