-
The Third Annual State of Data Compliance and Security Report: 2026 Edition
- A Letter from the Authors
- High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up
- Why Data Protection Breaks Down in Practice
- How Organizations Are Responding to Growing Data Risk
- Key Takeaways: What It Takes to Protect Data at Scale and AI Speed
- Respondents Snapshot: Segments, Industries, & Job Titles
- Key Terms to Know
Report > The Third Annual State of Data Compliance and Security Report: 2026 Edition
High Confidence, Persistent Risk: Why Data Protection Isn’t Adding Up
Mandates Are Widespread, but Enforcement Breaks Down in Practice
As organizations scale development, analytics, and AI initiatives, they create more copies of sensitive data in non-production environments. These environments often mirror production systems, but they are typically accessed by more people and governed by fewer controls. This expands the exposure footprint of sensitive data across the enterprise.
In our survey of more than 500 enterprise leaders, 84% said they are concerned about this expanded exposure footprint in non-production environments.
As data grows and spreads outside production, leaders see a clear and increasing risk of exposure.
Non-production environments = environments used for purposes other than live, operational use. They are typically used for software development, testing, and staging, business data analysis and reporting (BI), and AI/ML model training and fine-tuning.
How concerned are you about the expanded exposure footprint in non-production environments at your organization?
84% concerned about expanded exposure footprint
| Category | Extremely concerned | Very concerned | Moderately concerned | Slightly concerned | Not at all concerned |
|---|---|---|---|---|---|
| 2 | 39 | 43 | 16 | 0 |
Building on this concern, leaders are also worried about the consequences. 77% are concerned about data breaches and theft in non-production environments, and 74% are concerned about audit issues or failures.
What is your level of concern with the following involving sensitive data in non-production environments?
77% concerned about breaches, 74% about audit issues/failures
| Category | Extremely concerned | Very concerned | Moderately concerned | Slightly concerned | Not at all concerned |
|---|---|---|---|---|---|
| Data breaches/theft | 7 | 29 | 41 | 22 | 1 |
| Audit issues/failures | 5 | 29 | 40 | 23 | 3 |
| Regulatory compliance | 5 | 20 | 36 | 35 | 4 |
| Ransomware | 3 | 15 | 32 | 34 | 16 |
The vast majority of organizations already address these risks at a policy level.
Data masking, in particular, has become a near-universal standard. 99% of organizations report having a masking mandate or policy in place for non-production environments, underscoring its role as a foundational protection strategy.
Does your organization have a data masking mandate/policy in non-production environments?
| Category | ||||
|---|---|---|---|---|
| Yes, currently have a mandate/policy | 99 | |||
| No, but we expect to have one in the next 12 months | 1 | |||
| No, but we expect to have one more than 12 months from now | 0.5 | |||
| No, and we do not expect to have one | 0 |
Yet, in practice, most organizations do not apply these protections consistently. 84% report allowing data compliance exceptions in non-production environments.
When does your organization allow data compliance exceptions in non-production environments? Select all the apply.
84% allow data compliance exceptions
| Category | Allow exceptions | Do not allow exceptions |
|---|---|---|
| We use data minimization | 48 | |
| We allow use of limited data set | 38 | |
| If business accepts the risk | 29 | |
| Explicit consent has been given from the data subject | 12 | |
| We do not allow any data compliance exceptions | 16 |
Do Leaders Have a False Sense of Confidence?
We see a clear contradiction in this data.
Leaders obviously recognize the risks, and they have mandates in place — but they still allow exceptions that weaken those controls.
We have found that teams often have multiple opportunities to bypass protections to avoid what they see as barriers. (We’ll explore these perceived barriers more in Why Data Protection Breaks Down in Practice.)
Back to top
In AI, Confidence Is High — But So Are Concerns
AI and analytics are expanding how organizations use sensitive data — and increasing the complexity of protecting it.
This shift is creating new challenges in how data protection policies are applied in practice. Agentic AI accelerates these challenges by increasing the speed, scale, and autonomy of data access in ways that are harder to govern consistently.
On Paper, Enterprises Appear Prepared for AI
For most organizations, formal policies are in place to guide how sensitive data should be handled in AI/ML environments. 86% of organizations report having a corporate data privacy mandate for AI, ML, and analytics workflows.
Do you have a corporate data privacy compliance mandate for AI/ML and analytics workflows?
| Label | Value |
|---|---|
| Yes | 86 |
| No | 13 |
| I'm not sure | 1 |
This level of preparedness extends to confidence in execution. 98% of leaders say they are confident in their ability to protect sensitive data in AI workflows, with most describing themselves as very confident.
How confident are you that your organization is prepared with the necessary tools and approaches to protect sensitive data in AI?
98% confident
| Category | Extremely confident | Very confident | Moderately confident | Slightly confident | Not at all confident |
|---|---|---|---|---|---|
| 6 | 65 | 27 | 10 | 1 |
On the surface, organizations appear well-prepared for AI data protection.
Despite This Confidence, Concerns About AI Data Risks Are High
68% of leaders are concerned about data leaks in AI/ML development, and 62% are concerned about the theft or breach of model training data.
This concern extends across multiple risk areas. More than half of respondents also report concern about:
- Unauthorized data access (53%)
- Privacy compliance and audits (51%)
- Personal data re-identification (51%)
What is your level of concern with the following involving AI/ML development and training environments at your organization?
Concerned about: Data leakage (68%), theft/breach (62%), unauthorized access (53%), privacy compliance & audits (53%), data re-identification (51%)
| Category | Extremely concerned | Very concerned | Moderately concerned | Slightly concerned | Not at all concerned |
|---|---|---|---|---|---|
| Data leakage | 3 | 23 | 42 | 28 | 4 |
| Theft or breach of model training data | 5 | 20 | 42 | 31 | 3 |
| Unauthorized data access | 5 | 16 | 35 | 41 | 4 |
| Privacy compliance and audits | 4 | 14 | 33 | 44 | 5 |
| Personal data re-identification | 3 | 10 | 38 | 42 | 7 |
The high level of concern is warranted. AI and ML environments are often less governed than production systems, which increases the risk of data breaches and compliance issues. As organizations adopt agentic development, this risk grows further. LLMs introduce new pathways for data exposure and leaks, particularly in agentic workflows where models act on and generate data autonomously, while rapidly expanding data usage continues to increase the overall attack surface.
So, we’re seeing that on the one hand, most organizations express confidence in their AI data protection capabilities. On the other hand, they feel there is significant and persistent risk with these environments at their organization.
What is the reason for this contradiction? We have some ideas. (We will dig into them in Why Data Protection Breaks Down in Practice.)
Back to top
Leaders Should Be Concerned. Many Experienced Breaches, Audit Failures, & More
The concerns that leaders have across both traditional and AI environments and workflows are not just theoretical. They reflect real problems organizations are already having: 43% report audit issues or failures in non-production environments, and 34% have experienced data breaches or theft related to non-production.
This reinforces the broader contradiction we see throughout the data. Leaders express strong confidence in their ability to protect data, yet many are already facing the very risks they fear and aim to prevent — across both traditional non-production environments and emerging AI use cases.
Has your organization experienced any of the following involving sensitive data in non-production environments?
| Category | Yes | No | I'm not sure |
|---|---|---|---|
| Audit issues/failures | 43 | 56 | 1 |
| Data breaches/theft | 34 | 64 | 2 |
| Regulatory non-compliance fines | 14 | 84 | 2 |
| Ransomware | 8 | 87 | 5 |
Complying with Multiple Privacy Regulations Adds Complexity
Furthermore, 100% of organizations report having sensitive data in non-production that is subject to regulatory requirements, most commonly PCI DSS (60%) and GDPR (41%), as well as CCPA (26%), LGPD (21%), and the EU AI Act (14%).
As we can see, there is a high level of overlap in this data; Many organizations must comply with multiple data privacy regulations at once. Keeping on top of all these regulations and remaining compliant with them is a growing challenge that requires identifying and protecting all sensitive data.
Does your organization have data in non-production environments that is subject to any of the following data privacy regulations
| Category | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| PCI DSS | 60 | ||||||||||
| GDPR | 41 | ||||||||||
| CCPA | 26 | ||||||||||
| LGPD | 21 | ||||||||||
| EU AI ACT | 14 | ||||||||||
| GLBA | 12 | ||||||||||
| HIPAA | 10 | ||||||||||
| FINRA | 8 | ||||||||||
| DORA | 7 | ||||||||||
| Other | 44 | ||||||||||
| No | 0.5 |
Watch How to Mask Data for Regulations Like GDPR
Perforce Delphix lets you automatically mask sensitive production data to comply with regulations like GDPR, PCI DSS, HIPAA, and many more. It does this by profiling your production environments to find where sensitive data. Then, masking algorithms will mask data, keeping it realistic and maintaining referential integrity across datasets and systems.