Europe trails on AI governance despite leading on security, Kiteworks survey finds
Europe scored highest on general data security but lowest on AI governance in Kiteworks’ 2026 survey, leaving the region tied for the weakest overall readiness. The findings suggest regulators and companies are facing more AI compliance pressure, but many still lack the controls to govern AI at the same pace as traditional security.
Why it matters: - Europe’s stronger security posture is not translating into AI readiness, creating a gap between existing controls and the governance needed for AI systems and agents. - The mismatch matters for compliance with GDPR, DORA, NIS2 and the EU AI Act, which all demand evidence from the same security and governance teams. - The survey shows the region is leading on one risk frontier while falling behind on the one that is expanding fastest.
What happened: - Kiteworks released European findings from its 2026 Data Security and Compliance Risk: Annual Survey Report, based on primary research with 459 security, compliance, risk and IT professionals across 10 industries and three global regions. - Europe posted a mean Data Security Maturity Score of 40 out of 100, the highest of the three regions. - Europe’s mean AI Governance Maturity Score was 33, the lowest of the three regions. - Europe’s mean Data Security and Compliance Readiness Index was 15, tied with the Middle East for the lowest regional score. - Tim Freestone, Kiteworks chief strategy officer, said Europe’s gap is AI governance, not security.
The details: - Europe’s DSMS of 40 beat North America’s 38 and the Middle East’s 37. - Europe’s AIGMS of 33 trailed North America’s 39 and the Middle East’s 34. - EU/UK organizations ranked AI-specific regulatory requirements as their top compliance challenge more than any other region, with 29% naming it their single biggest concern. - That compares with 24% in North America and 7% in the Middle East. - EU/UK organizations reported the lowest compliance consequence rate of any region, at 57%, versus 69% in North America and 76% in the Middle East. - EU/UK organizations discovered shadow AI usage monthly at 11%, compared with 24% in North America. - EU/UK organizations reported AI tool data exposure incidents at 20%, compared with 36% in North America. - The report says lower detection numbers can reflect more controlled environments, but they can also mean exposures go unnoticed longer. - Patrick Spencer, Kiteworks SVP of Americas Marketing and Industry Research, said Europe is producing compliance activity, not governance architecture. - Spencer said organizations closing the gap are using one policy engine and one audit log to govern people and agents together.
Between the lines: - The survey points to a broader global control gap, not just a European one. - Worldwide, 74% of organizations lack purpose binding for AI data use. - No AI containment control measured in the survey is deployed by more than 31% of organizations. - The report says DORA, NIS2 and EU AI Act audit obligations now run on timelines that 50% of organizations cannot meet. - The data suggests that regulatory pressure alone is not enough to produce AI governance capability. - Kiteworks argues the winning model is architectural, with controls enforced at the data layer rather than through policy that people can bypass.
What's next: - Kiteworks says organizations should classify and enforce sensitive data, deploy AI-specific DLP through a centralized policy engine, and integrate MFT and AI infrastructure with a SIEM. - Other priorities include implementing and testing an AI kill switch, building audit trails that meet regulatory production timelines, assigning dedicated AI data governance ownership and consolidating sensitive data exchange platforms. - The full report includes global, industry, regional and organization-size breakdowns. - The research was conducted by Centiment on behalf of Kiteworks in Q2 2026.
The bottom line: - Europe is ahead on traditional security controls, but the survey says it still lacks the AI governance layer needed to turn compliance pressure into real readiness.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The European Gazette
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.