42 ResearchResearch
← ALL STUDIES DOC 42R-2026-01 STATUS PUBLISHED
2026 Benchmark Study  ·  Findings · n = 155

AI moved into production. Governance hasn't caught up.

We asked 155 practitioners who are scaling AI inside their organizations one question the category keeps dodging: now that AI is live, who actually governs the data behind it? The answer is reshaping the buying center, the budget, and the vendor landscape — and the tools built for the old owner are getting left behind.

00 / TOPLINE

Three readings that frame the year

The owner movedR.01
57%
say IT / Engineering now owns data governance for AI. The privacy office: 2%.
The demand is liveR.02
73%
are in-market for a new privacy or data-governance solution inside 12 months — 89% with budgets rising.
No default existsR.03
78%
name recognition tops out at one legacy brand. Below it, the specialist field fragments fast.
Fig. 00 — Headline readingsn = 155 · fielded June 2026
01 / FINDING

The owner moved out of the privacy office

For a decade, governing sensitive data was the privacy office's job. In 2026 it isn't. 57% of organizations say IT / Engineering now owns data governance for AI — the privacy office / DPO is named by just 2%. The work followed the AI: whoever ships the models inherits the obligation to govern what they touch.

When AI went to engineering, so did the data problem.
IT / Engineering57%
The CISO / security team16%
A cross-functional committee14%
A dedicated data-governance team9%
A new role created specifically for this2%
The privacy office / DPO2%
Fig. 01 — Who primarily owns data governance for AIn = 155
02 / FINDING

Demand is live, not hypothetical

This isn't a category waiting on pilots. 79% already have AI scaling across functions or deeply embedded, and 85% say that adoption is materially reshaping their privacy and governance priorities. The result is a market that is actively shopping: 73% are in-market within 12 months, 89% with budgets increasing. The pressure is real and the money is moving.

AI is deeply embedded across the organization40%
Scaling AI across multiple functions39%
Deploying AI in a few production use cases17%
Experimenting / running pilots4%
Fig. 02a — AI adoption stagen = 155
Very likely55%
Somewhat likely21%
We're already actively evaluating now18%
Not sure3%
Unlikely1%
Fig. 02b — Likelihood to evaluate / buy in 12 monthsn = 155
03 / FINDING

Confidence outruns control

Ask organizations to rate themselves and 81% say their governance is already “automated” or “managed.” Ask what actually happened in the last twelve months and the swagger thins: 63% took at least one hit — an audit finding, a breach, a regulatory inquiry, or a missed data-rights deadline. Maturity is being self-declared faster than it is being earned, and the gap is where new tools get bought.

Managed — consistent processes with some tooling43%
Automated — governance is built into our systems and workflows38%
Defined — we have policies but enforcement is mostly manual16%
Ad hoc — handled case by case, no clear process3%
Fig. 03a — Self-rated governance maturityn = 155
A privacy or data-protection audit finding43%
None of these37%
A data breach or security incident34%
A regulatory inquiry or investigation31%
A missed data-subject-request deadline23%
A failed customer security/privacy review15%
Fig. 03b — Experienced in the last 12 monthsn = 155
04 / FINDING

A category without a default

Here is the opening. Awareness peaks with the one legacy enterprise brand respondents already know from everything else — then collapses. Recognition for the purpose-built specialists clusters low and spreads thin; no challenger has claimed the AI-governance slot in buyers' heads. In a market this in-market, the absence of a default is the whole opportunity — recall is defaulting to incumbency, not fit.

IBM watsonx.governance78%
OneTrust74%
TrustArc51%
Credo AI39%
Securiti37%
Transcend37%
BigID35%
Holistic AI33%
Collibra28%
Atlan28%
Ketch23%
Didomi15%
Ethyca15%
Fig. 04a — Aided vendor awarenessn = 155
IBM watsonx.governance68%
OneTrust59%
TrustArc31%
BigID26%
Securiti24%
Credo AI24%
Transcend19%
Holistic AI17%
Collibra15%
Atlan13%
Ketch10%
Didomi6%
Ethyca5%
Fig. 04b — Would seriously consider (12mo)n = 155
05 / FINDING

How the buy actually happens

When buyers do go looking, a new AI or data initiative is the most common trigger — not a compliance deadline. They vet credibility through independent reviews, certifications and analyst rankings before they will talk; they want case studies with real metrics and technical depth, not narrative; and the decision runs through a committee that now seats engineering, security and the data team side by side. The motion is technical, proof-led, and multi-threaded.

Launching a new AI or data initiative63%
New or changing regulation (GDPR, CCPA, EU AI Act, state law55%
A privacy or security incident / breach45%
Board, executive, or customer pressure28%
A finding from an audit or assessment26%
Our current tool / manual process can't keep up26%
Fig. 05a — What triggers a search (top 3)n = 155
Independent reviews (G2, Gartner Peer Insights…)48%
Analyst reports / rankings43%
Compliance certifications (SOC 2, ISO, etc.)41%
A hands-on trial, demo, or proof of concept35%
Customer case studies and references26%
Conversations with the vendor's experts26%
Fig. 05b — Most-trusted credibility signals (top 3)n = 155
Detailed technical documentation65%
Customer case studies with real metrics63%
Analyst reports62%
Product comparisons50%
Live demos or sandbox access45%
Peer / reference calls38%
Fig. 05c — Content that actually helps evaluationn = 155
CISO / security leadership61%
CIO / CTO / engineering55%
Data / data-governance team54%
Compliance / risk42%
Finance / CFO34%
Procurement30%
Fig. 05d — Who else approves the purchasen = 155
06 / SO WHAT

What the data is telling the market

T.01

Sell to the builder, not just the office

Governance now sits with engineering and security. Messaging and product built for the privacy office alone are aimed at a 2% minority of the decision.

T.02

The window is open now

73% in-market with rising budgets is a buying wave, not a forecast. The cost of being unknown is highest in exactly the year buyers are choosing.

T.03

Close the confidence gap

Buyers feel mature and still got hit. Proof that surfaces the blind spots they can't see — coverage of what AI is actually touching — beats another maturity pitch.

T.04

Own the empty slot

No specialist owns the AI-governance category in buyers' minds. Recall is defaulting to incumbency. Whoever plants the flag with proof and reach takes the default.

07 / METHODOLOGY

About the study

Sample
155 qualified respondents with direct involvement in evaluating or buying data privacy, governance, and security tooling.
Audience
Practitioners scaling AI — leaders across IT / engineering, security, data governance, and compliance.
Organizations
Mid-to-large enterprises, the majority at 1,000+ employees, with material data-protection obligations.
Design
Blinded category benchmark. Sponsor-blinded; no respondent saw any vendor positioned as the author of the study.
Fielding
Online panel, June 2026. Quality-screened for attention and completion; reported in aggregate only.
Reporting
Aggregate & anonymous. No response is attributed to any individual or organization.
// Blinded

This is an independent benchmark, not a vendor survey. Vendor questions measure the category at large; no product is presented as the study's sponsor, and no respondent is identifiable in any published output.

Briefing

Want the full cut — by sector, size, and buying role?

42 Research runs independent benchmarks on the questions B2B categories keep dodging. We can walk your team through the data behind this report.

Request a briefing