AI has moved from experimentation to implementation, but despite organisations being full steam ahead, gaps still remain both in organisations technical foundations and CISOs’ confidence.
MIND has reported that 90% of organisations have deployed AI, yet 70% struggle to enforce related security policies. This AI adoption problem is further aggravated as 1 in 5 projects fail due to data issues. When data foundations are strong, organisations can embed AI significantly more successfully. Poor data results in slow innovation and increased risk.
The report centres on one hypothesis: ‘data trust is not a security feature. It is the invisible but decisive ingredient that determines whether AI projects succeed or fail’.
MIND surveyed 124 security leaders and found 65% of CISOs are not confident or are only somewhat confident in their AI data security controls.
When asked about the biggest challenges with AI security ‘Enforcing policies on GenAI tools’ came out on top (70%), and ‘Understanding what data AI agents can access’ was another close concern (68%).
A number of key insights were highlighted through the research.
Policy must be enforced
There is still a wide gap between visibility and enforcement of AI policies, creating risk and uncertainty for c-suite leaders. By this point, most organisations have AI policies in place, but how widely they have been embraced is hard to measure. CISOs are concerned about non-compliance with policy and how this could expose businesses. The survey suggested 98% are struggling with at least one AI security problem.
Strong data foundations are key
Data fundamentals are lacking and impede AI projects, with AI exposing significant data debt. Years of poor data governance, unclassified data, and inaccurate information has created and an environment where errors are identified, accessible and used by AI agents at scale. The survey found 65% do not know what data is accessible for AI input and 68% don’t know what data their agents are accessing.
This poor data is already resulting in failed projects. The report suggested that many AI projects are being re-architected or abandoned completely as a result of producing unreliable outputs from poor data. Findings suggest 68% of CISOs struggle to manage data input to GenAI, with only 1 in 5 achieving desired KPIs from AI projects.
When AI is applied to this landscape of incomplete and inaccurate data, it uncovers the existing vulnerabilities and system weaknesses.
Recommended reading
- 82% of Firms Say the Exposure Management Gap is Widening
- Economic Turmoil Tops AI As Leading Emerging Risk of Q3 2025
- CEOs Bracing For An Explosion of Cyber-Fraud in 2026, Finds WEF
What does good look like?
In comparison, organisations with high levels of data trust are capitalising on this competitive advantage. Accurate, classified and well-governed data is allowing organisations to remove friction and embrace AI projects confidently. The CISOs who showed confidence in AI projects were those with a robust and transparent data estate.
CISO, Jacob Combs noted: “There is a direct correlation between high data trust and the speed of AI project adoption.”
The report highlights a reality, not wherein AI tools inhibit project success themselves, but rather issues in the organisational data structure they are being applied to.
The report suggests better data infrastructure, enforced AI policy and confidence create strong conditions for AI project success. But more fundamentally, organisations must treat data as a strategic asset rather than an afterthought. This means investing in clear data ownership, robust classification systems and continuous visibility into how data is accessed and used in AI systems. Without these robust foundations even the best AI systems will struggle to deliver the desired results.





