Kiteworks: Europe leads on security, lags on AI governance
Kiteworks’ 2026 survey finds Europe with the strongest data security maturity score but a weaker AI governance score, underscoring a gap as EU and UK organizations face rising regulatory pressure. The report says 29% of European organizations rank AI regulation as their top compliance concern, the highest share in any region.
Why it matters: - Europe has the strongest measured security infrastructure in the survey, but its AI governance score trails other regions. - That gap matters because regulations such as the EU AI Act, DORA, NIS2 and GDPR require organizations to prove how they control data and AI systems. - The report suggests many organizations are building security controls without the governance architecture needed for AI agents and automated data use.
What happened: - Kiteworks released the European findings from its 2026 Data Security and Compliance Risk: Annual Survey Report on July 29, 2026. - The survey covered 459 security, compliance, risk and IT professionals across 10 industries and three global regions. - Europe posted a median Data Security Maturity Score of 40 out of 100, the highest of the three regions. - Europe posted a median AI Governance Maturity Score of 33, the lowest of the three regions. - Europe’s combined DSCRI readiness index was 15, tying the Middle East for the lowest regional score.
The details: - North America scored 38 on data security maturity and 39 on AI governance maturity. - The Middle East scored 37 on data security maturity and 34 on AI governance maturity. - EU and UK organizations said AI-specific regulatory requirements are their top compliance concern at 29%, above North America at 24% and the Middle East at 7%. - EU and UK organizations reported the lowest compliance consequence rate at 57%, compared with 69% in North America and 76% in the Middle East. - EU and UK organizations reported monthly shadow AI use at 11%, compared with 24% in North America. - EU and UK organizations reported AI tool data exposure incidents at 20%, compared with 36% in North America. - The report says lower detection can reflect more controlled environments, but it can also mean longer periods of undetected exposure. - Globally, 74% of organizations lack purpose limitation for AI data use. - No containment mechanism is used by more than 31% of organizations. - The report says audit requirements from DORA, NIS2 and the EU AI Act now set deadlines that 50% of organizations cannot meet. - Resilient organizations, defined as those with both DSMS and AIGMS at 50 or higher, have a median DSCRI of 46. - Exposed organizations, which make up 66% of respondents, have a median DSCRI of 8. - The gap between the highest and lowest performers in the study is 38 DSCRI points. - The report identifies seven priorities for closing the gap: classifying sensitive data, enforcing it, deploying AI-specific DLP through a central policy engine, integrating MFT and AI infrastructure into a SIEM, implementing and testing an AI kill switch, building audit trails that match regulatory production timelines, assigning dedicated accountability for AI data governance, and consolidating secure data-sharing platforms. - The report is based on research conducted by Centiment for Kiteworks in the second quarter of 2026. - The full report is available as the 2026 Data Security and Compliance Risk: Annual Survey Report.
Between the lines: - Europe’s stronger security score does not automatically translate into stronger AI governance. - The report frames the problem as an architecture issue, not a lack of regulatory pressure. - Lower shadow AI and incident figures in Europe may signal tighter control, but they may also point to blind spots in detection. - Kiteworks argues organizations need one policy engine and one audit log that cover both people and agents.
What's next: - Kiteworks says organizations that close the gap will need to unify governance, logging and enforcement across human and AI-driven data activity. - The report points to faster adoption of AI-specific controls, central auditability and tighter policy enforcement as the most likely next steps for compliance teams. - The broader question is whether European organizations can turn regulatory pressure into measurable AI governance gains before enforcement timelines tighten further.
The bottom line: - Europe leads the survey in security maturity, but not in AI readiness, and that mismatch is now a compliance risk.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The Middle East Gazette
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.