The Observability Gap Report
The first primary research study to quantify AI-security observability maturity across regulated mid-market organizations nationwide — how many have generative AI in production with no AI-specific monitoring, no shadow-AI inventory, and no board-level AI risk briefing. The report launches Wednesday, September 9, 2026, with vertical-specific cuts through Q4 2026.
Research Scope
What the Report Measures
The 2026 report is built on responses from at least 300 mid-market organizations between 100 and 2,500 employees, spanning healthcare, manufacturing, defense, financial services, and K-12 education across the United States. The instrument is a 28-question battery covering AI adoption maturity, AI security observability, governance and policy, incident history, current operating model, and budget direction.
Headline statistics the report will publish
- The percentage of mid-market organizations with generative AI in active production use that have no AI-specific security monitoring
- The percentage that have not conducted a shadow-AI inventory in the past 12 months
- The percentage with AI in production but no formal AI Acceptable Use Policy
- The percentage whose board has not received a formal AI risk briefing in the past 12 months
- The percentage whose current IT or security provider does not offer AI-specific capabilities
- Cross-tabulations by vertical (healthcare, manufacturing, defense, financial services, K-12), by employee band (100–499, 500–1,499, 1,500–2,500), by region, and by incident-history segment
Methodology
Built for Examiner-and-Analyst Credibility
The report is built on a methodology designed to withstand scrutiny from examiners, analysts, and trade press alike. Recruitment combines paid B2B panel access, trade-association partnerships across manufacturing, healthcare finance, and hospital systems, and direct outreach to confirmed decision-makers.
95% Confidence Intervals
Sample sizes are reported by segment, with confidence intervals on every headline statistic and significance testing on cross-tabulated sub-samples.
Independent Peer Review
The analysis is reviewed by a statistician unaffiliated with Armorstack — a deliberate choice that makes the report citable by analysts and trade press, not dismissible as vendor-funded research.
Full Methodology Disclosure
Sample sizes, weighting approach, recruitment channels, response rates, field period, instrument cognitive pretest results, and conflicts-of-interest disclosure all publish in the report appendix.
Participate
Participate in the Survey
The survey is open to security and IT leaders at mid-market organizations between 100 and 2,500 employees in regulated industries. Participation takes approximately 10–12 minutes. Respondents receive:
Embargoed Early Access
An embargoed copy of the published report 48 hours before public release.
Your Benchmark Report
A one-page benchmark comparing your organization to survey averages.
Strategic Briefing
An optional 30-minute briefing on how the findings apply to your industry — no commitment required.
To request the survey link, email [email protected] with subject “Mid-Market AI Security Survey 2026,” or use the button below.
Publication Schedule
When Each Release Publishes
Looking Ahead
Future Reports
The Observability Gap Report is intended as a recurring annual study. The 2027 report will measure year-over-year change in the same headline statistics, producing a defensible time-series view of how mid-market AI security capability is evolving. Subscribers to the 2026 report receive priority access to the 2027 survey instrument.
For organizations that want to help shape the 2027 instrument — suggesting additional questions, advocating for specific vertical cuts, or partnering on co-branded data collection — contact Armorstack directly.
Subscribe to the Report
Receive the September 9, 2026 launch and every subsequent vertical cut. No cost. Unsubscribe anytime.