AI Adoption Outpaced AI Governance: What's Next for the Public Sector?

Heimdal
7 Aug 2026

AI adoption didn't start with a board-level strategy. It started with browser extensions, public chatbots, and AI features embedded in tools people already used.

By the time many organisations began discussing AI governance, employees were already using Chat GPT and the likes.

The State of AI Risk Management in 2026 report, Heimdal’s latest research, suggests a bigger problem is now emerging. The IT pros closest to AI risk are far less confident that things are under control than the organisation’s executives.

For this survey, we talked about AI risk with 1,000 IT professionals across the UK and US. Here’s what we found out.

Executives say AI is under control. The IT teams disagree

The report’s finding is blunt: confidence in how AI risk is managed falls the closer you sit to the keyboard.

In the US, 29% of C-suite and VP respondents say AI risk is under control. Among the practitioners running it day to day, that figure is 7%. In the UK it's 18% against 11%.

Both gaps show that those in direct contact with AI use impact are less confident in how risks are managed.

Executives are more confident

Adoption first, controls later

Our data also shows ChatGPT already running in 72% of UK IT environments and 69% of US ones. Microsoft Copilot sits at 68% UK, 59% US.

So, AI is already embedded. But readiness lags adoption: only around four in ten teams rate their security stack as ready for AI-related risk.

Across both markets, adoption has outrun the controls built to manage it by roughly two to one.

Figures show concern rises with visibility.

Among UK teams with full visibility into their organisation's AI use, 56% flag data leakage as a top concern, against 27% of teams with none.

In a nutshell, the people who can see the most are the most worried. If your own AI risk dashboard shows green, check who's reporting it.

It's worth repeating to any leadership team reviewing its AI posture: misplaced confidence is one of the most dangerous things in security.

adoption-vs-control

Public sector faces the same AI risks as private companies

The findings of the report are more than a private-sector curiosity.

This recent CISA case is proof that the pattern works the same in government institutions.

In January 2026, it emerged that the acting director of CISA, the US cybersecurity agency, had uploaded documents marked "For Official Use Only" to public ChatGPT. The leak happened in mid-2025. The agency's own monitoring flagged it within a week. However, nothing stopped it from happening in the first place.

The case highlights a familiar security challenge. Detection found the issue, but the controls failed to prevent it.

Executives may approve AI use policies that tell staff what not to do. That’s a good, but insufficient measure. Because policies won't stop a file being pasted into a prompt box, or a plugin quietly summarising a spreadsheet that should never have left a secure network.

So, the real risk here is the gap between governance and enforcement. Policies define acceptable behaviour, but technical controls are what prevents sensitive data from reaching AI tools.

What should change in AI integration strategies

The fix for AI risk isn't a longer policy document. It's treating AI services the way you'd treat any other supplier with access to sensitive data.

Here’s what that means for public sector teams:

  • Inventory before you govern. List every AI tool in use, sanctioned and unsanctioned. You can't control what you haven't counted and shadow AI risk is real.
  • Apply supplier due diligence, not a sign-off form. Data-handling terms, sub-processor disclosures, retention periods: use the same scrutiny given to any system touching citizen data. Apply it to AI tools by default.
  • Push controls to the point of use. Policy and training still matter, but the CISA case showed they're not enough. Technical controls over which tools can run, what data can leave, and what an AI-connected process can chain together are what stop an upload before it happens.
  • Close the reporting gap on purpose. If practitioner concern isn't reaching the people signing off budgets, those budgets are being set against a false picture of control.

The takeaway

None of this is an argument against adopting AI in the public sector.

Organisations getting this right aren't the ones blocking AI. They're the ones building clear guardrails while still letting staff use these tools well.

For public sector teams under pressure to modernise fast, that's the balance to build toward. Not a blanket ban, and not a policy PDF and a shrug.

DigiGov banner