IT teams are bullish on AI tools, but they’re worried security practices can’t keep pace
Executives and IT teams are at odds over the risks associated with AI adoption
IT teams are growing increasingly concerned about AI-related risks amidst continued adoption, according to new research.
Findings from Heimdal’s State of AI Risk Management in 2026 report show AI tools are now commonplace across most IT estates, with teams often running several at one.
ChatGPT, for example, runs in nearly three-quarters (71%) of UK IT environments, while Microsoft Copilot is present in 68%. These same figures are reflected across the Atlantic, with US-based IT teams often using a combination of multiple different AI solutions.
AI tools are playing a key role in reducing workloads, the study noted, which IT teams highlighted as the most positive benefits of the technology.
Nearly three-quarters of IT and security teams said they lose around a quarter of their week to “repetitive, low-value work” - and AI is helping reduce that manual toil.
Indeed, teams facing the highest levels of operational load are often ranked among the most optimistic when it comes to AI. More than half (59%) of US teams said they expect AI to alleviate pressure, while 55% in the UK expect the same.
AI-related risks are haunting IT teams
Despite this optimism, a key recurring concern among IT leaders is that controls and security capabilities haven’t kept pace with the rate of adoption. Heimdal noted that only four-in-ten teams rate their security stack as “ready for AI-related risk”.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Teams are increasingly concerned about data leakage, for example, with 56% of UK respondents highlighting this risk. Visibility is a major issue in this regard, Heimdal found.
UK teams with full visibility into AI use were most likely to flag data leakage as a leading concern, compared to just 27% of those with no visibility. In the US, 59% of teams with full visibility also highlighted data leakage as a key concern.
While concerns over potential risks typically mount as AI tools are integrated, Heimdal noted that unauthorized AI use, or ‘shadow AI’, is also a recurring problem for enterprises.
Heimdal specifically highlighted the Salesloft Drift breach in August 2025 as a key example of how poor AI-related visibility can impact organisations.
The incident saw threat actors steal OAuth tokens for Drift’s AI chatbot integration with Salesforce, using these to extract data from several hundred Salesforce instances.
A host of organisations, including Cloudflare, Palo Alto Networks, and Zscaler were impacted in the attacks.
“Drift was the AI tool. Salesforce held the data,” the company noted in a blog post.
“Most of the affected teams had never personally provisioned Drift,” it added. “A third-party AI chatbot, plugged in through an OAuth grant few had recently reviewed, became the way in.”
Contrasting priorities
Perception of AI-related risk among frontline practitioners and executives is a major problem, according to Heimdal. Indeed, “executive confidence” in AI security is a repeated point of friction when it comes to governance and risk management.
In the US, for example, 29% of executives said AI risk is under control, yet just 7% of practitioners agreed. In the UK, meanwhile, these figures stand at 18% against 11%.
Adam Pilton, cybersecurity advisor at Heimdal, said this shows many organizations still aren’t fully aligned on how they manage AI risk.
"Misplaced confidence is one of the most dangerous things in security. This data shows executives are far more confident that AI risk is under control than the evidence supports. Most of the conversation right now is about productivity, when the bigger question is how AI can be turned against the business,” he said.
“The report shows the gap between how secure leaders feel and how secure they actually are.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Copilot Cowork is now generally availableNews A host of partner plugins are already available for Copilot Cowork, and more are coming
-
Westcon-Comstor eyes new growth with General Atlantic investmentNews The strategic agreement introduces the investment firm as a minority shareholder and financing partner as the distributor targets further expansion
-
‘These sorts of post-compromise techniques used to be restricted to actors with the technical knowledge to carry them out’: Anthropic warns AI is helping lower the bar for up-and-coming hackersNews AI is making it harder to differentiate between high and low-skilled actors
-
AI is shrinking attack windows, and it’s forcing a complete rethink of cyber resilience – here’s how organizations can prepareNews Commvault has urged companies to improve their business continuity and resilience plans in the face of flaws spotted by AI
-
Google says AI is now being used to build zero-days – and we just narrowly avoided a 'mass exploitation event'News Google cyber researchers think they’ve found the first AI-generated zero-day exploit
-
UK firms left in the dark over what workers are sharing with AINews Security teams can’t keep track of what workers are sharing with AI applications, regardless of whether they’re approved or unauthorized
-
AI is now a ‘standard part of the attacker toolkit’News Cyber attacks are increasing in scale, intensity, and velocity thanks to AI, and it’s forcing defenders to react faster than ever before
-
AI is raising the stakes for cyber professionals – Claude Mythos just took things to another levelNews AI efficiency gains work both ways, and threat actors are already capitalizing on powerful new tools