IT teams are bullish on AI tools, but they’re worried security practices can’t keep pace
Executives and IT teams are at odds over the risks associated with AI adoption
IT teams are growing increasingly concerned about AI-related risks amidst continued adoption, according to new research.
Findings from Heimdal’s State of AI Risk Management in 2026 report show AI tools are now commonplace across most IT estates, with teams often running several at one.
ChatGPT, for example, runs in nearly three-quarters (71%) of UK IT environments, while Microsoft Copilot is present in 68%. These same figures are reflected across the Atlantic, with US-based IT teams often using a combination of multiple different AI solutions.
AI tools are playing a key role in reducing workloads, the study noted, which IT teams highlighted as the most positive benefits of the technology.
Nearly three-quarters of IT and security teams said they lose around a quarter of their week to “repetitive, low-value work” - and AI is helping reduce that manual toil.
Indeed, teams facing the highest levels of operational load are often ranked among the most optimistic when it comes to AI. More than half (59%) of US teams said they expect AI to alleviate pressure, while 55% in the UK expect the same.
AI-related risks are haunting IT teams
Despite this optimism, a key recurring concern among IT leaders is that controls and security capabilities haven’t kept pace with the rate of adoption. Heimdal noted that only four-in-ten teams rate their security stack as “ready for AI-related risk”.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Teams are increasingly concerned about data leakage, for example, with 56% of UK respondents highlighting this risk. Visibility is a major issue in this regard, Heimdal found.
UK teams with full visibility into AI use were most likely to flag data leakage as a leading concern, compared to just 27% of those with no visibility. In the US, 59% of teams with full visibility also highlighted data leakage as a key concern.
While concerns over potential risks typically mount as AI tools are integrated, Heimdal noted that unauthorized AI use, or ‘shadow AI’, is also a recurring problem for enterprises.
Heimdal specifically highlighted the Salesloft Drift breach in August 2025 as a key example of how poor AI-related visibility can impact organisations.
The incident saw threat actors steal OAuth tokens for Drift’s AI chatbot integration with Salesforce, using these to extract data from several hundred Salesforce instances.
A host of organisations, including Cloudflare, Palo Alto Networks, and Zscaler were impacted in the attacks.
“Drift was the AI tool. Salesforce held the data,” the company noted in a blog post.
“Most of the affected teams had never personally provisioned Drift,” it added. “A third-party AI chatbot, plugged in through an OAuth grant few had recently reviewed, became the way in.”
Contrasting priorities
Perception of AI-related risk among frontline practitioners and executives is a major problem, according to Heimdal. Indeed, “executive confidence” in AI security is a repeated point of friction when it comes to governance and risk management.
In the US, for example, 29% of executives said AI risk is under control, yet just 7% of practitioners agreed. In the UK, meanwhile, these figures stand at 18% against 11%.
Adam Pilton, cybersecurity advisor at Heimdal, said this shows many organizations still aren’t fully aligned on how they manage AI risk.
"Misplaced confidence is one of the most dangerous things in security. This data shows executives are far more confident that AI risk is under control than the evidence supports. Most of the conversation right now is about productivity, when the bigger question is how AI can be turned against the business,” he said.
“The report shows the gap between how secure leaders feel and how secure they actually are.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Broadcom eyes security, performance boosts with vDefend and Avi Load Balancer updatesNews Enhancements to VMware vDefend and VMware Avi Load Balancer use AI-powered automation to help secure private cloud environments
-
How business leaders are using the Dell Pro 7 and Dell Pro 5Sponsored Thanks to flexibility and a range of spec options, the Dell Pro 7 and Pro 5 laptops can suit a variety of business leaders across a mix of workplaces
-
Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agentsInter-agent collaboration is a serious cause for concern, says security expert
-
Anthropic joins OpenAI in admitting loss of control in cybersecurity testsThe company found Claude AI had escaped containment three times and targeted other organizations
-
'It delivers world-class performance at 50 percent of the cost of leading models': Microsoft unveils cut-price AI for security with latest in-house model launchNews Pairing the MAI security model with GPT-5.4 gives benchmark leading results at half the cost, according to the tech giant
-
The case for the channel in an AI-driven security marketIndustry Insights AI won't replace channel partners; SMB cybersecurity still relies on trust
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
Cyber professionals are flocking to AI tools, but they’re getting tired of fixing mistakes and reviewing outputsNews Cyber pros are spending significantly more time validating AI outputs and deciding when to trust AI-generated recommendations
-
'It’s a marker of where extortion tradecraft is heading': Cyber experts say they've identified the first case of ‘agentic ransomware’ – but there’s a catchNews While the JadePuffer ransomware has alarm bells ringing, it still needed a human in the loop
-
Three quarters of firms have halted AI projects over safety and security concerns – and cyber pros think things will deteriorate as models like Claude Mythos improveNews AI has become a leading problem for enterprise security teams, they can't automate their way out of trouble