AI Confidence vs Cyber Reality: Why companies may be underestimating their biggest security blind spot

AI cybersecurity concept showing executive confidence contrasted with a security operations centre monitoring digital threats
The growing gap between AI confidence in the boardroom and cybersecurity realities on the ground.

Companies are rapidly adopting artificial intelligence, but a new cybersecurity survey suggests that confidence at the top of the organisation may not always match what security and IT teams are experiencing on the ground.

The findings from DNSFilter’s 2026 Visibility Deficit cybersecurity survey point to a widening gap between executives and the professionals responsible for protecting corporate systems. The disconnect is particularly visible around business continuity, AI enabled attacks, Shadow AI and the governance of autonomous AI agents.

The survey, conducted in June 2026 among 400 IT and cybersecurity professionals at manager level and above, covered companies with 150 to 5,000 employees across North America.

The confidence gap

The sharpest difference appears when organisations are asked whether they could keep critical operations running during a major cyberattack.

Nearly three quarters, or 73.9% of executives, believe their organisation could maintain critical operations through a 72 hour cyberattack. But that confidence falls to 47.5% among IT management and 50% among cybersecurity professionals.

That gap matters because the latter groups are closer to the systems, infrastructure and security incidents that determine whether an organisation can actually withstand an attack.

The survey also found a significant difference in perceptions around incidents going unreported. While 45.8% of IT managers said their organisations had experienced unreported security incidents, only 17.4% of executives believed this was happening.

Limited detection capability was another concern. 52% of IT management said incidents had been downplayed because of limited detection capabilities, compared with 39.1% of executives who acknowledged the same.

AI is changing the threat equation

The disconnect is not limited to conventional cybersecurity.

Between 69% and 71% of IT management and network and cloud professionals said attackers are adopting AI faster than their own organisations can keep pace. Among executive leaders, the figure was only 43%.

In fact, 26% of executives said their own teams were ahead of attackers in AI adoption.

The difference also extends to which AI tools organisations consider risky. While 65% of executives identified ChatGPT as a top AI risk, security practitioners reported a broader threat surface involving tools and models such as DeepSeek, Kimi K2 and Mistral.

This suggests that the challenge for companies is no longer simply deciding whether employees should use generative AI. The larger challenge is understanding which AI tools are being used, how they connect to corporate systems and what information they can access.

Shadow AI is becoming a bigger problem

One of the most important findings concerns Shadow AI, or the use of AI tools without adequate organisational visibility or approval.

DNSFilter found that 40% of organisations had experienced a security incident linked to a third party SaaS or AI tool during the previous 12 months.

The problem was particularly pronounced among organisations using six to 10 AI tools. Their Shadow AI incident rate stood at 32.5%, compared with 20.1% overall.

In addition, 20% of organisations said an unauthorised AI connection had directly caused a security incident.

The visibility problem is even more pronounced because organisations do not always know when new AI connections are being established. More than a third, 36.8%, said IT is notified only after access has already been granted, while 6.5% said there was no notification at all.

More spending does not automatically mean better protection

Cybersecurity budgets are rising. 74.5% of respondents said their budgets had increased over the previous year.

But executives and practitioners are not necessarily prioritising the same areas.

Executives identified AI security governance as their biggest investment priority, at 52.2%, followed by network security at 26.1%.

Security practitioners, meanwhile, wanted greater investment in endpoint detection, security training and incident response.

Interestingly, AI governance was simultaneously identified as the largest security gap by 36.25% of respondents and the top investment priority by 40.25%.

That suggests that simply allocating more money towards AI governance may not be enough. Companies also need better visibility into how AI is actually being used inside their environments.

Autonomous AI creates another governance challenge

The next layer of risk could come from AI agents that can perform tasks with limited human intervention.

DNSFilter found that only 49% of organisations have formal and consistently enforced policies governing autonomous AI agents.

That creates a potential gap between the speed at which agentic AI is being introduced and the controls designed to monitor its access, permissions and behaviour.

The issue is particularly important because an AI agent can potentially interact with corporate applications, data and workflows in ways that traditional employee focused security policies were not designed to handle.

The bigger issue is visibility

The survey does not suggest that executives are unconcerned about cybersecurity. Instead, it highlights a difference in what executives believe is happening and what security teams are observing.

That distinction could become increasingly important as companies deploy more AI tools and autonomous agents.

For businesses, the challenge is therefore moving beyond simply having an AI policy. They need to know where AI is being used, what systems it can access, whether those connections are authorised and how quickly security teams can detect unusual activity.

As AI becomes embedded deeper into enterprise infrastructure, the biggest cybersecurity blind spot may not be a lack of investment. It could be the gap between what organisations think they can see and what is actually happening inside their networks.

Source: DNSFilter, 2026 Visibility Deficit cybersecurity survey. The survey covered 400 IT and cybersecurity professionals at manager level and above, at companies with 150 to 5,000 employees across North America, and was conducted in June 2026.

5 Key Takeaways From The Survey
01

73.9% vs 47.5%
A Major Confidence Gap

Nearly three quarters of executives believe their organisations can withstand a 72-hour cyberattack, compared with 47.5% of IT managers and 50% of cybersecurity professionals.

02

40%
Shadow AI Is Creating Real Incidents

40% of organisations reported a security incident linked to a third-party SaaS or AI tool, while 32.5% of the largest AI-using organisations reported Shadow AI incidents.

03

69%–71%
Attackers May Be Moving Faster

Between 69% and 71% of IT, network and cloud professionals believe attackers are adopting AI faster than their organisations can keep up.

04

49%
AI Governance Remains Incomplete

Only 49% of organisations have formal and consistently enforced policies governing autonomous AI agents.

05

74.5%
More Spending Hasn’t Closed The Gap

74.5% said cybersecurity budgets increased, yet AI governance remains the largest reported security gap at 36.25% and the top investment priority at 40.25%.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    Your email address will not be published. Required fields are marked *