European organisations trail behind global benchmarks when it comes to AI security controls, new research from Kiteworks has found.
The firm’s Data Security and Compliance Risk: 2026 Forecast Report found that European firms are lacking with it comes to AI threat detection, AI breach response, and AI data flow governance.
The research, based on a survey of security, IT, compliance, and risk leaders across 10 industries and 8 regions, exposes a widening gap between Europe’s regulatory leadership, with regulations such as the EU AI Act, and its actual AI security posture.
European organisations trail on AI anomaly detection (France 32%, Germany 35%, the UK 37% vs. 40% global), training-data recovery (40% to 45% vs. 47% global), and software bill of materials (SBOM) visibility for AI components (20% to 25% vs. 45%+ in leading regions).
When AI systems behave unexpectedly – or when AI-enabled attacks target European infrastructure – most organisations lack the detection capabilities to identify the threat. This can result in compliance fines and negative brand exposure as well as breaches of sensitive data.
“Europe has led the world on AI governance frameworks with the AI Act setting the global standard for responsible AI deployment. But governance without security is incomplete,” said Wouter Klinkhamer, GM of EMEA Strategy & Operations, Kiteworks. “When an AI model starts behaving anomalously, such as accessing data outside its scope, producing outputs that suggest compromise, or failing in ways that expose sensitive information, European organisations are less equipped than their global counterparts to detect it. That’s not a compliance gap. That’s a security gap.”
The report identified six predictions for European organisations in 2026.
The implications extend beyond compliance. AI systems are increasingly processing sensitive data, making autonomous decisions, and integrating with critical infrastructure. Every AI model that can’t be monitored for anomalies is a system where adversarial inputs, data poisoning, or model manipulation go undetected.
Every third-party AI component that can’t be tracked is a dependency where upstream compromises silently inherit into your environment. Every AI vendor relationship without a joint incident playbook is a breach that spreads unchecked across organisational boundaries.
Recommended reading
- Report: 28% Global Cyber-attack Increase in Q1 2024
- 92% of Enterprise Devices Unprepared for AI Security Challenges
- NCSC Releases Cyber Incident Response Guidance for CEOs
- Over 1 in 10 Business Leaders Don’t Know if They’ve Been Hacked
These aren’t governance failures waiting for a regulatory audit. They’re attack surfaces waiting for an adversary. Compliance gaps carry the abstract risk of penalties. Security gaps carry the concrete certainty of compromise: data exfiltration, manipulated outputs, operational disruption. The difference is between a fine you can budget for and a breach you can’t predict.
The global report, which includes 15 predictions across data visibility, AI governance, third-party risk, and compliance automation, identifies “keystone capabilities” – unified audit trails and training-data recovery – that predict success across all other security metrics, showing a measurable advantage for organisations that have implemented them.
“The AI Act establishes what responsible AI governance looks like. The question for European organisations is whether they can secure what they’re governing,” added Klinkhamer. “By the end of 2026, the organisations that have closed the gap between AI policy and AI security through anomaly detection, training-data recovery, supply chain visibility, vendor incident coordination will be positioned for both compliance and resilience. Those still running AI workloads without detection capabilities will learn about their security gaps the hard way: from attackers, not auditors.”





