If you care about 80% of Organisations Are Worried, this is the story you need to read today. Something’s gone wrong with how we’re handling AI security, and the numbers are staring us in the face.
I was reading through Mimecast’s State of Human Risk 2026 report this morning, and there’s a stat that stopped me cold: 80% of organisations are concerned about sensitive data leaking through generative AI tools. Eighty percent. That’s almost everyone.
Now here’s the kicker. Only 40% report being fully prepared with specific strategies for AI-driven threats. That’s a 40-point gap between knowing there’s a problem and actually doing something about it. It’s like knowing your house is on fire but only half the residents have bothered to buy a fire extinguisher.
The report surveyed 2,500 IT security and decision-makers across nine countries, and the findings are brutal. 69% of security leaders say AI-powered attacks are inevitable within the next 12 months. Yet 60% are not fully prepared. We can see the train coming, but nobody’s getting off the tracks.
When Theory Meets Reality
If you think this is just numbers on a page, consider what happened at NYC Health + Hospitals last week. The largest public healthcare system in the United States disclosed a breach affecting 1.8 million people. Hackers had access for three months, from November 2025 to February 2026, and they walked away with medical records, Social Security numbers, and here’s the scary part, fingerprints and palm prints.
Think about that for a second. You can change your password. You can cancel a credit card. But you cannot change your fingerprints. Those 1.8 million people will carry that exposure for the rest of their lives.
The breach came through a third-party vendor, which is exactly the kind of supply chain vulnerability that AI tools are making easier to exploit. When you’re rushing to deploy AI across your organisation, every integration point becomes a potential attack vector.
The AI Vulnerability Explosion
It’s not just Mimecast sounding the alarm. Cycode’s research shows that publicly reported AI security incidents increased by 56.4% from 2023 to 2024, and the trend hasn’t slowed. Their analysis of the top AI security vulnerabilities in 2026 paints a worrying picture:
- Prompt injection remains the number one attack vector, with a critical CVE (CVSS 9.6) enabling remote code execution through hidden prompts in GitHub Copilot.
- 81% of security teams lack visibility into how AI is used in their own codebases. You can’t protect what you can’t see.
- 45% of AI-generated code contains vulnerabilities. That’s nearly half the code being pushed by tools developers trust.
- Shadow AI (unauthorised AI tool usage) affects 76% of organisations and adds an average of $670,000 to breach costs.
What This Means for You
If you’re running a business, here’s what you need to do right now:
1. Inventory your AI tools. Find out what’s being used across your organisation, including the unofficial stuff. If your team is using ChatGPT on personal accounts for work tasks, that’s Shadow AI, and it’s a data leak waiting to happen.
2. Audit your AI-generated code. If your developers are using Copilot, Claude, or any AI coding assistant, you need a review process. That 45% vulnerability rate isn’t a theoretical risk, it’s a code review backlog.
3. Review your vendor access. NYC Health + Hospitals got hit through a third-party vendor. Every external tool and service that touches your systems is a potential entry point.
4. Implement least-privilege access for AI agents. If you’ve deployed AI agents (and according to Gartner, 40% of enterprise apps will have them by end of 2026), make sure they can only do what they absolutely need to do. 80% of IT workers have already witnessed unauthorised agent actions.
5. Train your people. The report found that only 28% of organisations combine security awareness training with continuous monitoring. Training alone isn’t enough. Monitoring alone isn’t enough. You need both.
The Bottom Line
We’re in a weird moment where everyone can see the problem but almost nobody is moving fast enough to fix it. AI is simultaneously the biggest security risk and the most promising security tool. The organisations that figure out how to manage that paradox are going to be fine. The rest are going to end up in next quarter’s breach statistics.
The gap between knowing you have a security problem and actually fixing it is where attackers live. Right now, that gap is 40 percentage points wide, and it’s growing. Stop reading about it and start doing something about it.
