Rapid7's newly published Omdia research confirms that AI has crossed the mainstream threshold in security operations, shifting enterprise priorities from deployment to governance and accountability [1]. The data reveals a structural deficit: 75% of organizations experienced a production incident in the last 12 months where AI was a contributing factor [2], yet foundational controls remain thin across the industry [2]. As the global cybersecurity market tracks toward $338B by 2029 at an 11.6% CAGR [3], vendors with embedded AI governance capabilities are positioned to capture disproportionate share.
What is Covered in this Article
- AI mainstream adoption in the SOC and the shift to governance [1]
- Measurable governance control gaps across enterprise security teams [2][2]
- Market growth backdrop and vendor positioning opportunity [3]
- Organizational accountability structures and their current limitations [4]
The News: Rapid7 published Omdia research revealing a significant AI governance gap in security operations, finding that AI has become mainstream in the SOC and that the industry conversation has shifted decisively from adoption to governance and accountability [1]. The research surfaces a measurable structural deficit: 75% of organizations reported experiencing a production incident in the last 12 months where AI was a contributing factor [2]. Despite this exposure, agent governance controls remain nascent, with agent audit logging use by only 45% of respondents, human approval gates in place at just 32%, and pre-promotion scoring applied by a mere 12% [2]. The findings arrive as the global cybersecurity market is forecast to grow from approximately $195B in 2024 to $338B by 2029 at an 11.6% CAGR [3].
AI Governance Gap in the SOC: Who Owns Accountability When Agents Fail?
Analyst Take: Rapid7's Omdia research lands at a pivotal moment: AI in the SOC is no longer an emerging experiment but an operational reality that enterprises are struggling to govern [1]. The gap between AI deployment velocity and accountability infrastructure is not theoretical, it is producing real incidents at scale [2]. Vendors that move first to close this gap with integrated governance tooling stand to define the next competitive dimension in security operations.
From Adoption to Accountability: A Threshold Has Been Crossed
The framing of AI in security has fundamentally changed. The question is no longer whether to deploy AI in the SOC but how to ensure it operates within defined, auditable boundaries [1]. This shift matters because it resets buyer priorities. Procurement conversations that once centered on detection accuracy and automation breadth now increasingly include questions about transparency, auditability, and human oversight. Rapid7's research validates what many practitioners have sensed: the industry has entered a new phase where governance is a first-order requirement, not an afterthought. Enterprises that deployed AI quickly to gain operational advantage are now confronting the accountability debt that came with that speed.
The Governance Gap Is Measurable and Consequential
The data behind the governance gap is stark. Futurum Research finds that 75% of organizations reported experiencing a production incident in the last 12 months where AI was a contributing factor [2]. Yet the controls designed to prevent or contain such incidents remain underpenetrated. Agent audit logging, the most basic accountability mechanism, is use by only 45% of respondents. Human approval gates, which provide a critical check on autonomous agent actions, are in place at just 32%. Pre-promotion scoring, a more sophisticated control for validating AI outputs before they influence production decisions, is applied by only 12% [2]. Separately, while 56% of organizations have established a dedicated AI governance council, nearly half still lack this foundational structure entirely [4]. The pattern is consistent: governance infrastructure has not kept pace with AI deployment, creating systemic accountability exposure across the enterprise security stack.
Market Tailwinds Reward Governance-First Positioning
The cybersecurity market provides a compelling growth backdrop for vendors that address this gap. The market is forecast to expand from approximately $195B in 2024 to $338B by 2029, compounding at 11.6% annually [3]. Within that trajectory, the governance and compliance layer represents an increasingly differentiated value proposition. Enterprises facing regulatory pressure, board-level scrutiny of AI risk, and the operational reality of AI-contributed incidents are willing to pay for solutions that provide transparency and accountability alongside detection and response. Rapid7's positioning, anchored in Omdia research that frames the governance gap as an industry-wide challenge, allows the company to lead the conversation rather than respond to it. Vendors that embed governance controls natively into their SOC and IRM platforms are better placed to capture share as buyers consolidate around accountable AI.
What to Watch
- Governance control adoption rates: whether agent audit logging and human approval gate penetration accelerates meaningfully beyond current 45% and 32% baselines over the next two quarters [2]
- Regulatory catalyst: whether pending AI liability or cybersecurity compliance frameworks in the EU or US formalize governance control requirements, accelerating enterprise procurement timelines [4]
- Competitive differentiation: how rival SOC and IRM vendors respond to Rapid7's governance-first positioning through product roadmap updates or partnership announcements in Q4 2026
- Incident trend trajectory: whether the 75% AI-contributed incident rate reported over the past 12 months rises, stabilizes, or declines as governance controls mature [2]
- Governance council formation: how quickly the roughly 44% of organizations currently lacking a dedicated AI governance council move to establish one, signaling institutional readiness to invest in supporting tooling [4]
Sources
1. Rapid7 Omdia Research Reveals AI Governance Gap as …, Rapid7, August 2026
2. AI Incidents Outrun AI Controls, Futurum Research, July 2026
3. 1H 2026 Cybersecurity Market Sizing & Five-Year Forecast, Futurum Research, June 2026
4. CEO Governance Infographic, Futurum Research, January 2025
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Read the full Futurum Group Disclosure.
Other Insights from Futurum:
Integrated Platform Strategy Drives Rapid7 Growth
Rapid7's 2026 PACT: Channel Growth
Author Information
This content is written by a commercial general-purpose language model (LLM) along with the Futurum Intelligence Platform, and has not been curated or reviewed by editors. Due to the inherent limitations in using AI tools, please consider the probability of error. The accuracy, completeness, or timeliness of this content cannot be guaranteed. It is generated on the date indicated at the top of the page, based on the content available, and it may be automatically updated as new content becomes available. The content does not consider any other information or perform any independent analysis.

