Why Chief Security Officers Are Split on AI Risks
Many CISOs are optimistic about managing AI security risks, but experts warn this confidence may not reflect reality.

Key points
- 41% of 113 CISOs surveyed in 2025 feel optimistic about AI security risks.
- Optimism linked to leadership support, not technical controls.
- Analysts warn of a gap between perceived and actual security readiness.
How do security leaders feel about AI risks? In a survey conducted by IANS Research, 41% of chief information security officers (CISOs) expressed optimism about handling AI security risks over the next two years, while 38% felt pessimistic. The survey, first reported by ThreatVectr, highlights a nearly even split in confidence among these security leaders.
Why does optimism vary?
The factors that make CISOs feel optimistic are not about technology. Instead, confidence grows when senior leadership understands AI risks, someone in the organization is responsible for AI governance, the CISO controls the security budget, AI tools are used effectively, and staffing is adequate. The survey shows that confidence hinges on organizational support rather than the maturity of existing security measures.
Should that confidence be trusted?
Analysts advise caution. Rock Lambros from Zenity notes that respondents might rate their programs highly, skewing the results. Sanchit Vir Gogia of Greyhound Research emphasizes that leadership support and budget control do not guarantee that AI systems are secure. Justin Greis from Acceligence questions the optimism, noting that many CISOs face significant challenges with AI security.
What are the real gaps?
Pearl Almeida from Info-Tech Research Group identifies two major issues. First, many leaders cannot explain how AI agents work, which hampers their ability to assess risks accurately. Second, governance that is added after processes are established is less effective. Brian Levine of FormerGov points out a third concern: the risks from AI tools integrated into vendor software, which are often overlooked.
Common questions
Does this affect ordinary employees or customers?
Yes, indirectly. If companies use AI tools hastily without proper controls, it increases the risk of errors and data breaches affecting customer and employee information.
What should organizations actually do right now?
Experts recommend identifying all AI tools in use, including those in vendor products, understanding what data they access, and assigning someone with real authority to oversee each tool.



