How This Benchmark Is Compiled
Transparency about what is measured, what is estimated, and where every number comes from.
What This Benchmark Is
The 2026 State of Enterprise AI Security Benchmark is a curated synthesis of published industry research on shadow AI, AI governance, and AI data security. It is not a primary survey. Aona AI compiles and presents the strongest available public data so security leaders can see the state of the field in one place.
Every figure that names a source comes directly from that published report. Figures without a named source are illustrative estimates modeled on the trends those reports describe; they exist to show the shape of the problem and should not be cited as research findings.
Primary Sources
AI governance policy gaps, AI access control failures, added breach costs from shadow AI.
Enterprise AI activity growth and AI/ML data transfer volumes.
Bring-your-own-AI (BYOAI) prevalence among AI users at work.
Employees entering non-public company information into generative AI tools.
Share of generative AI adopters using unapproved tools at work.
What Comes Next: The 2026 Shadow AI Index
The next edition of this benchmark replaces estimates with measured data: anonymized, aggregated telemetry from the Aona platform, which continuously profiles 5,600+ AI tools, together with real customer outcomes.
The result will be a recurring, citable index with a transparent method, published on this site. Until then, treat unattributed figures on this site as directional illustrations, not measurements.
Questions about sources or methodology? Contact research@aona.ai. Research curation by Aona AI.