A new report by Drata delves into the perceptions and realities of Artificial Intelligence (AI) adoption among security and IT professionals, specifically within the governance, risk, and compliance (GRC) domain. The analysis highlights a critical disparity between the anticipated benefits of AI in GRC and its actual performance, attributing this gap to several factors: vendors' overpromising capabilities, organizations purchasing overly broad solutions, and an inadequate focus on establishing robust governance frameworks. This comprehensive survey reveals that despite the growing interest in AI, a significant portion of GRC-focused AI tools are not yet deemed enterprise-ready, leading to tangible risks and compliance failures. The report serves as a crucial assessment of the current state of AI in GRC, pointing towards the need for more realistic expectations, strategic deployment, and stronger governance to harness AI's full potential securely and effectively within organizations.
GRC AI Tools Not Enterprise Ready
A striking 86% of surveyed security and IT teams concur that a considerable number of AI tools designed for Governance, Risk, and Compliance (GRC) lack the maturity and capabilities required for robust enterprise-level deployment. This indicates a widespread skepticism regarding the current state and readiness of these advanced technological solutions to handle complex organizational GRC needs effectively and reliably, suggesting that vendors may be premature in their offerings or that the technology itself still requires significant development and refinement to meet rigorous corporate standards for security and compliance.
Lack of Preparedness for AI Integration
An overwhelming 83% of organizations openly admit that they are inadequately equipped or fully prepared to manage the impending and rapid influx of AI technology integration across their various operational and security systems. This substantial lack of preparedness points to potential future challenges in managing AI-related risks, maintaining compliance, and ensuring the secure and ethical use of artificial intelligence as it becomes more embedded in critical business functions, underscoring a significant organizational vulnerability in the face of rapid technological evolution.
Discontinuation of Underperforming AI Tools
The report reveals a trend where three-quarters of organizations are now more swiftly abandoning AI tools that fail to meet their expected performance benchmarks or demonstrate significant shortcomings. Furthermore, in instances where these AI solutions expose deficiencies or create new problems, more than half of these organizations opt to revert back to their traditional manual processes. This demonstrates a pragmatic approach by businesses, prioritizing operational integrity and compliance over poorly implemented AI, and highlights the ongoing reliability issues faced by current AI offerings in the GRC space.
Preference for Targeted AI Systems
A clear preference is emerging among respondents, with 64% favoring highly targeted, agentic AI systems that perform specific functions rather than broad, all-encompassing platforms that attempt to do everything. This preference is even more pronounced among buyers whose primary concern is risk management, with 70% opting for specialized solutions. This trend suggests that organizations are seeking precision and reliability in their AI deployments, recognizing that focused tools can deliver more accurate and manageable results in critical areas like GRC, rather than the complexity and potential unpredictability of monolithic AI platforms.
Benefits of External Trust Centers
The adoption of external trust centers is proving beneficial, as nearly half of the organizations that utilize them report significantly greater transparency regarding the security posture of their vendors. In addition, 44% of these organizations observe a noticeable acceleration in their vendor review processes. This indicates that a centralized, transparent approach to demonstrating security and compliance can streamline vendor management, enhance trust, and improve overall operational efficiency, serving as a valuable component in an organization's broader GRC and AI integration strategy.