Logicalis-CIO-Report-2026 - Flipbook - Page 22
ma nag in g s ec u r i ty i n t h e a i e ra
believe it has reduced their organisation’s
ability to detect breaches and cyberattacks effectively (35%). More concerning
still, two in 昀椀ve report that incident
response times have worsened (41%).
These are early warning signals. AI is
increasing complexity inside security
62% admit they
compromise on AI
governance standards due
to limited knowledge or
capability
operations faster than processes, skills
and tools are adapting. Systems are
becoming harder to observe, harder to
interpret and harder to control with con昀椀dence.
That is not a failure of intent. It is a sign
that AI governance is running ahead of
institutional capacity.
Just 37% of CIOs say they
have full visibility of the
AI tools and services in
use
The data reveals a structural imbalance.
Ownership of AI is distributed across the
organisation, but accountability for its
consequences is increasingly concentrated with the CIO.
This makes AI risk different from most
Logica Lis gLoBa L cio R EPo RT 2026
previous technology risks. It is not just
22
Most organisations recognise the need
technical. It is organisational. It sits in the
for AI-speci昀椀c governance, and almost all
gaps between roles, teams, and decision
report having some form of it in place but
rights.
only around a third of CIOs are extremely
con昀椀dent that their AI governance
Vendor dependence adds another layer
controls can keep pace with deployment
of fragility. Many organisations acknowl-
(34%), and just over a third believe they
edge that they are increasingly reliant
have full visibility of all the AI tools and
on a small number of AI providers for
services in use across their organisation
critical functions (59%). At the same time,
(37%).
concern about an “AI bubble” is widespread (67%), re昀氀ecting unease about the
Even more revealing is the degree of
market’s stability and maturity. Despite
compromise. Nearly two-thirds (62%)
this, a signi昀椀cant proportion still lack
admit relaxing governance standards due
continuity plans should a key provider
to limited understanding or capability.
become unavailable (16%).