Security News

AI Is Spreading Through Workplaces Faster Than the Skills to Govern It

Infosecurity Magazine · 9 Oct 2026
Key Takeaway Before expanding your use of AI tools, make sure your staff have basic training and clear rules for how those tools can be used, especially around privacy and security.

AI is becoming part of everyday business operations, but many organisations still lack the skills and governance frameworks to manage it well. According to ISACA's State of Cybersecurity 2026 report, 54% of organisations are now onboarding or implementing AI solutions, up from 46% in 2024.

The gap between adoption and oversight is clear in ISACA's earlier research. Only 32% of digital trust professionals believed their organisations adequately address AI risks such as privacy, bias and security. ISACA's 2025 AI Pulse Poll, which surveyed more than 3000 professionals, also found that 32% said no AI training is provided to any employees in their organisation.

In response, ISACA plans to launch an AI governance certification in early 2027, with applications currently open in a beta phase. It will complete a series of AI-focused credentials: Advanced in AI Audit, Advanced in AI Security Management and Advanced in AI Risk. ISACA's chief global strategy officer, Chris Dimitriadis, said the aim is to help people control and govern AI "rather than having AI on the loose". He called for more specialised, well-rounded AI training across roles, including auditors, cyber professionals, risk managers and IT managers, combined with soft skills.

AI governance security training ISACA risk management
Putting a number on risk like this? How to run an ISO 31000 risk assessment ->

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.