As high-profile security events like OpenAI’s rogue AI hacker monopolize the news cycle, enterprise leaders are facing their own AI dilemma: how to balance rapid adoption with mounting security risks.
Security incidents are costing enterprises serious capital. Over 40% of respondents said AI-related incidents cost their organizations $2 million or more in the past year, according to a survey of 300 enterprise decision-makers by security platform provider WitnessAI.
Meanwhile, 91% reported concerns that AI agents are increasing their financial risk exposure, and 86% of respondents said they had investigated one or more AI-related security or operational incidents in the last 12 months.
Yet enterprises are pushing ahead on adoption, with worker access to AI surging by 50% in 2025, according to Deloitte’s “State of AI in the Enterprise” report.
“This seems like the first time that I can think of where risk isn’t slowing anybody down,” Rick Caccia, CEO of WitnessAI, told Channel Dive. “Typically, you'd see risk, and security would put the brakes on, and the brakes would actually work. And this is an example where the brakes aren't being put on, and if they are, they're not working. So, you're seeing adoption happen really quickly, despite all these risks.”
Shadow AI, the unsanctioned use of AI tools by individuals working for a corporation, is among the biggest security risks for enterprises.
“Every prompt, upload, or query is a potential breach,” Aditya Patel, cloud security specialist at AWS, wrote in a Cloud Security Alliance blog post. “The problem isn’t just volume — it’s velocity. AI’s self-learning nature means risks compound faster.”
Strikingly, respondents said IT/infrastructure departments are the biggest source of shadow AI activity. The department most responsible for governing AI use within the organization is also the department most likely to be operating outside its own policies, according to WitnessAI.
Amid this chaos, companies are allocating significant portions of their AI budgets to risk management and governance — more than half dedicate between 21% and 45% of AI spending to these efforts — yet risk ownership remains unclear, Caccia said.
“Is it the CFO? Is it the CEO? Is it legal? Who the heck owns control of AI risk?” he said.
The survey also revealed a significant perception gap between enterprise executives and VP-level decision-makers. While 68% of C-suite respondents expressed confidence in their visibility into AI tools, models and agents accessing company data, only 46% of VPs shared that confidence.
For enterprises grappling with security incidents, AI visibility is the top priority. You can't control what you can't see, according to Caccia.
For channel partners, the enterprise AI security challenge represents a significant business opportunity.
“This is a generational opportunity for channel partners because your client base is trying to figure all of this stuff out,” Caccia said. “This is a chance to help your clients with real strategy and real solutions.”