90% of organizations expanded their privacy programs because of AI in the past year, according to Cisco's 2026 Data and Privacy Benchmark Study, which surveyed 5,200 IT, technology, and security professionals across 12 countries in late 2025. AI adoption inside companies has outrun the privacy and governance work needed to manage it safely, and the gap between how many businesses use AI and how many have a real policy covering it is one of the widest in recent privacy research.
That gap is the story this page documents: how many companies now run AI against real user and customer data, how many have written an actual governance policy for it, and how often the absence of that policy shows up later as a breach.
How many companies use AI in their operations?
Business AI adoption is now close to universal at the "at least one use case" level. Stanford HAI's 2026 AI Index reports that 88% of organizations use AI in at least one business function, with generative AI specifically reaching 70% adoption. McKinsey's most recent State of AI survey found a near-identical 88% figure for regular AI use in at least one function, with more than two-thirds of respondents using AI in more than one function at once.
Broad adoption does not mean deep, well-governed adoption. Stanford HAI's report notes that AI agent deployment, the more autonomous, higher-risk category of AI use, remains in the single digits across nearly all business functions, meaning most of that 88% is still simpler, human-supervised AI use rather than systems acting on personal data with less oversight.
Figure 1: Adoption drops sharply as AI use gets more autonomous. Source: Stanford HAI 2026 AI Index.
How many organizations have expanded privacy programs for AI?
90% of organizations expanded their privacy programs specifically because of AI in the past year, and 93% plan to keep increasing that investment, per Cisco's 2026 Data and Privacy Benchmark Study. Spending has moved with that intent: 38% of organizations now spend at least 5 million dollars a year on privacy programs, up from just 14% one year earlier, roughly a threefold jump in high-spending organizations in a single survey cycle.
The same study found that 96% of respondents say a strong privacy framework actually enables AI agility rather than slowing it down, and 95% say privacy is essential to keeping customer trust in AI-powered products. Spending and stated intent are climbing together, though as the next section shows, spending has not yet translated into governance maturity at the same pace. If your own privacy policy has not been updated since before your organization adopted AI tools, you can generate a current, AI-aware privacy policy that discloses what automated processing you actually run.
How many companies have a real AI governance policy?
Fewer than expected. 75% of organizations in Cisco's 2026 study have stood up a dedicated AI governance body, but only 12% describe that body as mature. IBM's 2025 Cost of a Data Breach Report, based on 600 organizations studied by the Ponemon Institute between March 2024 and February 2025, found an even starker number: 63% of those organizations had no AI governance policy in place at all to manage AI use or prevent unapproved "shadow AI" tools.
Figure 2: Most organizations have started AI governance; few call it finished. Sources: Cisco 2026 Data and Privacy Benchmark Study; IBM 2025 Cost of a Data Breach Report.
The IAPP's AI Governance Profession Report 2025, based on survey responses from more than 670 privacy and governance professionals across 45 countries, adds a more optimistic data point: 77% of surveyed organizations say they are actively building or refining an AI governance program, and that share rises to nearly 90% among organizations already using AI. Read together with Cisco and IBM's numbers, the pattern is consistent: most organizations have started the governance work, few have finished it, and the unfinished middle is where the risk concentrates.
Figure 3: The path from no AI policy to a reported AI-related breach. Sources: IBM 2025 Cost of a Data Breach Report; Cisco 2026 Data and Privacy Benchmark Study.
How many data breaches now involve AI systems?
13% of organizations in IBM's 2025 Cost of a Data Breach Report reported a breach involving an AI model or AI application. Of those breached organizations, 97% lacked working AI access controls at the time of the incident, and 60% of the AI-related incidents led directly to compromised data, with 31% causing an operational disruption on top of the data exposure.
Shadow AI, meaning AI tools employees adopt without security or IT approval, carries its own separate cost signal. 20% of the 600 organizations studied experienced a breach linked to shadow AI, and those incidents added an average of 670,000 dollars to the total breach cost compared to organizations with little or no shadow AI exposure. Cisco's 2026 study reinforces the trend from the concern side rather than the incident side: data leaks from generative AI became the top security concern for 34% of organizations heading into 2026, up sharply from 22% the year before, making it the single fastest-rising item on that survey's risk list.
Figure 4: What happened after an AI-related breach, among organizations that reported one. Source: IBM 2025 Cost of a Data Breach Report.
How has AI changed privacy risk over the past two years?
The trend line across every major benchmark study points the same direction: AI adoption has climbed steadily while the specific worry about AI-driven data leaks has climbed even faster. Cisco's own year-over-year tracking shows generative AI data leak concern nearly doubling in relative terms between its 2025 and 2026 survey waves, even as overall AI adoption growth flattened slightly compared to the sharper year-over-year gains recorded in 2024.
Figure 5: Concern about generative AI data leaks rose 12 percentage points in one survey cycle. Source: Cisco 2026 Data and Privacy Benchmark Study.
Figure 6: How spending, adoption, and risk concern moved together across three survey cycles. Sources: Cisco 2026 Data and Privacy Benchmark Study; IBM 2025 Cost of a Data Breach Report; Stanford HAI 2026 AI Index.
The Bottom Line
Every 2026 benchmark tells a version of the same story: AI adoption is close to universal, spending on privacy has roughly tripled at the high end in a single year, and governance maturity has not caught up with either one. 88% of organizations use AI somewhere in the business, 90% have responded by expanding their privacy programs, and yet only 12% call their AI governance body mature, and 63% of breached organizations in IBM's study had no AI policy at all. For any organization publishing a privacy policy today, the practical gap to close is disclosure: if AI now touches how personal data gets processed, stored, or used to train anything, that needs to be named in the policy itself, not assumed to be covered by older, pre-AI language.
Frequently Asked Questions
How many organizations expanded their privacy programs because of AI? 90% of organizations expanded their privacy programs in response to AI in the past year, according to Cisco's 2026 Data and Privacy Benchmark Study of 5,200 IT, technology, and security professionals across 12 countries, and 93% plan to keep increasing privacy investment.
What percentage of businesses use AI in at least one function? 88% of organizations use AI in at least one business function, per Stanford HAI's 2026 AI Index, and generative AI specifically is used by 70% of organizations, up from prior-year levels tracked in the same annual survey.
How many companies have an AI governance policy? 63% of the 600 organizations studied in IBM's 2025 Cost of a Data Breach Report had no AI governance policy in place, even though 13% of those organizations had already suffered a breach involving an AI model or application.
How many data breaches in 2026 involve AI systems? 13% of organizations reported a breach of an AI model or AI application, per IBM's 2025 Cost of a Data Breach Report, and 97% of those breached organizations lacked basic AI access controls at the time of the incident.
Where the Numbers Come From
- Cisco. (2026). "2026 Data and Privacy Benchmark Study." Survey of 5,200 IT, technology, and security professionals across 12 markets, published January 2026.
- Stanford HAI. (2026). "The 2026 AI Index Report." 88% overall organizational AI adoption, 70% generative AI adoption.
- IBM Security, research by the Ponemon Institute. (2025). "Cost of a Data Breach Report 2025." 600 organizations studied, data collected March 2024 through February 2025, published July 2025.
- IAPP and Credo AI. (2025). "AI Governance Profession Report 2025." Survey of more than 670 professionals across 45 countries.
- McKinsey. (2025). "The State of AI in 2025: Agents, Innovation, and Transformation." Global executive survey on enterprise AI adoption.
Note: All figures verified as of July 2026. The Cisco 2026 and Stanford HAI 2026 figures are the most current survey waves available at publication; the IBM Cost of a Data Breach figures are from the 2025 edition, the most recent published as of this writing, and will be refreshed against the next annual edition when it becomes available. This page is reviewed and its figures refreshed at least twice a year.