The AI Oversight Gap: Why Compliance Alone Won’t Save You in 2026
Most boards believe they have contained their AI risk. IBM’s 2025 Cost of a Data Breach Report tells a different story. 97% of organisations that suffered an AI-related breach in the past year had no proper access controls on their AI systems. That is not a technology failure. It is a governance blind spot forming at the exact moment AI is being embedded into every business process.
The Problem
In 2025, the global cybersecurity narrative inverted. The average cost of a data breach fell for the first time in five years to $4.44 million globally, and £3.29 million in the UK, according to IBM’s Cost of a Data Breach Report 2025. AI-driven defences are finally moving the needle on detection and containment.
Beneath the headline, however, a far more alarming picture has emerged:
- 20% of breached organisations now report incidents tied to “shadow AI”, unsanctioned GenAI tools adopted by employees outside IT’s visibility (IBM, 2025).
- Shadow AI breaches cost an average of $4.63M, $670,000 more than standard incidents, and take 247 days to detect (IBM, 2025).
- 97% of AI-related breaches occurred in organisations with no proper access controls on their AI systems (IBM, 2025).
- 63% of breached organisations lack any formal AI governance policy entirely (IBM, 2025).
- 62% of organisations experienced a deepfake attack in the past 12 months (Gartner, 2025).
- In the UK, 43% of businesses reported a breach in the past year, rising to 74% of large enterprises (UK Government Cyber Security Breaches Survey, 2025).

The Gap: Why Organisations Are Failing
Three structural failures are converging at once.
1. Compliance is not resilience. NIS2 is now being enforced across EU member states, expanding scope to an estimated 160,000 entities across 18 sectors, up from 10,000 to 15,000 under the original directive, according to ENISA. Certification tells a regulator what you have. It does not tell your board how you perform when an AI-augmented adversary comes through the door.
2. The boardroom vacuum. According to the UK Government’s 2025 Cyber Security Breaches Survey, only 27% of UK businesses have a board member formally accountable for cyber security, down from 38% in 2021. AI risk is still being discussed as a technical issue at CIO level, while it is landing at board level as a financial, regulatory, and reputational one.
3. The skills mismatch. According to ISC2’s 2025 Cybersecurity Workforce Study, 59% of cybersecurity leaders now report critical or significant skills shortages, up from 44% in 2024, with AI (41%) and cloud security (36%) topping the list of most-needed capabilities. Meanwhile, 29% of organisations say they simply cannot afford the talent their own policies now require.
The Risk: Translated to the Board
- Financial. £3.29M average UK breach cost, plus a ~£525,000 shadow AI premium.
- Regulatory. Under NIS2 and DORA, essential entities face fines of up to €10 million or 2% of global turnover, with personal liability for senior management.
- Operational. Gartner reports that deepfake-enabled voice phishing (vishing) attacks surged over 1,600% in Q1 2025 alone. One successful CFO impersonation can bypass every control you certified to.
- Reputational. Gartner predicts that by 2026, 30% of enterprises will no longer trust standalone identity verification as a reliable control. The authentication stack most businesses rely on is on borrowed time.
The Shift
The winning posture for 2026 is no longer compliance-driven security. It is AI-governed cyber resilience. A posture that assumes AI is already inside your business (sanctioned or not), already inside your adversary’s toolkit, and already inside the regulation landing on your board next quarter.
The organisations pulling ahead share three traits:
- They treat AI governance as a board-level accountability, not an IT deliverable.
- They close the loop between certification and operational readiness through continuous testing.
- They solve for talent before frameworks because no policy survives contact with an understaffed team.
The Garzon Cyber Solutions Perspective
At Garzon Cyber Solutions, we work with CISOs, CIOs, and executive boards to close the AI oversight gap across three integrated pillars:
- Cybersecurity: Identifying where AI is already embedded in your business (shadow AI discovery, access controls, resilience testing).
- Compliance: Turning NIS2, DORA, ISO 27001, and the EU AI Act from paperwork into operational strength.
- Resourcing: Placing the specialist cyber and AI talent your policies now demand.
Compliance gets you through the audit. Resilience gets you through the attack. In 2026, the difference between the two will be measurable on your balance sheet and in your boardroom.
Sources
IBM, Cost of a Data Breach Report 2025
Gartner, “Why CIOs Cannot Ignore the Rising Tide of Deepfake Attacks,” September 2025
Gartner, Identity Verification Predictions, February 2024
UK Government, Cyber Security Breaches Survey 2025
ENISA, NIS2 Technical Implementation Guidance
ISC2, 2025 Cybersecurity Workforce Study
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →