BREAKING NEWS
Logo
Select Language
search
AI Sep 21, 2026 · min read

New AI Security Alert: 60% of Firms Blind to GenAI Use

AI adoption has outpaced AI governance in enterprises. Here is why visibility is the first step to securing your AI ecosystem and regaining control.

Civic News India

Civic News India

Civic News India

New AI Security Alert: 60% of Firms Blind to GenAI Use

TL;DR — Quick Summary

Enterprise AI adoption has moved faster than governance, leaving organisations unable to see how employees use AI tools. Visibility is now the base requirement for every other AI security control.

Key Facts
Core problem
AI adoption has outpaced AI governance across enterprise environments
Security gap
Organisations cannot protect what they cannot see
Visibility status
Visibility has become the prerequisite for all other AI security controls
Tool failure
Traditional monitoring tools fail to track AI activity effectively
Key finding
Cisco's 2025 Cybersecurity Readiness Index found 60% of organisations do not know the specific requests employees make to GenAI tools
Resulting risk
Lack of visibility makes it harder to monitor data movement and enforce policy
Required action
Security teams need new strategies to regain control of their AI ecosystems

Enterprise AI adoption has moved faster than the rules meant to govern it. That gap has created a basic security problem: organisations cannot protect what they cannot see. Visibility across the enterprise AI ecosystem is now the starting point for every other AI security control.

The issue is not that companies are ignoring AI security. It is that the tools they rely on were not built to track AI activity. Traditional monitoring tools fail to follow how employees actually use AI systems, which leaves security teams working blind.

Why Enterprise AI Visibility Is a Security Problem

The numbers show how wide the blind spot is. Cisco's 2025 Cybersecurity Readiness Index found that 60% of organisations do not know the specific requests employees make to GenAI tools. That means most companies have no clear record of what data is being sent into AI systems, or what comes back out.

Without that record, monitoring data movement becomes guesswork. Enforcing policy becomes guesswork too. A security team cannot block a risky request it never sees, and it cannot write a rule for behaviour it cannot measure.

This is why visibility sits at the base of the AI security stack. Access controls, data loss prevention, and policy enforcement all depend on knowing what is happening inside the AI ecosystem first. Skip that step, and every control built on top of it rests on assumptions rather than facts.

What Security Teams Need to Change

The original reporting is clear on one point: the old approach is not working. Traditional monitoring tools fail to track AI activity effectively, and that failure creates significant risks. Closing the gap requires new strategies, not more of the same tooling.

To put it plainly, the fix starts with answering basic questions. Which AI tools are employees using? What are they asking those tools? What company data is leaving the organisation through those requests? Until a security team can answer these questions with evidence rather than estimates, it does not have an AI security programme. It has an AI security hope.

Our Take: Visibility First, Everything Else Second

In our view, the enterprise AI visibility crisis is a governance failure, not a technology failure. Companies rolled out AI tools fast because the business demanded speed. Few of them built the monitoring layer at the same time. Now they are paying for that order of operations.

The good news is that the fix is logical. Visibility comes first. Once security teams can see AI activity across the organisation, every other control becomes easier to design, enforce, and measure. Data movement can be tracked. Policy can be written against real behaviour. Risk can be managed instead of guessed at.

For readers working in security or IT leadership, the message is direct. If you do not know what your employees are asking GenAI tools, you do not know your risk. Start there. Build visibility across your AI ecosystem before you invest in anything else, because every other AI security control depends on it.

Civic News India

Written by

Civic News India

Senior Reporter