Report
The Third Annual State of Data Compliance and Security Report: 2026 Edition
Data Management,
Security & Compliance,
AI
-
The Third Annual State of Data Compliance and Security Report: 2026 Edition
- A Letter from the Authors
- High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up
- Why Data Protection Breaks Down in Practice
- How Organizations Are Responding to Growing Data Risk
- Key Takeaways: What It Takes to Protect Data at Scale and AI Speed
- Respondents Snapshot: Segments, Industries, & Job Titles
- Key Terms to Know
Executive Summary: What It Takes to Protect Data in the Age of Agentic Development
Organizations are handling more sensitive data than ever before across development, analytics, and AI workflows. Based on a survey of more than 500 enterprise leaders, our third annual report shows a clear pattern: Policies are in place, but consistent data protection in practice remains a challenge.
As data volumes grow and usage expands, especially with the emergence of agentic development, the gap between policy and execution is becoming clearer. Leaders report strong confidence in their ability to protect sensitive data, yet many still worry about and experience breaches, audit failures, and compliance gaps.
This gap reflects the reality of modern data environments. Organizations must balance security, compliance, speed, and quality, often under pressure from AI-driven development and a growing need for production-like data. Closing this gap will require approaches that can scale with data growth while still maintaining data usability and performance.
Key Findings
A gap between policy and practice.
- 99% of organizations have data masking mandates, but 84% still allow compliance exceptions.
- (Read more: High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up)
Confidence does not reflect outcomes.
- While 98% of leaders are confident in protecting sensitive data...
- 77% are concerned about data breaches and theft in non-production environments, and 74% are concerned about audit issues or failures...
- And 43% have experienced audit failures, while 34% have experienced breaches or theft in non-production environments.
- (Read more: High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up)
The need for quality data and the challenges of scale drive risk.
- Leaders say the top barriers to protecting all sensitive data in non-production are their concerns about data quality (24%) and the high level of effort involved (23%).
- (Read more: Why Data Protection Breaks Down in Practice)
Data growth is expanding the exposure footprint.
- 57% report increasing volumes of sensitive data in non-production, driven by faster release cycles (31%) and increased use of data for decision-making (30%).
- (Read more: Why Data Protection Breaks Down in Practice)
AI introduces new complexity... and contradictions.
- While 86% have AI data privacy mandates and 98% feel confident about protecting sensitive data in AI workflows...
- 68% are concerned about data leaks and 62% about training data breaches in these environments.
- (Read more: High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up)
Most organizations use a portfolio approach to protect sensitive data in non-production.
- 86% use static masking.
- 60% use dynamic masking.
- 51% use synthetic data.
- (Read more: How Organizations Are Responding to Growing Data Risk)