Breaking
AI & MLDeveloping Story

AI Training Gap Tests Governance

ISACA research shows 32% of digital trust professionals say their organizations fail to address AI risks, as adoption climbs.

··4 hours ago·6 min read
a computer circuit board with a brain on it
Photo by Steve A Johnson on Unsplash

Artificial intelligence is spreading through enterprise operations faster than many organizations can build the skills and oversight structures to manage it safely. That mismatch was the focus of a media roundtable at ISACA's Europe conference in Munich, Germany on 8 October, where the training and certification body outlined a coming AI governance credential and pointed to persistent gaps in workforce readiness.

ISACA plans to launch an AI governance certification in early 2027, currently accepting applications in beta phase. The credential will complete a series of AI-focused certifications the organization has been rolling out, aimed at helping professionals manage the technology securely and responsibly.

Governance gap persists despite adoption

ISACA's previous research revealed that only 32% of digital trust professionals believe their organizations adequately address AI risks such as privacy, bias and security, even as workplace adoption widens. That figure has been a recurring signal for ISACA as it builds out its certification lineup.

The incoming governance certification joins existing credentials: Advanced in AI Audit (AAIA), Advanced in AI Security Management (AAISM) and Advanced in AI Risk (AAIR). Each targets a different slice of the professional population that touches AI systems — auditors, security managers, risk specialists and others.

At the same time, the organization's State of Cybersecurity 2026 report found that 54% of organizations are involved in onboarding or implementing AI solutions, up from 46% in 2024. The two data points together describe a workforce adopting AI at scale while a substantial share of professionals still see governance as inadequate.

An umbrella over functions

Chris Dimitriadis, chief global strategy officer at ISACA, framed the governance certification as a way to connect disciplines that have traditionally operated in separate lanes. During the roundtable, he described the credential's purpose in terms of unifying oversight across cyber, audit and risk functions.

“The governance certification is important in terms of providing an umbrella around the operations of professions from cyber to audit to risk. We’re trying the help individuals in controlling and governing AI rather than having AI on the loose,”

— Chris Dimitriadis, chief global strategy officer at ISACA

That "umbrella" framing points to a structural reality: AI deployments rarely sit with a single team. Security teams monitor model behavior, auditors check controls, risk managers assess exposure, and IT managers handle configuration. A governance credential, as ISACA describes it, is meant to give all of those roles a shared vocabulary and baseline.

Training uptake and the missing employees

Dimitriadis said uptake of ISACA-provided AI trainings had been positive, especially in AI-forward regions like Europe, the US and Asia. But aggregate enthusiasm does not mean individual organizations have rolled out programs broadly.

ISACA's 2025 AI Pulse Poll, which surveyed more than 3000 digital trust professionals, found that within organizations, 32% said there is no AI training provided to any employees. That number underscores a gap between the availability of credentials and the internal training programs that would prepare staff to use them.

Dimitriadis argued the need cuts across job titles, not just technical staff:

“The message we’re trying to convey is that we need more AI training, specialized AI training across the domain, whether you’re an auditor, if you’re a cyber professional, a risk manager, project manager or IT manager dealing with governance of AI technology, we need more AI training. We need this to be holistic and well rounded with soft skills in order for them to be successful in their job.”

That emphasis on soft skills reflects a view that AI governance is not purely a technical task. Communication, judgment and cross-functional coordination are part of the job description as ISACA frames it.

What professionals will still do

From its 2026 research, ISACA has concluded that AI is set to dominate most of the technical and orchestration tasks. Professionals will therefore focus on tasks that require context and intuition, as well as communication. These include governance, AI configuration and monitoring, and final decision making.

If that prediction holds, the value of human roles shifts toward oversight and interpretation rather than execution. This is consistent with the governance certification's stated aim: equipping people to control AI systems rather than compete with them on raw processing.

Security skills that matter most

ISACA's State of Cybersecurity report also identified the security skills respondents considered most important. Threat detection and response alongside identity and access management represented the most important security skill needed. Also highlighted were vulnerability management, data security and incident response skills.

Those priorities map onto AI risk in direct ways. Identity and access management controls who can reach models and data; vulnerability management covers the software supply chain around AI tools; incident response determines how quickly an organization recovers when something goes wrong. The governance credential ISACA is preparing sits above these operational skills, providing the policy and oversight layer.

The numbers behind the gap

Several figures from ISACA's research illustrate the scale of the challenge and the pace of adoption:

  • 32% of digital trust professionals believe their organizations adequately address AI risks such as privacy, bias and security.
  • 32% said there is no AI training provided to any employees, per the 2025 AI Pulse Poll of over 3000 digital trust professionals.
  • 54% of organizations are involved in onboarding or implementing AI solutions, up from 46% in 2024, according to ISACA's State of Cybersecurity 2026 report.

Read side by side, the percentages suggest a workforce that is adopting AI faster than it is training for it. The governance certification, scheduled for early 2027, is ISACA's attempt to close that distance with a formal credential rather than ad hoc upskilling.

Why the governance umbrella matters

ISACA's framing of the certification as an "umbrella" is a response to how AI work actually happens inside companies. Audit teams need to know what to inspect; risk teams need consistent ways to score exposure; security teams need controls that match the models they defend; IT managers need configuration guidance that does not conflict with policy. A shared credential does not solve any single function's problem, but it can reduce the friction when those functions must coordinate.

The organization's own data suggests coordination is not yet the norm. With only 32% of digital trust professionals rating their organizations' AI risk handling as adequate, and a third reporting no training at all, the governance layer is in many cases either missing or informal.

ISACA is currently accepting applications for the governance certification in beta phase, ahead of the early 2027 launch. The other AI credentials — AAIA, AAISM and AAIR — are already part of its lineup, and the new governance credential will complete the set.

What this means for organizations

The gap ISACA describes is not primarily a tooling problem. It is a skills and oversight problem, and it exists at the same time that more than half of organizations are actively implementing AI. That combination leaves less room for the assumption that governance will catch up on its own.

For security and risk leaders, the practical implication is that AI training may need to be treated as an organizational requirement rather than an optional credential for interested staff. ISACA's research points to roles across audit, risk, project management and IT as candidates for that training, not just security specialists.

The early 2027 governance certification gives organizations a defined target to plan around, but the data on missing internal training suggests the harder work is inside companies: deciding who owns AI oversight, how that oversight is documented, and how staff are prepared to exercise it. Without that, the governance umbrella ISACA is building may have fewer people trained to hold it.

#ai governance#ai training#isaca#security skills#certification

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories