Frank Balonis on why energy is the unlikely sector leading on AI governance
Energy and utilities organizations post the highest AI Governance Maturity Score (AIGMS) of any sector in the Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report, at 39.2 out of 100. It may not be the industry most people picture when they think of AI governance leadership, but that is precisely why the finding deserves attention.
An index built from what is actually deployed, not what is planned
AIGMS counts how many of 19 AI specific governance capabilities an organization has deployed, such as purpose binding on AI agents, AI specific audit trails, and tested termination controls, then converts that count into an index: AIGMS equals capabilities deployed divided by 19, multiplied by 100. The sector’s general security score, the Data Security Maturity Score (DSMS), works the same way across 11 controls. Energy and utilities scores 43.2 on that measure, the second highest of any sector, just behind financial services.
The report’s combined readiness figure, the Data Security and Compliance Readiness Index (DSCRI), multiplies the two together: DSCRI equals DSMS multiplied by AIGMS divided by 100. Energy and utilities leads every sector on that combined score, at 19.6. Both halves must be strong at once for the result to move, which is why this sector’s showing is worth more than a passing mention.
Why the operational technology habit appears to transfer
The likely driver is structural rather than accidental. Operational technology environments have spent years building a specific discipline: know exactly what has access to what, log it, and restrict it by default, because an ungoverned access path in a physical system carries consequences that are not merely financial. That discipline maps closely onto what AI governance actually requires, namely knowing what an AI system can reach, logging what it does once it has reached it, and restricting that access to an authorized scope from the outset.

Most sectors are building AI governance controls from a standing start, often only after AI deployment has already outrun them. Energy and utilities appear to be doing something different: extending the discipline it already had into a domain that is new.
Representation data in the survey supports this. The sector is showing in the leadership quadrant, where both dimensions are strong at once, and comes in at 1.38 times the rate one would expect given its share of respondents, meaningfully above proportional and second only to healthcare among every sector measured.
The exposure that matters
Of course, the relevant risk is not the industrial control system itself. It is what happens to the sensitive information that moves alongside it. Compliance filings, interconnection studies, vendor contracts, and increasingly AI tools summarizing regulatory submissions or forecasting demand from that same data. The Verizon 2026 Data Breach Investigations Report found that third party and supply chain related breaches now account for 48 percent of all breaches studied, a rise of 60 percent year-on-year. A sector built on dense vendor, contractor, and regulator relationships carries that exposure as a matter of course, whatever the maturity of its control system security.
That is the point worth sitting with. The same discipline that keeps unauthorized access out of a control system needs to extend to the compliance data, vendor exchanges, and AI tools sitting on top of it. The energy sector’s advantage is genuine, but it is a head start on the underlying discipline, not a finished build of the specific controls, purpose binding, and AI specific audit trails among them, that this year’s survey measures directly.
None of this means the work is done. A DSCRI of 19.6 is well above the survey mean of 16.2, yet still a long way short of the top of the scale. IBM’s Cost of a Data Breach Report 2026 puts the average industrial sector breach at five and a half million dollars, a reminder that a vendor-facing or third-party breach in a sector this dependent on external relationships is exactly the profile that figure describes.
Where leaders should look next
If your organization already runs a mature operational technology security program, this year’s data suggests you have more of a headstart on AI governance than you might assume. The underlying habit of default restricted access and consistent logging is largely the same skill. The mistake would be assuming that head start closes the gap on its own. Extend the same rigor explicitly to AI systems, covering purpose binding, AI specific audit trails, and technically enforced access boundaries, rather than assuming operational technology culture covers it by implication.
The energy sector leading this year’s data did not get there by building something new. It got there by refusing to let a well-established discipline stop at the edge of the plant.
Frank Balonis
www.kiteworks.com
As Field CTO at Kiteworks, frank Balonis works with security and compliance leaders across regulated industries on data governance architecture. Having previously worked in both system integrator and service provider environments, Frank’s extensive experience spans a wide range of technologies and applications.

