AI Governance Library

The Rise in Unstructured Data and AI Security Risks

Only 35% of organizations report full visibility into where unstructured data resides, while classification and labeling practices remain inconsistent. Security, governance, privacy, and compliance are top concerns, yet many organizations struggle to execute foundational controls.
The Rise in Unstructured Data and AI Security Risks

⚡ Quick Summary

Published by the Cloud Security Alliance (CSA) and sponsored by Thales, The Rise in Unstructured Data and AI Security Risks investigates how enterprises manage, protect, and govern the rapid expansion of unstructured data across cloud, on-premises, and hybrid environments. Drawing on survey findings from 210 IT and security professionals, the report identifies a significant disconnect between organizational confidence and operational capability. While 75% of respondents express confidence in their security posture, 68% report that most of their unstructured data remains unprotected, and only 35% maintain full visibility into storage locations.

As organizations prepare to deploy artificial intelligence for threat detection and automated security workflows, the report highlights that advanced AI capabilities risk being built upon fragile data foundations characterized by fragmented tooling, slow vulnerability scanning, and undefined data lineage.

🧩 What's Covered

The report provides an empirical breakdown of unstructured data governance and risk management across five key areas:

  • Enterprise Data Composition and Growth: Documents and files (73%), communications (62%), and operational logs (43%) comprise the bulk of unstructured data estates. Nearly one-third (29%) of enterprises report unstructured data accounts for over half of annual data growth, with sensitive unstructured data heavily distributed across cloud apps (58%), file servers (57%), and public clouds (47%).
  • Visibility, Classification, and Baseline Gaps: Only 35% of organizations maintain complete visibility over unstructured data repositories, while 10% perform no sensitivity labeling whatsoever. Sensitive data protection (44%) and detecting bad practices (42%) are cited as the most difficult operational tasks.
  • The Confidence-to-Capability Disconnect: While three-quarters of organizations claim confidence, one-fifth allocate under 5% of IT budgets to unstructured data protection, and 23% completely lack capabilities to scan unstructured data for vulnerabilities or risk.
  • Tool Sprawl and Decentralized Accountability: Over 32% of respondents deploy 11 or more tools to manage unstructured data. Responsibility remains fragmented across data governance teams (32%), security leadership (28%), and business units (18%), resulting in manual process bottlenecks.
  • AI as Threat and Solution: Advanced AI-driven threats are ranked as the leading risk to unstructured data (47%). Concurrently, enterprises plan to leverage AI for threat detection (40%) and classification (37%), despite the operational hazard of deploying AI onto unmapped and unscanned datasets.

💡 Why it matters?

As enterprises accelerate generative AI adoption, model outputs, fine-tuning, and retrieval-augmented generation (RAG) depend directly on unstructured corporate data. If governance, discovery, and access controls are missing, AI systems can inadvertently ingest or leak sensitive intellectual property, personally identifiable information, and regulated financial or healthcare records. Establishing verified visibility, lifecycle governance, and automated scanning is essential to securing enterprise AI initiatives against data leakage and automated adversary techniques.

❓ What's Missing

The report focuses primarily on high-level survey statistics and threat perceptions, providing limited prescriptive implementation frameworks or technical architectures for remediation. It does not explore specific technical standards for AI data ingestion pipelines, granular data sanitation mechanisms, or cross-border regulatory compliance mappings (such as the EU AI Act or GDPR requirements for unstructured processing).

👥 Best For

This report is best suited for CISOs, Chief Data Officers (CDOs), AI Governance Officers, privacy engineers, and security architects evaluating data security posture management (DSPM), tool consolidation, and AI readiness strategies.

📄 Source Details

  • Source Title: The Rise in Unstructured Data and AI Security Risks
  • Publishing Entity: Cloud Security Alliance (CSA) & Thales
  • Publication Year: 2026 (Survey Conducted November 2025)
  • Sample Size: 210 IT and cybersecurity professionals
  • Report Format: Industry Survey & Research Report

📝 Thanks to

Lead Author: Hillary Baron. Contributors: Marina Bregkou, Josh Buker, Ryan Gifford, Alex Kaluza, Lynne Murray. Design: Stephen Lumpe, Stephen Smith. Special Thanks: Lynne Murray, Jon-Rav Shende, Krishna Ksheerabdhi. Sponsor: Thales.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.