A new global risk report has revealed a widening gap between artificial intelligence adoption and the governance structures needed to control it, posing significant cyber security and resilience concerns for organisations in 2025.
According to The 2025 New Generation of Risk Report, only 12% of organisations feel “very prepared” to assess, manage and recover from AI and AI governance risks, despite widespread deployment of generative and emerging agentic AI technologies across enterprise environments.
For Zensec, the findings reinforce a growing concern. AI is rapidly becoming an unmanaged attack surface.
AI adoption is accelerating but oversight is not
The report shows that nearly 60% of organisations are considering incorporating agentic AI solutions into operations or products. Yet more than half of those have not assessed the associated risks.
More concerning still:
-
42% have no formal policy governing employee AI use
-
72% lack policies governing AI use by partners and suppliers
-
75% do not have a dedicated plan to address generative AI risks
-
26% report taking no meaningful action on AI risk at all
This governance gap exists at a time when AI-driven fraud, deepfakes, automated decision-making errors and data leakage risks are increasing in both scale and sophistication.
For cyber security leaders, this signals a critical imbalance. Innovation is moving faster than internal controls.
Shadow AI is creating blind spots
The report also highlights a growing disconnect between leadership and operational teams. A higher proportion of senior executives report not considering agentic AI deployment compared to managers and directors, suggesting AI tools may be entering organisations through informal or unsanctioned channels.
Often referred to as “shadow AI”, this trend creates significant blind spots in data governance, compliance and cyber defence strategies. If organisations do not have visibility of where AI tools are being used, they cannot effectively secure them.
For many businesses, this is no longer a theoretical risk. It is an operational one.
Geopolitics and cyber risk are converging
AI risk is emerging alongside rising geopolitical volatility. The report finds that 62% of risk leaders believe restrictive trade policies or geopolitical conflict could increase exposure to state-sponsored cyberattacks.
With political risk now ranked among the top corporate threats globally, cyber security is increasingly intertwined with economic and international instability. Nation-state actors are expected to exploit digital supply chains, third-party vulnerabilities and AI systems as part of broader strategic conflict.
In this environment, cyber resilience is not just a technical concern. It is a board-level priority.
Preparedness remains worryingly low
Beyond AI, the findings paint a broader picture of underpreparedness:
-
Only 9% feel very prepared for unknown or unpredictable risk events
-
Just 17 to 18% feel very prepared for political or geopolitical risks
-
Third-party visibility remains limited, with only a small minority able to assess risks beyond Tier 1 suppliers
At the same time, risk budgets have largely stagnated despite rising threat complexity.
The imbalance is clear. Risk awareness is increasing, but resilience investment is not keeping pace.
Zensec’s view
For Zensec, the report underscores an urgent priority for organisations across the UK. AI must be treated as a core enterprise risk and governed with the same rigour as cyber security, compliance and operational resilience.
This requires:
-
Clear AI governance frameworks
-
Active monitoring of shadow AI usage
-
Third-party and supply chain cyber risk assessments
-
Scenario planning for AI-enabled threat events
-
Security embedded into AI deployment from the outset
AI has the potential to deliver major efficiency and innovation gains. However, without structured oversight, it also introduces new vectors for breach, manipulation, fraud and operational disruption.
The message from 2025’s risk landscape is straightforward. Innovation without governance creates exposure.







