AI Security Benchmark
Methodology

How This Benchmark Is Compiled

Transparency about what is measured, what is estimated, and where every number comes from.

What This Benchmark Is

The 2026 State of Enterprise AI Security Benchmark is a curated synthesis of published industry research on shadow AI, AI governance, and AI data security. It is not a primary survey. Aona AI compiles and presents the strongest available public data so security leaders can see the state of the field in one place.

Every figure that names a source comes directly from that published report. Figures without a named source are illustrative estimates modeled on the trends those reports describe; they exist to show the shape of the problem and should not be cited as research findings.

Primary Sources

IBM Cost of a Data Breach Report 2025

AI governance policy gaps, AI access control failures, added breach costs from shadow AI.

Zscaler ThreatLabz AI Security Report 2026

Enterprise AI activity growth and AI/ML data transfer volumes.

Microsoft & LinkedIn Work Trend Index 2024

Bring-your-own-AI (BYOAI) prevalence among AI users at work.

Cisco Data Privacy Benchmark Study 2024

Employees entering non-public company information into generative AI tools.

Salesforce generative AI research 2024

Share of generative AI adopters using unapproved tools at work.

What Comes Next: The 2026 Shadow AI Index

The next edition of this benchmark replaces estimates with measured data: anonymized, aggregated telemetry from the Aona platform, which continuously profiles 5,600+ AI tools, together with real customer outcomes.

The result will be a recurring, citable index with a transparent method, published on this site. Until then, treat unattributed figures on this site as directional illustrations, not measurements.

Questions about sources or methodology? Contact research@aona.ai. Research curation by Aona AI.