2026 SANS AI Survey - Free Report | Backslash Security

The 2026 SANS AI Survey - Free Report

Security teams have inherited responsibility for enterprise AI without the infrastructure to act on it. 76% now hold a governance role for AI, up from 68% last year - yet only 36% have a formal AI risk program. And the gap practitioners name first isn't policy or budget. It's visibility: 63% say they cannot see where AI is running or what it can reach, up from 56% a year ago.

That blind spot has a location. AI agents, copilots, and coding assistants execute on employee and developer endpoints, inheriting the permissions of the identities behind them - the one layer EDR, DLP, and AI gateways were never built to inspect.

Backslash sponsored the 2026 SANS AI Survey because its findings match what we see across enterprise fleets every day. Written by SANS Certified Instructor Matt Bromiley from 536 practitioner responses and a parallel survey of 57 CISOs, it's the clearest independent picture yet of how far AI adoption has outrun AI governance.

Download the report to learn:

  • Why visibility is the first control, not the last. 63% can't see where AI is running or what it exposes, and 52% name closing that gap as their single most common planned adaptation. It's the same sequence that works in practice: see it, govern it, then protect it.
  • How much AI is running with no policy at all. Only 41% of organizations use generative AI under strict policy. 39% report informal use with no policy whatsoever. That's shadow AI, measured.
  • Why point-in-time assessments aren't governance. The most common governance activity is periodic assessment and penetration testing (30%), while just 16% monitor continuously. Snapshots don't catch drift, and the agentic fabric on an endpoint changes daily.
  • Where the AI supply chain risk actually sits. 69% now run third-party AI risk assessments, yet 47% still trust vendors to manage their own AI risk without auditing them. For MCP servers and agent Skills installed directly onto an endpoint, that trust is the exposure.
  • What leaders believe versus what practitioners live with. 50% of leaders report a formal AI risk program; only 36% of practitioners agree, using identical wording. Governance the people doing the work can't see isn't governing much.

The gap this survey ranks first - visibility into where AI runs and what it can reach - is the problem Backslash was built to close.

Backslash discovers every AI agent, MCP server, and Skill running on your endpoints, surfaces the risk each one carries, enforces policy automatically, and blocks risky actions in real time. Continuously, not periodically.

The survey found the gap. Find yours.

Get the SANS Survey →

Get the AI SANS Survey >
Back to Feed

2026 SANS AI Survey - Free Report | Backslash Security

-

August 16, 2026

Backslash sponsored the 2026 SANS AI Survey because its findings match what we see across enterprise fleets every day. Written by SANS Certified Instructor Matt Bromiley from 536 practitioner responses and a parallel survey of 57 CISOs, it's the clearest independent picture yet of how far AI adoption has outrun AI governance.

Download the report to learn:

  • Why visibility is the first control, not the last. 63% can't see where AI is running or what it exposes, and 52% name closing that gap as their single most common planned adaptation. It's the same sequence that works in practice: see it, govern it, then protect it.
  • How much AI is running with no policy at all. Only 41% of organizations use generative AI under strict policy. 39% report informal use with no policy whatsoever. That's shadow AI, measured.
  • Why point-in-time assessments aren't governance. The most common governance activity is periodic assessment and penetration testing (30%), while just 16% monitor continuously. Snapshots don't catch drift, and the agentic fabric on an endpoint changes daily.
  • Where the AI supply chain risk actually sits. 69% now run third-party AI risk assessments, yet 47% still trust vendors to manage their own AI risk without auditing them. For MCP servers and agent Skills installed directly onto an endpoint, that trust is the exposure.
  • What leaders believe versus what practitioners live with. 50% of leaders report a formal AI risk program; only 36% of practitioners agree, using identical wording. Governance the people doing the work can't see isn't governing much.

The gap this survey ranks first - visibility into where AI runs and what it can reach - is the problem Backslash was built to close.

Backslash discovers every AI agent, MCP server, and Skill running on your endpoints, surfaces the risk each one carries, enforces policy automatically, and blocks risky actions in real time. Continuously, not periodically.

The survey found the gap. Find yours.

Get the SANS Survey →