By Evan Vega
A new industry report highlights a significant disconnect between executive confidence and technical reality regarding the governance of artificial intelligence systems, according to findings from Atlantic Insights and data-resilience firm Rubrik.
The report, titled “The Control Gap,” suggests that corporate leadership is often insulated from the operational complexities of AI security. In a survey of AI system control awareness, 80% of CEOs and board chairs reported confidence in their organization’s governance. In contrast, only 57% of CTOs and CIOs and 45% of Chief Information Security Officers (CISOs) expressed the same level of confidence.
Analysts suggest this disparity reflects a reporting gap rather than a direct failure of control, noting that executives furthest from the technical implementation of AI systems tend to report the highest levels of confidence.
Beyond the confidence gap, the report reveals a stark contradiction between perceived and actual capabilities. While 89% of respondents stated they were confident in their ability to trace, contain, and audit a breach caused by AI or autonomous agents, only 50% of organizations reported that they comprehensively track Non-Human Identities (NHIs)—the machine credentials under which AI agents operate.
The report has also faced scrutiny over its data aggregation methods. Critics point to inconsistent reporting rules used to frame the study’s findings. For example, when discussing data access, the report claimed 92% of respondents knew who touched critical AI data by combining those who were “fully mapped” (60%) with those whose permissions were “mostly understood” (32%).
However, when addressing the tracking of NHIs, the report excluded “partially” tracked responses to claim that “only 50%” of organizations tracked these identities comprehensively. This shift in methodology suggests a tendency to fold “hedged” responses into totals when the narrative is reassuring, while excluding them when the goal is to signal alarm.
Despite these methodological inconsistencies, the core finding remains: a substantial portion of the U.S. corporate landscape is operating AI systems with a significant gap between executive perception and the technical ability to secure those systems against breaches.
Related: Frontier Watch