Gaps in information readiness are causing enterprises to struggle securing, governing, and aligning their AI initiatives across various business interests, according to new research from the Ponemon Institute.
The research firm’s latest report, The Challenges to Ensuring Information Is Secure, Compliant and Ready for AI, published alongside cloud firm OpenText, found that 73% of senior IT leaders believe simplifying information environments is essential for AI readiness, but only 43% feel confident that their current investments in managing information assets are up to the task.
Polling almost 1,900 senior IT and security leaders around the world, the report found that most senior leaders (52%) are finding it difficult to accurately gauge the effectiveness of their information management, for example in measuring reduced errors and rework, gains in efficiency, and reduced compliance risks.
While measuring ROI is a challenge, that is compounded by a lack of direction. The study found that fewer than half (47%) of CIOs, CISOs, and other executives say their business’s IT and security goals are aligned with those driving AI strategy.
The Ponemon Institute found that security leaders are being pulled in competing directions, being required to keep sensitive data safe and meet compliance rules, but without slowing down innovation or getting in the way of business growth.
To help meet that burden, half (50%) of enterprises have either hired or are in the early stages of bringing in a chief AI officer or a chief digital officer to lead on AI strategy, although others in the C-suite are more likely to have final authority for setting the AI agenda, including CEOs (14%) and CIOs (14%).
While there may not be much clarity in who is directing AI strategy, or even where that strategy is heading, the majority of leaders (57%) agree that AI is their top priority for the road ahead.
Even then, almost a third (31%) of respondents said that they were suffering from insufficient budgets for pursuing AI, while 29% said they don’t have enough time to integrate AI-based technologies into their security workflows before rolling it out.
Recommended reading
- PwC Interview | How Agentic AI is Reshaping Business
- How to Avoid Wasting Months on AI That Doesn’t Work
- AI Agents to Hasten Account Exposure Exploitation by 50% by 2027
Perhaps more concerning, more than half (53%) admit that it is very difficult to reduce the legal and security risks surrounding the adoption of AI, being particularly concerned about copyright issues stemming from genAI use.
To meet that challenge, 46% of firms are now developing data security and governance programmes as a first line of defence, while others are using tools to validate AI prompts and their responses (39%), or training teams to spot AI-generated behaviour patterns (39%).
“This research confirms what we’re hearing from CIOs every day. AI is mission-critical, but most organisations aren’t ready to support it,” said Shannon Bell, chief digital officer at OpenText. “Without trusted, well-governed information, AI can’t deliver on its promise.”





