Thoropass today released its 2026 State of Audit and Compliance Report, revealing that AI adoption has rapidly become the most significant new source of IT security compliance risk. Almost 7 in 10 sec...

Majority of organizations losing the race to control use of corporate and personal AI solutions in the workplace, increasing the “governance gap”
NEW YORK: Thoropass today released its 2026 State of Audit and Compliance Report, revealing that AI adoption has rapidly become the most significant new source of IT security compliance risk. Almost 7 in 10 security and compliance leaders say AI adoption is outpacing their security and compliance controls, signaling a growing governance gap.
The report, based on a survey of more than 500 security, IT, and compliance professionals, shows that while compliance programs are more mature than ever, they are under increasing strain from multi-framework audits, evidence management overhead, and the fast rise of AI-related risk.
“AI has moved faster than governance,” said Sam Li, CEO of Thoropass. “Most organizations didn’t plan for how quickly employees and teams would adopt AI tools, and compliance programs are now racing to catch up. What we’re seeing is a widening gap between innovation and oversight.”
AI is becoming integral not just to organizations’ technology stacks, but to how companies operate. That same technology can and should be used to help organizations run smoother, more efficient audits, empowering them to eliminate manual effort, improve evidence quality, and give teams confidence as audit expectations evolve.”
Key findings from the research include:
AI Has Become the Leading Compliance Risk
AI-related concerns now eclipse traditional security threats in both perceived likelihood and potential regulatory impact:
Compliance Maturity Is High, but Audit Friction Persists
Even as organizations report mature compliance programs, operational inefficiencies remain widespread:
The report finds that compliance is increasingly viewed as an ongoing risk management function – driven by security posture, insurance requirements, and customer trust – rather than a once-a-year certification exercise.
“The audit model itself is changing. Organizations don’t just need more controls - they need audits that operate continuously and keep pace with how modern systems actually work. The future of audit is less manual collection and more real-time assurance,” continued Li.
What This Means for IT Audit in 2026
The definition of “audit-ready” is changing. Organizations that can consolidate compliance workflows, maintain up-to-date evidence, and integrate AI governance into existing frameworks will be better positioned for both upcoming audits and regulatory scrutiny.
Download the full 2026 State of Audit and Compliance Report to see how your organization compares.
Survey methodology: 536 InfoSec leaders across SMB to enterprise organizations were surveyed online in January 2026. The breakdown of respondents was:
By role:
By company size:
About Thoropass
Thoropass is the only end-to-end cybersecurity auditor. Our Audit Lifecycle Platform combines continuous, AI-powered evidence collection with the industry’s most advanced suite of AI agents and a highly experienced team of auditors to deliver comprehensive, trusted security audits.
Thoropass offers the most flexible and scalable solution for organizations to ensure compliance with more than 30 frameworks, including SOC 2, ISO, PCI, and HITRUST. The Thoropass Audit Lifecycle Platform works seamlessly with any GRC platform and systems of record, ensuring organizations have absolute confidence in their audit–regardless of which software they use across the organization.
To learn more about doing your cybersecurity audits the Oro way, visit us at thoropass.com.
Fonte: Business Wire
Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…
G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes
Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries
Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…
$BABA #alibaba--Alibaba Group Holding Limited (NYSE: BABA and HKEX: 9988 (HKD Counter) and 89988 (RMB Counter), “Alibaba” or “Alibaba Group”) today announced…
RSA Conference -- Cobalt, the pioneer of penetration testing as a service (PTaaS) and a leading provider of human-led, AI-powered offensive security solutions,…
GTC 2026 – EQTY LAB announced today at NVIDIA GTC 2026 the launch of its new Verifiable Runtime, a solution engineered to secure and optimize autonomous…
FiscalNote Holdings, Inc. (NYSE: NOTE) (“FiscalNote” or the “Company”), a global leader in AI-driven policy and regulatory intelligence, today reported…