Enterprises are racing into genAI deployment without the governance and security foundations vital to managing its risks, with firms unwittingly creating trust gaps that are limiting the effectiveness of autonomous AI pilots.
New research from OpenText in partnership with the Ponemon Institute shows fewer than half of businesses (43%) have adopted a risk-based strategy to govern their AI systems, leaving only one in five confident they’ve reached AI maturity – where cybersecurity activities are fully deployed, and security risks are continually assessed.
Polling over 1,800 IT and security pros globally, the survey found that 79% of enterprises haven’t reached full AI maturity in cybersecurity, with only 41% having AI‑specific privacy policies in place.
In fact, more than half of firms (59%) report that AI is actually making it harder to meet existing privacy and security regulations, citing challenges around managing user risks, including the unintended spread of misinformation and harmful responses.
While the study found that more than half of enterprises have either fully or partially deployed genAI to improve efficiency, including within security operations, gaps in trust, reliability, and explainability suggest cyber-focused AI tools may be limiting the technology’s wider impact.
For instance, despite its promise in threat detection, OpenText found that just 51% of organisations agreed that AI is reducing the time to detect anomalies or emerging threats, while fewer still (48%) rate AI as effective in threat detection and hunting for deeper insights.
Among the biggest roadblocks firms face is shaky operational reliability, with 45% of respondents citing errors in AI decision rules as a top barrier to effectiveness, while 40% report errors in data inputs ingested by AI.
The growing risk of flawed or biased AI models is also causing trust issues, with nearly two‑thirds (62%) of respondents saying it is very or extremely difficult to control model and bias risks, including unfair or discriminatory outputs.
As a result, more than half of respondents (51%) say human oversight is still crucial in AI governance, even as AI systems become more autonomous. According to OpenText, closing this maturity gap will be essential for ensuring compliance and long-term business value.
Recommended reading
- UK Tech Workers Take AI Security Risks to Stay Ahead
- AI Ranks As Top Data Security Risk in 70% of Orgs
- Over-priviledged AI Systems Driving Security Incidents
“Security and governance are foundational to getting real value from AI,” said Muhi Majzoub, EVP for product and engineering at OpenText.
“As AI becomes embedded in day-to-day operations, organisations need secure information management as the foundation; clear governance frameworks, policy-based controls, and continuous monitoring that ensure AI systems remain trustworthy and compliant.
“Just as important is aligning AI with the right data, security practices, and oversight from the outset so innovation can scale responsibly and deliver measurable business value.”





