Guides

AISec Study: Closing the Gap in Enterprise AI Security

Written by UltraViolet Cyber | Aug 27, 2026, 12:00:00 PM

The AISec Study documents what AI security programs actually do, based on confidential interviews with the people running them.

UltraViolet Cyber sat down with security, AI, governance, and engineering leaders at 10 organizations across banking, enterprise software, healthcare, manufacturing, hospitality, government, and the nonprofit sector. Each organization was scored against a shared catalog of 64 activities across three domains: Direction & Oversight, Engineering & Usage, and Assurance & Protection. Every activity lands in one of three tiers: Established, Emerging, or Unobserved.

The result is a comparable, evidence-based view of AI security maturity across the data pool.

StrategyVisibilityGov & PolicyModel LifecycleAI SDLCAI SecOpsData GovernanceSecurity AssuranceRuntime MonitoringIncident Response
Data-pool averageRange across the 10 organizations (min and max)


What's in the report:

  • Full capability and domain-level scores across all 10 organizations in the data pool
  • The breadth-versus-depth gap, and what it means for where programs are actually exposed
  • Findings on AI coding assistant governance and agent identity, the two areas with the widest gap between adoption and control
  • A practitioner's view from Aravind Venkataraman, UltraViolet Cyber, on where the data points next