New research highlights urgent need for data governance as enterprise AI grows

Applications of AI


“What this research shows is that AI adoption in enterprises is not only accelerating, but fragmenting,” said Nishant Doshi, CEO of Cyberhaven. “While a small number of teams are moving quickly and deeply embedding AI into daily operations, security and governance are often catching up.As organizations plan for 2026 and beyond, the risk is not the AI itself, but how it is actually used. Without visibility into what tools are running, what data is flowing through them, and where controls need to be applied, companies risk widening the gap between innovation and trust.”

This report reveals the following key findings regarding enterprise AI adoption and usage:

1. AI implementation gap has become apparent
The adoption and use of AI is not unfolding in steady waves across industries. In fact, polarization is increasing.

  • The gap between early adopters of AI and organizations that remain hesitant to adopt AI technology is widening.
  • The top 1% of early adopter organizations use over 300 GenAI tools.
  • In contrast, prudent companies typically employ fewer than 15 GenAI tools.

2. Most GenAI SaaS tools are objectively risky, with the average employee entering sensitive data into an AI tool once every three days.
Much of today’s AI use is done in tools that don’t meet traditional enterprise risk standards, yet employees continue to enter sensitive data into tools at high frequency.

  • Of the top 100 most popular GenAI SaaS applications, 82% are classified as medium, high, or critical risk.
  • According to data from Cyberhaven Labs, 32.3% of ChatGPT usage occurs through personal accounts, as does 24.9% of Gemini usage.
  • 39.7% of all data movements to AI tools involve sensitive data such as prompts and copy-paste operations.
  • This behavior significantly limits an organization’s visibility into AI usage and data flows.

3. Coding assistants and AI agents are becoming the “second wave” of workplace AI.
AI coding assistants (Cursor, GitHub Copilot, Claude Code, etc.) continued to grow steadily through 2025.

  • At companies leading AI adoption, nearly 90% of developers use these tools, while adoption rates in typical organizations are closer to 50%.
  • Meanwhile, only 6% of developers use AI coding assistants. This shows that the gap in AI adoption is widening, with developers at frontier companies now 11.5 times more likely to use AI coding assistants.
  • In the second half of 2025, 30% of developers using AI coding assistants reported using at least two.

As enterprise AI adoption continues to accelerate; Cyberhaven Labs 2026 AI Adoption and Risk Report This highlights the widening gulf between innovation and surveillance. AI adoption is becoming uneven across organizations, teams, and workflows, with the highest levels often being deployed in environments with the least mature governance and visibility.

“AI is no longer a side experiment for most enterprises, but is becoming a core part of their infrastructure,” Doshi added. “Successful organizations are those that go beyond one-size-fits-all policies and invest in a security approach that reflects real-world usage patterns. By bringing together visibility, context, and control, enterprises can empower their teams to innovate with AI while maintaining trust, compliance, and resilience as deployments continue to evolve.”

See the full report findings here.

These findings will be discussed live in today’s webinar from Harvard Business Review Analytics Services. The seminar will feature conversations with HBR-AS Managing Director Alex Clemente, Cyberhaven CEO Nishant Doshi, and Datavant CISO Dan Walsh. register here.

Earlier this week, Cyberheaven announced the following: General availability of data security posture management solution that is a key part of a unified AI and data security platformdesigned to protect sensitive data wherever it resides, including endpoints, SaaS, cloud, on-premises environments, and AI workflows.

About Cyber ​​Heaven
Cyberhaven protects sensitive data no matter where it resides, no matter where it resides. Built for the AI ​​era, Cyberhaven’s unified data security platform combines DSPM, data loss prevention, insider risk management, and AI security with deep data lineage and agent AI. Cyberhaven helps organizations stop data loss, reduce insider risk, and securely enable AI deployments without slowing down the business. For more information, please visit www.cyberhaven.com.

Media contact:
[email protected]

Source: Cyberheaven



Source link