aisecurity.llc
Survey Findings
What the primary research layer shows across all four survey instruments and the flash baseline.
About this survey program
Four purpose-built survey instruments — targeting hiring managers, security leaders, AI security practitioners, and adjacent security engineers — plus a 60-second flash baseline provide a primary research layer across 385 respondents. The program was designed as a claim-validation engine, not a pulse survey: each instrument uses a 12-question shared core that enables cross-persona comparison, plus a 10–15 question persona-specific module targeting materially different operational realities. Findings triangulate with ATS corpus analysis, arXiv research momentum data, and GitHub tooling activity to provide multi-signal validation for the report's 15 named findings.
Key findings — cross-persona
Risk signal
25%
25% report no clear AI security owner
Ownership fragmentation is the most-cited blocker across all four personas. No designated owner means controls cannot be commissioned, evidence cannot be required, and accountability cannot be assigned — the structural precondition for most of the technical deficits this report documents from the hiring corpus side.
Validates → The vCISO Vacuum
Validates finding
2 / 5
Avg program maturity sits at 2/5 — emerging band
Scores cluster in the emerging-to-developing range, consistent with a discipline that has achieved executive awareness but has not built systematic engineering delivery. Hiring managers score lowest, suggesting organizations are staffing roles ahead of the programs those roles are meant to build.
Validates → The Frankenstein Role
Validates finding
88%
88% describe AI Security Engineering as a distinct discipline
Market recognition of a new discipline is outpacing formal role definition. Respondents who affirm AI security as distinct correlate with higher program maturity, suggesting that conceptual clarity is a leading indicator of operational investment — and that hiring language needs to move faster.
Validates → The Frankenstein Role
Risk signal
34%
"AI asset inventory gaps" is the top-cited cross-persona risk
34% of cross-persona respondents selected this as a top-5 concern. Practitioner responses confirm it operationally — 49% have observed sensitive data leakage in prompts or outputs. Yet hiring language is dominated by legacy compliance frameworks by 108:1 over AI-native controls, a divergence the Compliance Reflex finding quantifies from the ATS corpus.
Validates → The Compliance Reflex
Opportunity
79%
79% of adjacent engineers plan to enter AI security
A latent workforce supply exists — but it is contingent on structured transition pathways. Without them, this supply signal will not convert to actual capacity. This reinforces the Entry-Level Extinction finding from the ATS corpus, where zero junior pathways exist despite 290× role growth since 2022.
Validates → Entry-Level Extinction
Per-persona narrative
Recruiters & Hiring Managers
Staffing roles ahead of the programs
With an average maturity of 1.8/5, hiring managers are building requisitions before building programs. The hardest skills to source — prompt injection testing, agent security, secure AI SDLC — are precisely the capabilities that require program infrastructure to apply.
Take this survey →CISOs & Security Leaders
Ownership fragmentation at the leadership layer
32% of security leaders report no clear AI security owner — the highest rate across all personas. Budget fragmentation mirrors this: 23% report no dedicated AI security budget, while 36% rely on informal allocations from the general security envelope.
Take this survey →AI Security Engineers & Practitioners
Observed risk confirms the theoretical hierarchy
Practitioners have operationally encountered what hiring managers are trying to staff against: 49% have observed sensitive data leakage in prompts or outputs, 44% have seen insecure RAG retrieval, and 43% report poor authorization around retrieved data. These are not theoretical risks.
Take this survey →Adjacent Security Engineers
A latent pipeline waiting for pathways
53% report active or near-term transition interest into AI security. But 30% cite no clear ownership structure as the reason they haven't moved yet. The workforce is willing; the organizational scaffolding is missing.
Take this survey →Methodology and interpretation guidance
- ›Minimum defensible sample threshold: 30 responses per persona bucket. Recommended credible baseline: 50.
- ›All findings are aggregate directional signals from self-reported responses — not independent audits of individual organizations.
- ›Psychometric and survey outputs reflect role-language and self-reported indicators, not individual capability diagnoses.
- ›Sponsor support does not influence methodology, scoring, or editorial conclusions.
- ›Cross-persona comparisons use a 12-question shared core present in all four full survey instruments.
- ›Results are intended for triangulation with ATS corpus data, arXiv research signals, and GitHub tooling activity — not as standalone primary evidence.
Aggregate findings — 385 respondents · cross-persona
survey
Top AI Security Risks — Cross-Persona
Ranked by selection frequency across all four survey personas (select up to 5)
survey
AI Security Ownership — Who Holds It?
Cross-persona (select all that apply)
survey
Is AI Security Engineering a Distinct Discipline?
Cross-persona belief distribution
survey
Average Program Maturity by Persona
Self-reported maturity index (0–5 scale). Dashed line = developing threshold (2.5).
Cross-persona contrasts
Same question, different groups. Where responses diverge reveals accountability gaps, perception splits, and unresolved ownership questions.
Survey Research
AI Security Risk Priorities — By Persona
% of respondents per persona citing each risk as a top-5 concern. Reveals where hiring managers, CISOs, practitioners, and adjacent engineers prioritize differently.
Survey Research
AI Security Ownership — Each Persona's Perception
Each persona's view of who currently owns AI security. Divergence between leadership and practitioners reveals accountability gaps.
Survey Research
"Distinct Discipline" Belief — Compared Across Personas
Does each group believe AI Security Engineering is its own field? Hiring managers and practitioners often diverge significantly on this question.
Leadership signals — CISOs & security leaders
Control maturity self-reports, blockers, budget formality, and board pressure reported by CISOs and security leaders only.
Survey Research
AI Security Control Maturity — Leadership Baseline
CISOs rated 12 controls on 0–5 (Not started → Optimized). Sorted weakest-first. n=75 security leaders.
Survey Research
What Is Blocking AI Security Progress? (CISOs)
Top blockers cited by CISOs and security leaders. Multi-select. n=75.
Survey Research
AI Security Budget Formality (CISOs)
How formal is the AI security budget? n=75 security leaders.
Survey Research
Board-Level AI Security Pressure (CISOs)
How much pressure do boards apply on AI security? n=75.
Practitioner signals — AI security engineers
What practitioners have observed in production, where they see the biggest gaps, and what they believe leaders most misunderstand.
Survey Research
AI Security Issues Observed in Production (Practitioners)
What have practitioners personally witnessed? Multi-select. These are real incidents, not hypothetical. n=70.
Survey Research
Where Is the Biggest Gap? (Practitioners)
What practitioners identify as the primary deficit holding AI security back. Single-select. n=70.
Survey Research
What Leaders Most Misunderstand About AI Security (Practitioners)
Practitioners were asked: what is the most common leader misunderstanding about AI security work? n=70.
Adjacent engineer signals — workforce readiness
Confidence across AI security tasks, transition barriers, and training needs from adjacent security engineers considering the move into AI security.
Survey Research
Adjacent Engineer Confidence by AI Security Task
Confidence on a 1–5 scale (1=Not confident, 5=Very confident). Sorted weakest-first. Shows where adjacent engineers feel least prepared. n=100.
Survey Research
What Stops Adjacent Engineers Entering AI Security?
Main barrier to transition. Single-select. n=100 adjacent security engineers.
Survey Research
Training Adjacent Engineers Want for AI Security
What learning would most help adjacent engineers move into AI security? Multi-select. n=100.
Hiring signals — managers recruiting AI security talent
Hardest skills to source, preferred candidate backgrounds, and the most common reasons candidates fail AI security interviews.
Survey Research
Hardest AI Security Skills to Hire (Hiring Managers)
Which skills are most difficult to source in candidates? Multi-select. n=80.
Survey Research
Preferred Candidate Background (Hiring Managers)
Which background do hiring managers most value when recruiting AI security engineers? n=80.
Survey Research
Why AI Security Candidates Fail Interviews (Hiring Managers)
What causes AI security candidates to be rejected? n=80 hiring managers.
Contextual segments — org size, adoption stage, archetype
How maturity scores shift with organization size and AI adoption stage. Flash baseline archetypes show the distribution of current security posture in 60-second self-reports.
Survey Research
Program Maturity by Organization Size
Self-reported security maturity (0–5) segmented by headcount. Larger organizations generally report higher maturity — but the gap is smaller than expected.
Survey Research
Program Maturity by AI Adoption Stage
Organizations that treat AI as business-critical report meaningfully higher security maturity. Adoption stage is the strongest single predictor of maturity in this dataset.
Survey Research
Organization AI Security Archetype (Flash Baseline)
60-second flash respondents self-assigned to an archetype based on current state. n=60.