AI governance series

White papers

Two papers analysing two independent 2026 surveys — 3,145 respondents between them. Neither survey was ours. The research is published by the National Cybersecurity Alliance with CISA, and by KPMG International; the analysis, models and recommendations are Prompt Shields' own.

Free to read in full. No email required.

White paper I of II

The Accountability Gap

Two surveys, 3,145 respondents, and one finding neither set out to make: AI adoption has outrun AI ownership at every company size — and the organisations that close the gap are the only ones getting paid.

87.3%of small businesses use AI tools
45.6%have any formal guideline governing that use
75%of enterprises say the CEO owns AI as a priority
24%say the CEO is actually accountable for AI decisions
Read the paper · 12 min read

White paper II of II

The Visibility Dividend

Most organisations cannot say what their AI is doing, what it costs, or whether they have already been breached. The ones that can are five times more likely to be able to prove a return.

56.1%of small businesses cannot confirm a clean security record
35%of enterprises have full visibility into AI operating costs
more likely to report ROI where cost visibility is complete
49%have delayed or scaled back AI agents when costs outran value
Read the paper · 11 min read

Sources

NCA / CISA. 2026 Small Business Cybersecurity Awareness & Practices Survey. National Cybersecurity Alliance in partnership with the Cybersecurity and Infrastructure Security Agency. n=1,000 US SMB leaders with decision-making authority, 2–1,000 employees, across 10 industries.

KPMG International. Global AI Pulse Q2 2026. n=2,145 senior leaders across 20 countries and territories; organisations with US$50m+ revenue for the global sample, with the US tracking sample using US$1bn+. Fielded 28 April – 25 May 2026, online.

Statistics are attributed to their original publishers. Analysis, framing and recommendations are Prompt Shields' own. Prompt Shields is not affiliated with, endorsed by, or sponsored by the National Cybersecurity Alliance, CISA or KPMG International. Findings are correlational; cross-survey comparisons are directional, as the two samples differ materially in geography, organisation size and respondent seniority.