Global research · 600 C-suite leaders
The Data & AI Trust Gap
What C-suite leaders reveal about the difference between AI ambition and AI results. Most organizations can adopt AI. Far fewer can trust the data underneath it. Three leadership gaps explain why: perception, activism, and authority.
of CEOs report pressure to accelerate their AI and data capabilities.
say data challenges have slowed their AI progress in the past year.
Key takeaways
The five things every leader should know about the AI trust gap
Only 16% of CEOs feel comfortable leading strategic data discussions. That’s the authority gap, and it’s where accountability for data risk stalls.
Only 7% of organizations are AI-ready, but 97% of those report significant, quantified business outcomes.
88% run AI agents, yet only 28% are confident they could detect one operating outside approved parameters.
95% know employees use unapproved AI tools, but only 25% provide an approved alternative for everyone.
Closing the gap is an executive-alignment problem: treat data governance and risk management as board-level accountability.
What does it mean to truly trust your data?
Four conditions make data trustworthy.
Most organizations are missing at least one
“The infrastructure to deploy AI exists, but the infrastructure to trust it doesn’t.”
Clear visibility
Know where your data lives and how it moves, so nothing critical is invisible.
“The infrastructure to deploy AI exists, but the infrastructure to trust it doesn’t.”
Each condition is necessary; none is sufficient alone. Miss one and the other three can’t compensate.
-
Clear visibility
Know where your data lives and how it moves, so nothing critical is invisible.
-
Enforced controls
Controls that are enforced in practice and reduce exposure, not policy that exists only on paper.
-
Tested recovery
Recovery you’ve tested under real conditions, including restoring clean data. Not assumed to work.
-
Executive alignment
Ownership and accountability at the top. The condition most often absent, and the one on which all the others depend.
Each condition is necessary; none is sufficient alone. Miss one and the other three can’t compensate.
WHERE DO CEOS SEE THE OPPORTUNITY?
CEOs see the revenue upside most, but the data isn’t ready to deliver it
48% of CEOs believe
secure, compliant data could boost revenue by more than 25%,vs. 38% of all leaders.
The C-suite says its data needs to be:
CAN ORGANIZATIONS TRACE WHAT THEIR DATA DOES?
Traceability is the missing foundation
Only 40% are very confident they could isolate and precisely reverse an agentic AI failure. When asked what they could establish within minutes of a failure, respondents said:
Which systems were accessed:
What actions were taken:
What decisions were influenced:
Which data was used:
Where does data leadership break down?
Three gaps keep most organizations from closing the trust gap
Every gap is a risk management problem. Accountability for data risk falls between the CEO and the leaders closest to the data.
The perception gap
It’s a language problem. “Auditing” means regulatory exposure to one leader and a technical checklist to another, so CEOs and their data leaders don’t share the same picture of who leads on it.
of CEOs believe they lead by example on data, but only 41% of CISOs and 38% of CIOs agree.
The activism gap
Data leadership is reactive, not proactive. Data is discussed on opportunity (43%) or when diagnosing a problem (33%), rarely on a schedule.
say data discussions are proactively scheduled at board level; 4% discuss it only after a breach or quality failure.
The authority gap
The most consequential gap. CEOs join data discussions willingly, none actively avoid them, and just 5% find the conversations too technical. What’s missing is confidence to lead, and technical leaders want direction, not lessons.
of CEOs say they are comfortable leading strategic discussions on data. 47% of data leaders want them involved in strategic planning.
WHO OWNS WHAT AI AGENTS DO?
88% run AI agents but nobody clearly owns the risk
88% already use or pilot AI agents,
but only 28% are confident they’d detect one operating outside approved parameters.Ownership decides the outcome: detection confidence runs 24% higher where a CISO owns AI agent risk, and 47% lower where it’s split across functions.
Primary responsibility for what AI agents do:
DO LEADERS SHARE THE SAME PICTURE?
CEOs trust their AI inventory far more than the people who manage it
65% of CEOs say their
AI inventory is complete and reliable.If their picture is wrong, so are the decisions built on it.
“We have a complete and reliable AI inventory”
As the EU AI Act comes into force, that mismatch gets expensive. 47% already name audit trails for AI decisions as their top compliance concern, and penalties run from €7.5M to €35M, or 1% to 7% of global annual turnover.
Is AI investment actually paying off?
Most leaders claim success. Few have measured it
-
Nearly everyone claims a win
85%
say their data initiatives delivered significant success over the past 12 months.
-
Almost half aren’t checked
45%
have never formally measured the impact. Investments made on instinct rarely get repeated.
-
Process beats people
51%
reporting on process improvement, ahead of financial (48%) and strategic (45%).
-
Staff impact goes untracked
29%
track satisfaction or retention, the least-measured ROI category of all.
DO LEADERS ACT ON WHAT THEY SAY TRUST REQUIRES?
Across every area of data trust, intent runs ahead of action
Leaders were asked which areas of data trust matter most, then whether they’d acted. Every area came back with a gap, and the widest is security, at 20 points.
These gaps are leaving 70% of orgs without the visibility to demonstrate provenance.
24% have appointed a C-suite leader accountable for data; one in five cite lack of sponsorship as a barrier.
A quarter of leaders believe complete data trust could unlock a 25–50% revenue or efficiency gain. Another 13% put it above 50%.
Compliance
& regulatory
Security
& protection
Data
provenance
Governance
& ownership
HOW WIDESPREAD IS SHADOW AI?
Nearly every organization has a shadow AI problem
95% of organizations know their employees are using unapproved AI tools, and it persists anyway.
WHAT ARE MANAGERS DOING ABOUT IT?
Policies exist, enforcement and provision don’t
How organizations respond to shadow AI. Technical measures have limits: block the tools and employees switch to personal devices. Only 25% provide approved alternatives.
Where does investment turn into capability?
Investment in cybersecurity is rising, but not universally
Just 7% of organizations have all three building blocks in place. But 60% are only one or two blocks away. Click each stage to see where organizations sit today.
Ambition
Shared goals, set by the CEO and communicated across the business, are the basis of a data strategy that delivers.
Visibility
A full understanding of what data exists and where it sits. Without it, ambition is a wish list.
Governance
Structures and controls to use data safely and compliantly, avoiding regulatory risk and reducing exposure.
of organizations surveyed
Back of the grid
No building blocks in place: no ambition, visibility, or governance to treat data as a strategic asset.
What AI-readiness is actually worth
Just 7% are ready.
Almost all of them can prove the return
Only 7 in 100 organizations have all three building blocks in place. Within that group, nearly all report business results they can put a number on. The difference is trust, not technology.
What the payoff looks like:
-
47%
of organizations have formally quantified the results of a data initiative.
-
56%
more than half of them (56%) saw the gain in revenue growth.
-
60%
already have at least two of the three building blocks, so the distance is shorter than it looks.
Frequently asked questions
The data & AI trust gap, answered
It’s the distance between AI ambition and AI results: the difference between how ready organizations feel to use their data for AI and how trustworthy that data actually is. 83% of CEOs feel pressure to move faster on AI, yet 95% say data challenges have slowed their progress.
Three building blocks in place at once: ambition (clear, CEO-led goals), visibility (knowing what data exists and where), and governance (controls to use data safely and compliantly). Only 7% of organizations have all three, and 97% of them report significant, quantified business outcomes.
Success is claimed far more often than it’s measured. 85% report significant success with data initiatives, but 45% have not formally measured the impact at all, and people metrics like staff satisfaction (29%) are the least tracked of all.
Shadow AI is employees’ use of unapproved AI tools. 95% of organizations know it’s happening and 93% of leaders recognize it as a problem, yet only 25% provide an approved alternative for all employees, leaving data exposed.
Accountability is fragmented: an AI/innovation executive leads at 35% of organizations, technology/engineering at 29%, the CDO at 14%, the CISO at 11%, and 7% share it across functions. Only 28% could confidently detect an agent operating outside approved parameters, and 47% name audit trails as their top compliance concern.
61% say the EU AI Act has already influenced their AI investment or strategy. Confidence is uneven: 65% of CEOs say they’re fully prepared, but only 38% of CTOs and 57% of CISOs agree. Penalties run from €7.5M to €35M, or 1% to 7% of global annual turnover.
Treat data governance and risk management as board-level accountability rather than something to delegate, then build the three readiness blocks. Trust becomes real when it’s measurable, repeatable, and provable, not assumed.
Agentic AI acts on data automatically and at pace. One untrusted input compounds into many errors before anyone reviews them, which is why 88% run AI agents but only 28% are confident they’d detect one operating outside approved parameters.