Research report
The State of Enterprise AI Usage: The Illusion of Control
72% of organisations believe they have full visibility into AI usage. Yet 65% still uncover unauthorised or shadow AI.
Most organisations think they control AI.
The data says they don’t.
This research, based on 300 senior leaders across regulated industries, reveals why perceived control breaks down, and where real AI risk emerges.
Download the full research report
See where your organisation stands.
What the research found
Confidence without control
Perceived control is not real control
72% say they see AI use; 65% still find shadow AI. Our survey of 300 security and IT leaders reveals a critical visibility gap: confidence without control. Download the report to see where data is leaking and what to do about it.
Inside the report
AI adoption is surging. Control isn’t.
In Q4 2025, CultureAI surveyed 300 senior security, technology and risk leaders across North America and Europe to understand how organisations are managing AI usage in reality.
- How AI adoption has become widespread and decentralised
- Why traditional governance models create an illusion of control
- How AI risk manifests in practice, and why it is underestimated
- What organisations must do to move from intent to enforceable control
Download the full research report and see where your organisation stands.

Written by
Oliver Simonnet
Lead Cyber Security Researcher
Oliver Simonnet is the Lead Cybersecurity Researcher at CultureAI, focusing on human and AI-centric threats.
With nearly a decade of experience, holding roles such as Principal Security Consultant, Global Head of Application Security and SWIFT Security SME, his expertise spans multiple domains including reverse engineering, payment system technologies and artificial intelligence.

CultureAI commissioned Censuswide to conduct an industry survey in late 2025 to assess how prepared organisations are when it comes to adopting AI securely.
The survey gathered responses from 300 senior professionals, including CISOs, CIOs, CTOs, data protection officers, and IT and security leaders, across multiple sectors and geographies in North America and Europe.
Uncover hidden AI risk
Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.