Skip to content
News

UltraViolet Cyber Introduces AISec Study, the First Practitioner-led Benchmark for Enterprise AI Security

UltraViolet Cyber

UltraViolet Cyber

August 27, 2026

Confidential, interview-based assessment gives security leaders an evidence-based view of how organizations are actually governing, building and defending AI - replacing guesswork with data. 

MCLEAN, Va. — August 27, 2026 — Today, UltraViolet Cyber (UltraViolet), the only security operations partner that unifies red, blue and purple team capabilities into one integrated offering, released findings from its AISec Study, an inaugural, interview-based benchmark of how organizations are actually securing and governing enterprise AI. Each engagement delivers a private report, benchmarking the organization against industry patterns and peer practices, together with prioritized recommendations for closing the gaps that matter most.

Most AI security guidance today is prescriptive, drawing on standards and checklists that describe what a program should look like. The AISec Study is different: It draws on a methodology similar to BSIMM (the Building Security In Maturity Model), a long-established benchmark for software security programs. The company designed the AISec Study to measure what organizations actually do, not what a framework says they should do. The study highlights findings from the banking and financial services, enterprise software, healthcare, manufacturing, hospitality, government and nonprofit sectors.

"This study gives security leaders something the industry hasn't had: a clear, evidence-based picture of where AI security programs actually stand, not where a checklist says they should be,” said Aravind Venkataraman, VP of Technology and AI Security, UltraViolet Cyber. “The pattern is consistent across every organization we assessed: the decisions have been made, and now the work is building the engineering and assurance to back them up. That's exactly where we help close the gap between tested and detected."

Engineering and Depth are Still Catching Up

UltraViolet found that Governance & Policy was the strongest capability, while AI Incident Response was the weakest, and Direction & Oversight, Assurance & Protection and Engineering & Usage averaged in the middle — a consistent split between deciding what to do with AI and building the controls that defend it.

The gap shows up again when breadth is measured against depth. On average, participating organizations have started roughly 86% of the framework's activities but are depth-weighted at about 59% — a large difference between beginning a control and making it repeatable and enforced. Starting a control is the easy part; standardizing it is where coverage scores are won or lost.

The Clearest Shared Gap: AI-driven Development Lifecycle

The study's sharpest finding centers on how software now gets built. Every organization in the study has approved a variety of AI coding assistants, which is the single most adopted control observed. But the controls that would make that AI-driven development lifecycle accountable are still emerging: no organization has established a repeatable way to track which code an AI agent wrote, screen that code for license and IP risk or detect automated attacks targeting AI systems. Only one organization in this study has established detection for automated, AI-driven attack behavior.

Participants also aligned on the same open problem: giving non-human AI agents their own identities, scoping what they're allowed to do and containing the blast radius when something goes wrong. That capability was observed in some form at 80% of organizations, but was fully established at zero.

"The AISec Study gave us visibility into more data-driven insights to measure and improve our AI initiatives,” said Sandy Blackwell, Global Senior Director, Software Security, 74 Software. “This allows us to compare our practices against those of other organizations, and helps identify potential gaps as well as gauge what to prioritize in terms of improvements. We are looking forward to continuing to work with the AISec benchmark team."

About the AISec Study

The AISec Study is practitioner-led. Each participating organization is assessed through confidential interviews with security, AI, governance and engineering leadership, and every organization is measured against the same catalog so that results are comparable across the data pool. Figures reflect the ten organizations assessed to date and are shifting as the data pool grows with observations from the second cohort of organizations, which are already in progress.

Organizations that want the same view of their own AI security posture don’t have to wait for the next phase of the study. UltraViolet offers its AI Security Program Assessment as a standalone engagement, applying the same AISec methodology through confidential interviews with security, governance and product teams. To learn more or schedule the assessment, visit UltraViolet Cyber.

About UltraViolet Cyber

UltraViolet Cyber is the only security operations partner that unifies red, blue, and purple team capabilities into one integrated team — finding what's vulnerable, stopping active threats, and validating that your defenses hold under real pressure. Built by former U.S. intelligence community operators with 30+ years of experience, we serve 400+ Global 2000 enterprises and federal agencies. Our practitioner-led and AI-accelerated closed-loop operations turn offensive findings into defensive weapons immediately so gaps close in real time and defenses improve before attackers can exploit what testing uncovers. Offense informs defense. Defense sharpens offense. Security that gets smarter and stronger with every iteration.

UltraViolet is at the forefront of AI security. Purpose-built to test, validate, and govern the AI systems organizations are deploying today, UltraViolet brings the same offensive and defensive rigor to AI that it applies across the enterprise. UltraViolet is ranked #19 on the Top 250 MSSP List and is headquartered in McLean, Virginia. For more information, visit our website, read our blog, or follow us on LinkedIn.

Media Contact

W2 Communications for UltraViolet Cyber ultraviolet@w2comm.com