80% of Organisations Are Worried About AI Data Leaks. Most Aren’t Doing Anything About It.

If you care about 80% of Organisations Are Worried, this is the story you need to read today. Something’s gone wrong with how we’re handling AI security, and the numbers are staring us in the face.

I was reading through Mimecast’s State of Human Risk 2026 report this morning, and there’s a stat that stopped me cold: 80% of organisations are concerned about sensitive data leaking through generative AI tools. Eighty percent. That’s almost everyone.

Now here’s the kicker. Only 40% report being fully prepared with specific strategies for AI-driven threats. That’s a 40-point gap between knowing there’s a problem and actually doing something about it. It’s like knowing your house is on fire but only half the residents have bothered to buy a fire extinguisher.

The report surveyed 2,500 IT security and decision-makers across nine countries, and the findings are brutal. 69% of security leaders say AI-powered attacks are inevitable within the next 12 months. Yet 60% are not fully prepared. We can see the train coming, but nobody’s getting off the tracks.

When Theory Meets Reality

If you think this is just numbers on a page, consider what happened at NYC Health + Hospitals last week. The largest public healthcare system in the United States disclosed a breach affecting 1.8 million people. Hackers had access for three months, from November 2025 to February 2026, and they walked away with medical records, Social Security numbers, and here’s the scary part, fingerprints and palm prints.

Think about that for a second. You can change your password. You can cancel a credit card. But you cannot change your fingerprints. Those 1.8 million people will carry that exposure for the rest of their lives.

The breach came through a third-party vendor, which is exactly the kind of supply chain vulnerability that AI tools are making easier to exploit. When you’re rushing to deploy AI across your organisation, every integration point becomes a potential attack vector.

The AI Vulnerability Explosion

It’s not just Mimecast sounding the alarm. Cycode’s research shows that publicly reported AI security incidents increased by 56.4% from 2023 to 2024, and the trend hasn’t slowed. Their analysis of the top AI security vulnerabilities in 2026 paints a worrying picture:

  • Prompt injection remains the number one attack vector, with a critical CVE (CVSS 9.6) enabling remote code execution through hidden prompts in GitHub Copilot.
  • 81% of security teams lack visibility into how AI is used in their own codebases. You can’t protect what you can’t see.
  • 45% of AI-generated code contains vulnerabilities. That’s nearly half the code being pushed by tools developers trust.
  • Shadow AI (unauthorised AI tool usage) affects 76% of organisations and adds an average of $670,000 to breach costs.

What This Means for You

If you’re running a business, here’s what you need to do right now:

1. Inventory your AI tools. Find out what’s being used across your organisation, including the unofficial stuff. If your team is using ChatGPT on personal accounts for work tasks, that’s Shadow AI, and it’s a data leak waiting to happen.

2. Audit your AI-generated code. If your developers are using Copilot, Claude, or any AI coding assistant, you need a review process. That 45% vulnerability rate isn’t a theoretical risk, it’s a code review backlog.

3. Review your vendor access. NYC Health + Hospitals got hit through a third-party vendor. Every external tool and service that touches your systems is a potential entry point.

4. Implement least-privilege access for AI agents. If you’ve deployed AI agents (and according to Gartner, 40% of enterprise apps will have them by end of 2026), make sure they can only do what they absolutely need to do. 80% of IT workers have already witnessed unauthorised agent actions.

5. Train your people. The report found that only 28% of organisations combine security awareness training with continuous monitoring. Training alone isn’t enough. Monitoring alone isn’t enough. You need both.

The Bottom Line

We’re in a weird moment where everyone can see the problem but almost nobody is moving fast enough to fix it. AI is simultaneously the biggest security risk and the most promising security tool. The organisations that figure out how to manage that paradox are going to be fine. The rest are going to end up in next quarter’s breach statistics.

The gap between knowing you have a security problem and actually fixing it is where attackers live. Right now, that gap is 40 percentage points wide, and it’s growing. Stop reading about it and start doing something about it.


Related Reading

Subscribe

Related articles

FLUX 3: How Black Forest Labs Is Bridging Video AI and Real-World Robots

Black Forest Labs' FLUX 3 is expanding from video and image generation into robot control for Audi factories, with an open-weight model planned for factory hardware.

AI Found 12 Zero-Days in OpenSSL. Humans Found Zero.

A startup's AI system discovered all 12 new zero-day vulnerabilities in OpenSSL's January 2026 security release, demonstrating that AI can now find real flaws in the most scrutinised code on the planet.

Black Forest Labs stretches FLUX 3 from video to factory robots

Black Forest Labs opens early access to FLUX 3, a visual intelligence model for video and audio generation, and introduces FLUX-mimic for industrial robot control.

Australia Sets Rules for AI. The Hard Part Comes Next.

Australian writers, musicians and journalists will keep ownership of...

The Open Source AI Revolution: When the World’s Biggest Models Became Free

Chinese open-source AI models led by Moonshot Kimi K3 have functionally closed the gap with proprietary systems from OpenAI and Anthropic, with profound consequences for geopolitics, global markets, and the future of autonomous AI agents.