Report: AI Containment Controls Lag Deployment
by
August 4, 2026
Given the recent high-profile examples of AI tools going rogue, it probably won’t come as a surprise to our readers that Kiteworks’ 2026 Data Security and Compliance Risk Report found that AI containment controls aren’t keeping pace with the deployment of AI tools. Even so, the report’s conclusions about the magnitude of the gap between deployment and containment efforts may raise a few eyebrows:
64% of organizations have already directly integrated AI into internal systems or are actively using external AI platforms; among those with AI deployed, 70% are running 3 or more distinct AI use cases in production simultaneously. AI-specific anomaly detection and behavioral monitoring is deployed by 31% of organizations (69% have none).
AI kill switch capability is deployed by 21% (79% have no automated mechanism to terminate a misbehaving AI agent). Human-in-the-loop review for high-risk AI actions is deployed by 30% (70% have no human checkpoint).
AI-specific DLP policies are deployed by 28% (72% have no technical control governing data flows into AI systems). Purpose binding for AI agents is deployed by 26% (74% do not restrict AI agents to authorized tasks and data scopes).
Board-level AI data governance reporting is present at 46% of organizations with AI systems deployed (30% of all organizations) — the highest-rated control.
23% of organizations with AI in production have never tested their AI agent termination capability — an untested kill switch is an assumption, not a control.
22% of organizations with AI deployed have had to revise, roll back, or restrict at least one AI deployment in the past 12 months due to data security concerns.
54% have no standing AI data governance agenda item at board level.
72% cannot trace AI outputs to the source data that produced them; 74% cannot log which AI model version produced a given output; 75% cannot reconstruct source records for a specific AI output on demand.
That’s not a pretty picture – and these are by no means the report’s only concerning findings. The report says that 80% of organizations were hit by a security or AI incident in the last 12 months, and that 63% of those incidents turned into a real compliance consequence — such as an audit finding, board escalation, or regulatory investigation. The report also highlights the fact that 62% of organizations are running sensitive data through fragmented, disconnected systems — MFT, email, file sharing, web forms — with no single point of control, and that this fragmentation may be root cause behind most of the report’s other findings.