Purple Book Community and ArmorCode Survey Flags Shadow AI, AI-Generated Code Risks
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述就行。首先,我需要仔细阅读文章内容,抓住主要信息。 文章讲的是Purple Book Community和ArmorCode合作发布的2026年人工智能风险管理报告。他们调查了北美和欧洲的650多位企业网络安全领导者。结果显示,尽管90%的企业认为他们能监控AI的使用情况,但仍有59%的企业存在未授权的AI工具使用,也就是所谓的“影子AI”。此外,70%的企业表示AI生成的代码引入了漏洞,而73%的企业认为AI加速了软件开发速度,导致安全团队跟不上审查节奏。 报告指出企业在快速部署AI的同时,安全治理却跟不上,形成了治理缺口。专家们强调最大的威胁不是看不到的东西,而是看到了却无法及时管理。这说明企业在感知和现实之间存在差距。 接下来我要把这些信息浓缩到100字以内。首先确定主题:RSAC 2026报告揭示企业AI治理问题。然后列出关键数据:90%监控能力、59%影子AI、70%代码漏洞、73%开发速度过快。最后点出问题:治理缺口和感知与现实的差距。 组合起来就是:“RSAC 2026报告揭示企业AI治理问题:90%企业具备AI使用监控能力,但59%发现未授权工具使用;70%确认或怀疑AI生成代码漏洞;73%认为AI加速开发超出安全审查能力。专家指出治理缺口是关键挑战。” 这样既简洁又全面。 </think> RSAC 2026报告揭示企业AI治理问题:90%企业具备AI使用监控能力,但59%发现未授权工具使用;70%确认或怀疑AI生成代码漏洞;73%认为AI加速开发超出安全审查能力。专家指出治理缺口是关键挑战。 2026-3-23 13:35:16 Author: securityboulevard.com(查看原文) 阅读量:4 收藏

Avatar photo

RSAC 2026 coverage: The Purple Book Community (PBC), in partnership with ArmorCode, released its State of AI Risk Management 2026 report on Monday, based on a survey of more than 650 senior enterprise cybersecurity leaders in North America and Europe.

The report points to a governance gap as organizations operationalize AI faster than security programs can keep up. According to the survey, 90% of enterprises said they have visibility into their AI footprint, but 59% confirmed or suspected “shadow AI” in their environments. The findings suggest employees are using unsanctioned AI tools or deploying agentic AI systems outside established monitoring and governance processes.

The research also ties AI-assisted development to production risk. Seventy percent of respondents said they have confirmed or suspected vulnerabilities introduced by AI-generated code in production systems, and 73% said AI-assisted development is increasing software velocity beyond the pace security teams can review.

“The greatest AI security threat isn’t what organizations can’t see, it’s what they can see but can’t govern fast enough to stop,” said Sangram Dash, PBC Charter Member and CISO and VP of IT at Sisense.

PBC’s executive chair LingRaj Patil said the data shows security leaders expressing confidence in AI governance while reporting outcomes that contradict that confidence. “This is the defining challenge of AI risk management in 2026: closing the gap between perception and reality,” Patil said.

ArmorCode Chief Security and Trust Officer Karthik Swarnam framed the problem as operational ownership and execution. “Visibility into AI is improving, but the volume and speed of change are outpacing how teams actually operate,” he said.


文章来源: https://securityboulevard.com/2026/03/purple-book-community-and-armorcode-survey-flags-shadow-ai-ai-generated-code-risks/
如有侵权请联系:admin#unsafe.sh