This report examines why the most urgent AI risks facing enterprises today stem not from model failures, but from human behavior. While organizations often focus on hallucinations, bias, or frontier model capabilities, the report shows that everyday employee use of AI—often unapproved, invisible, and unmonitored—is the real threat surface. As the report states, “the greatest risk of AI misuse actually stems from human actions.”
Survey data from more than 800 IT, security, audit, and GRC professionals reveals a severe visibility gap: only 34% have an AI model inventory, 31% have AI incident response procedures, and just 18% auto-block unauthorized AI domains. Meanwhile, 82% report an increase in AI-enabled attacks, with CISOs seeing the sharpest rise. Employees frequently use embedded AI inside everyday tools, creating hidden third-party exposure and daily behavioral risks such as entering confidential data into AI tools or relying on AI outputs without verification.
The report also identifies an accountability gap: many leaders feel responsible for AI risks they cannot control, and CISOs report misalignment between authority and third-party AI risk ownership. Talent shortages further compound the issue, with internal audit and security teams lacking AI-risk expertise.
Optro outlines what effective GRC AI governance looks like: cross-functional integration, clear accountability, human-in-the-loop guardrails, and technology platforms that automate intake, compliance, and continuous monitoring. The report concludes that AI governance must evolve into a proactive, unified system that manages both technological and human-driven risk.