Eudai · Market report · September 2026
Where innovation and security are heading.
8 instruments reading the same domain at different lags — search demand, regulation, certification, analyst coverage, disclosure language, job postings, private capital and public procurement — across 2022 to 2026.
Executive summary
Eight instruments trace the same domain from 2022 to 2026. They point in the same direction, but move at different speeds. That gap is where a change in language becomes a positioning decision.
Five findings
Established terms still carry most of the attention. AI-framed language is opening a new route into capabilities many teams already have.
Across a 125-term control basket outside the domain, comparable business language fell more than twice as far. What is distinctive here is the speed of AI-language arrival — roughly twice the control rate.
DORA-related search attention has fallen to 24% of its peak since the deadline passed. Regimes with obligations still ahead sit at 82% of peak and continue to rise.
Assessment, audit, and certification terms grew across both established and AI-framed subjects. Platform and software language grew only where the subject made that framing meaningful.
In 2024, 2,176 US filings referred to business continuity.4 ISO reports 4,595 valid ISO 22301 certificates worldwide across its reported history.1 Disclosure is widespread; formal certification remains comparatively limited.
The instrument lag
Language moves first. Private capital follows. Public procurement arrives later, but is now the steepest curve in the set. Each instrument measures a different unit; none measures market size.
Three implications
Retain the reach of established terms while building authority in the arriving ones. The capability may be the same; the route through which people find it is changing.
Assessment, audit, and certification are the only modifier group growing regardless of whether the subject is established or AI-framed.
Risk responsibilities are moving into teams that did not inherit this vocabulary. Thirty percent of sampled AI-governance job postings already include established risk responsibilities.
Contents
The shift
Growth and volume · Where visibility is declining · Where demand is forming · From discipline to problem · 6 things in the data
Why now
How the vocabulary arrived · The regulatory demand curve · The regulatory split · Where the rules are
When attention becomes structure
The standards · Attention and adoption · A standard outlasting its category · The geography of certification · The analyst ladder · The two firms disagree · What executives put in writing · The regulator’s own words
The choices the shift creates
The scale–momentum map · The modifier · Learn, buy, prove · The invisible vocabulary · When demand happens · The price of attention
One shift, 8 markets
8 areas of expertise
The evidence underneath
The employment test · The capital test · The pattern behind the shift
The finding
Every function now runs the same loop. Most of them do not call it risk.
Product, operations, strategy, software delivery, marketing, support and AI development have converged on the same shape: a loop that governs, detects, responds, recovers, learns and proves it ran. That is not adjacent to risk, security, resilience and compliance. It is those disciplines, performed under other names, by people who do not report to them.
The numbers first. AI-framed language grew 302%. Established language fell 13% over the same period and 29% year on year. The two clusters have not crossed — established vocabulary still carries 8.3 times the monthly attention. How many times over depends on which terms you count. The growth rates do not.
Then the control. 125 terms outside this domain, pulled on identical settings. Established vocabulary in recruiting, accounting, marketing, support and software delivery fell a median 30% — more than twice the 14% here. So the decline is not this market being renamed around it. It is business language generally being answered without a click, and this domain is holding up better than most.
What is specific to risk and security is the speed of arrival. AI-framed language reaches it roughly twice as fast as it reaches comparable business functions.
Eight signals, one domain, four years. Search attention across 1,621 terms from September 2022 to August 2026, read against the regulatory calendar, five years of certification data, sixteen years of analyst coverage, the language of 13,675 annual filings, a corpus of job postings, 449 private transactions and 737 government contract awards.
The question is deliberately narrow. Not whether AI matters. That argument is over. How is this domain describing the problems it has to solve, and how has that description changed?
Search attention is not market demand. It measures the language people reach for when they are researching a problem, comparing approaches or looking for someone to solve it.
Each instrument runs at a different lag. Language moves first. Regulation sets the calendar it moves on. Disclosure records what executives will put their name to. Certification confirms adoption years later. The analysts either formalize a market or quietly retire it. Job postings show which duties have moved, and under whose title.
Where those five agree is where the finding is. Where they disagree is usually more interesting, and the report says so rather than smoothing it out.
Chapter 1
How much faster AI-framed language reaches risk and security than it reaches comparable business functions, measured against a control basket of 125 terms.
The language people use to discover risk and security solutions is changing. See where attention is growing, where it is declining and which terms now signal commercial intent.
The language used to describe your work is changing around you. See which established terms are losing attention—and how AI, regulation and evidence are reframing the same underlying capabilities.
1Growth and volume2Where visibility is declining3Where demand is forming4From discipline to problem5The practice and its replacement66 things in the data
Figure 1 · Growth and volume
Two clusters, one axis, total monthly searches. AI-framed language on one side — governance, agents, assurance, model risk. The established vocabulary of risk, security, resilience and compliance on the other. The plotted line is the earlier 509-term pull; the figures beneath it are the full 1,621-term set, which is why the legend and the panel disagree on the established cluster.
The lines are converging and have not crossed. How large the gap still is depends on how many established terms you count, so the direction is the durable finding, not the multiple. The established language still captures most discovery. AI-framed language captures the growth. That tension does not resolve itself. Move everything to AI and you abandon the larger share of current search. Stay where you are and you are absent from the language forming around it. The expertise transfers. What changes is who owns it.
Clusters assigned by term, not inferred intent. Brand names, named standards and generic terms without clear domain relevance are excluded. Both series use a 3-month rolling mean to reduce seasonal noise.
Figure 2 · Where visibility is declining
Steepest year-on-year declines among terms averaging at least 500 monthly searches.
Six of the thirteen steepest declines are software categories: incident management, business continuity, ERM, compliance management, risk management, GRC. Each is falling faster than the discipline it serves.
The capability still matters. Fewer people are looking for it under the names vendors have used for a decade.
Search is moving off the category name and onto the specific problem or obligation.
Figure 3 · Where demand is forming
The fourteen fastest-growing terms averaging 200 or more monthly searches, after the minimum-base rule. Logarithmic scale, 374% to 1,331%. Role titles excluded.
Eight of the fourteen concern agents or the infrastructure to govern them. The other six are security and response work.
Growth rate is not market size. “Agentic AI security”, fastest at +1,331%, averages 6,783 searches a month. The largest term here, “AI vulnerability management” at 9,809, grows slowest of the fourteen. This vocabulary is still forming.
Figure 4 · From discipline to problem
Eight pairs, each the same underlying work described two ways. The discipline name on the left. The AI-framed problem people actually type on the right.
Every pair moves in opposite directions. Check the volumes before concluding anything: “access control system” still carries 61,608 searches against 1,289 for “AI access control”, a 48-to-1 gap and closing. The growth is at the door. The volume is still in the hall.
One pair has already flipped. “AI audit” at 7,175 has overtaken “audit management software” at 1,582. The end state looks like that, and it took about three years.
Figure 5 · The practice and its replacement
Response-practice language against its AI-framed equivalents — command, exercise, recovery, investigation, response. 132 of 158 measurable response terms are declining. Eight per panel.
The practice vocabulary is enormous and falling: 199 terms, 1.59 million searches a month, down 16% year on year. Incident command system alone carries 450,000. Its AI equivalents total 33,000 — a fraction of the volume — and grow 229%.
Term by term the substitution is legible. “Incident response plan” falls 19% while “AI incident response plan” grows 778%. “Security operations center” falls 13% while “agentic AI security” grows 1,331%. The capability is identical. The language attached to it is not.
Response-practice group: 199 terms covering command, crisis, emergency, incident, recovery, exercise and investigation language, AI-framed terms excluded. AI operational group: 18 terms. Volume-weighted year-on-year change; term-level values from the 1,621-term pull, group aggregates on the original group definitions.
Figure 6 · 6 things in the data
The narrowing gap is the headline. Underneath it are six patterns the cluster averages hide.
“AI governance” grew 90%. “AI governance tools” grew 275% and “AI governance platform” 267%. Searchers are looking not only to understand AI governance but to find something that helps them implement it.
“Enterprise risk management” fell 54%; “ERM software” fell 76%. “GRC software” fell 64%. The tooling label declines faster than the discipline, reversing the AI pattern. One exception: “GRC platform” grew 36%.
“Cyber security training” averages 36,617 monthly searches and fell 74%. “AI governance training” grew 294% and “incident response training” 151%. Broad training labels are giving way to specific subjects and obligations.
ISO 22301 averages 27,783 and is flat at −3%. ISO 42001, published December 2023, already averages 44,383 and grows 91%. Interest is not adoption, but the speed signals a forming ecosystem around certification, readiness and audit preparation.
“AI testing” averages 146,000 — six times “AI governance” and about a third of the AI cluster. It carries at least 2 intents: testing AI systems, and using AI to test software. Its size makes it important; its ambiguity makes it hard for anyone to own.
“Agentic AI security” first registered in October 2024 and grew 1,331%, the fastest in the dataset; “agentic AI governance” 1,054%. Neither existed 2 years ago. A new architecture creates its own governance vocabulary fast. The volumes still show a market forming.
The observation to sit with. Number 2 is the most consequential for established providers. If you sell a GRC, ERM, business-continuity or incident-management platform, the data does not say the underlying problem has gone. It says the capability is less likely to be found through the category name vendors have historically used. “Business continuity manager” fell 88%, “incident management software” 83%, “compliance management software” 76%, while AI-framed language around controls, readiness and assurance grows. The capability remains. Its established route into the market is losing visibility.
Chapter 2
Before the EU AI Act was politically agreed, people were already searching how to comply with it.
Regulation creates the search long before it creates the obligation. See when attention forms around a new rule, how wide the window stays open and how fast it closes once the deadline passes.
Your organization starts asking questions on the regulator’s schedule, not yours. See where attention peaks relative to each deadline, and what happens to it afterwards.
7How the vocabulary arrived8The regulatory demand curve9The regulatory split10Where the rules are
Figure 7 · A new way of doing things arrives
Each dot marks a term’s first month with measurable search volume — its first observable appearance.
Figure 8 · The regulatory demand curve
Four regimes, each indexed to its own peak search volume and aligned on its compliance deadline. Two deadlines have passed. Two are still ahead.
NIS2 peaked in the exact month of its transposition deadline and has since fallen to 45% of peak. DORA peaked 3 months before it applied and now sits at 24% — a 76% collapse in the 18 months since it took effect.
The two regimes with deadlines still ahead behave the opposite way. Both sit at 82% of peak and are climbing. Regulatory attention is an anticipation curve. It peaks before the rule applies.
Verdict A regulation opens a front door when it is proposed and closes it when it takes effect. Where a regime sits on this curve matters more than its volume.
Figure 9 · The regulatory split
Of the 84 regulatory and standards terms in this dataset, the ones gaining demand and the ones losing it sort almost perfectly by subject.
The pattern is close to absolute. NIST AI RMF +195%, ISO 42001 +93%, EU Data Act +53%, Cyber Resilience Act +24% — against DORA −50%, ISO 31000 −42%, SOC 2 −29%, ISO 27001 −17% on 247,667 searches.
Two honest exceptions. CMMC grows 4%, a defense-contracting mandate with a hard enforcement date still ahead of it — which is Figure 8’s rule, not a counter-example. And “AI insurance” falls 6%, the only declining AI regulatory term.
Figure 10 · Where the rules are
Search demand for AI regulation by jurisdiction. This is what a provider selling internationally actually has to answer.
The EU AI Act holds 65,417 searches — 31 times the largest US state term. No US federal AI term registers measurable volume at all, so there is no national frame to search for.
Five state regimes exist instead, and all five are growing: NYC Local Law 144 +67%, Colorado +30%, Illinois +27%, California +6%, Texas +3%. Small numbers. Every one of them rising.
Verdict Europe gives you a category to sell into. The United States gives you five, and the fragmentation is the opportunity.
Chapter 3
ISO 42001 to ISO 22301 in mid-2026 search volume, 31 months after 42001 was published.
Search shows a question forming. Certification and analyst coverage show whether an ecosystem followed. See which standards are gaining ground, where certification concentrates and which markets the analysts have quietly closed.
The standard you hold may be outlasting the discipline built around it. See how certification volumes have moved, how unevenly they are distributed, and what the analysts stopped covering.
11The standards12Attention and adoption13A standard outlasting its category14The geography of certification15The analyst ladder16The two firms disagree17What executives put in writing18The regulator’s own words
Figure 11 · The standards
ISO 22301 has been the international management-system standard for business continuity for over a decade. ISO 42001, the first AI management-system standard, was published in December 2023. This chart measures attention, not certificates, adoption or revenue.
ISO 42001 overtook ISO 22301 in September 2025, about 21 months after publication. By July 2026 it had reached 49,500 monthly searches against 27,100 — a ratio of roughly 1.8 to one, some 31 months after it was published. ISO 22301 did not collapse. Its volume stayed broadly flat at −2%, which means the growth is new interest in AI management systems rather than attention transferred off the continuity standard.
Why the comparison matters. Management-system standards create recognizable work: readiness assessments, gap analyses, governance design, documentation, internal audits, certification preparation and training. Those structures already exist around ISO 22301 and ISO 27001. ISO 42001 applies them to a new subject. The requirements differ, but much of the delivery architecture is familiar.
The transfer opportunity. The broader AI and established vocabularies have not crossed, but one AI-specific standard has already overtaken a mature continuity standard in search interest. That does not prove certification volumes or budgets have crossed with it. It shows where attention, and an ecosystem of services, is forming. Firms experienced in management systems, assurance, auditing and training are not starting from zero. The methods transfer. Applying them still needs credible AI-specific expertise. The standard is new. Most of the work required to operationalize it is not.
Figure 12 · Attention and adoption
July 2026 global search volume beside the latest available official certificate counts. Shown together for context, not as equivalent units: search volume is current monthly attention; a certificate count is the installed base at a reporting date, where one organization may hold several certificates and one certificate may cover many sites.
| Standard | July 2026 searches | Latest valid certificates | Ecosystem |
|---|---|---|---|
| ISO/IEC 27001 | 201,000 | 96,709 | Substantial interest, large established base |
| ISO 22301 | 27,100 | 4,595 | Smaller but established |
| ISO/IEC 42001 | 49,500 | Not reported in cited survey | Published Dec 2023; attention ahead of the data |
ISO 42001 was published in December 2023. Search interest has developed quickly enough to overtake ISO 22301, but the annual certification statistics have not yet provided a comparable official count. Its figure is not reported — not zero.
The reporting lag is the useful part. A new standard needs accreditation bodies to extend their scopes, organizations to implement the management system, audits to complete and certificates to reach the reporting system. Search attention shows up years earlier in that sequence.
Verdict Search reveals the questions forming now. Certification statistics confirm adoption later. ISO 42001 currently sits in the gap between them.
Certificates: ISO Survey of Management System Standard Certifications 2024 (ISO/CASCO), compiled from IAF CertSearch. ISO 42001 is not among the standards that edition covers, so no official count exists. This is not a reported zero.
Figure 13 · A standard outlasting its category
Valid ISO 22301 certificates by annual survey edition, with the standard’s own search volume beneath each year. A certificate count is an accumulated stock; search volume is current discovery.
Reported certificates rose in every edition shown, from 2,205 to 4,595.1 Search interest in the named standard stayed relatively stable — but the wider business-continuity vocabulary weakened sharply: “business continuity manager” fell 88%, “business continuity software” 79%, and operational-resilience terms also declined.
These are not contradictory. A certification base can keep expanding while fewer people enter through the discipline’s terminology, the software category loses visibility, investment shifts toward cyber, regulation and AI, and continuity becomes embedded inside broader resilience programs.
Verdict The standard is proving more durable than the category built around it.
Certificates: ISO Survey 2020–2024, ISO/CASCO. Coverage varies by edition — ISO 27001’s count fell 32% in the 2023 survey on reduced participation, then rose with the 2024 move to IAF CertSearch. Counts are an accumulated stock shaped by renewals, regulatory requirements and procurement expectations.
Figure 14 · The geography of certification
Share of reported valid certificates by country in the cited ISO Survey edition. These show where certificates are reported — not where demand or spending resides, and may reflect differences in certification culture, regulatory expectation and reporting coverage.
ISO 27001 is highly concentrated: China accounts for 34.5% of reported valid certificates and the 5 largest countries for 57%. ISO 22301 is far more dispersed — Greece leads at 12%, then the UK at 9.6%, South Korea, the UAE and India, with the top 5 at 38%.
The United States accounts for 4.4% of reported ISO 27001 certificates and 2.3% of ISO 22301. That is not underinvestment. It is a market that proves the same things through different frameworks, assurance mechanisms and procurement conventions.
The standard may be global. Its commercial market is local.
Figure 15 · The analyst ladder
Gartner formalizes a market in rungs: a trend, then an emerging market, then a ranked one. Three categories, sixteen years, three outcomes.
AI governance climbed the whole ladder in under five years, and the last rung took seven months — Market Guide November 2025 to inaugural Magic Quadrant June 2026, the fastest promotion in the dataset. GRC took fourteen years and four renames to arrive back at the name it started with.
Business continuity is the one that matters most here. Its final Magic Quadrant was September 2019 and nothing succeeded it. Over the same period, ISO 22301 certificates rose from roughly 2,000 to 4,595 (Figure 13).1
Verdict Search and analyst coverage measure discovery. Certification measures the work. Here they come apart completely.
Figure 16 · The two firms disagree
Where each firm placed 7 domains on its own ladder. Ranked means a Magic Quadrant or Wave; emerging a Market Guide or Landscape; framework a model with no vendor evaluation. “Not in dataset” means absent from the compiled event tables, not necessarily from the firm’s coverage.
| Domain | Gartner | Forrester | Divergence |
|---|---|---|---|
| AI governance | MQ · Jun 2026 | Wave · Aug 2025 | Forrester first, by 10 months |
| AI security | Market Guide · Feb 2026 | AEGIS framework · Aug 2025 | No ranked market at either firm |
| GRC | MQ · 2025, after 4 renames | Wave · Q2 2026 | Gartner went dark 2022–24 |
| Integrated risk management | MQ 2018 → retired | Never formalized | Forrester, 2019: “IRM is GRC” |
| Business continuity | MQ retired · Sep 2019 | CEM Wave · Q4 2023 | Forrester reframed it as critical events |
| Physical security | No market | Tech Tide · Q2 2020 | Neither firm ranks it |
Forrester reached a ranked AI governance market 10 months before Gartner — Wave in August 2025 against Magic Quadrant in June 2026 — then renamed it Responsible AI Solutions in January 2026, returning to the label it first used in November 2020. A five-year round trip.
On integrated risk management they contradict each other outright. Gartner built the market in 2018 and retired it; Forrester refused to build it, writing in 2019 that IRM was simply GRC. Forrester was right.
Figure 17 · What executives put in writing
Matching 10-K result documents on SEC EDGAR, 8 exact phrases, August 2022 to July 2026. Documents, not companies — not deduplicated issuers, and may include 10-K/A filings and exhibits. A proxy for disclosure commitment, not budget.
Business continuity accounts for 8,374 of the 13,675 documents — 61% on its own.4 In formal disclosure the established vocabulary is not in retreat. But every steep growth rate belongs to the newer language: third-party risk management rose 14× between 2023 and 2025, cyber incident response 16×, operational resilience nearly 4×.
Of 80 sampled 2026 passages, 68 contained the phrase. Only 8 read as procurement signals. 36 described operational action or governance, 20 were vendors positioning their own products.
Verdict Search shows what people ask. Disclosure shows what executives will sign. Both point the same way, and neither is a budget.
Figure 18 · The regulator’s own words
The 8 phrases from Figure 17, tested against DORA in full — 106 recitals, 64 articles, OJ L 333.5 An exact-string test on one instrument; the EU AI Act, NIS2 and the SEC rules have not had the same pass. Where a phrase is absent, the Regulation’s own term is given.
| Phrase, as filed and searched | In DORA | What the Regulation writes instead |
|---|---|---|
| business continuity | Obligation | Used directly — “ICT business continuity policy”, Arts 5(2)(e), 11, 16(1)(f) |
| operational resilience | Modified | “digital operational resilience” — defined term, Art 3(1); in the title |
| third-party risk management | Renamed | “ICT third-party risk” — defined term, Art 3(18); Chapter V heading |
| cyber incident response | Renamed | “ICT-related incident”, Art 3(8); “ICT-related incident response”, Art 17(3)(f) |
| model risk management | Absent | Not in scope. The Regulation governs ICT risk, not model risk; the obligation sits elsewhere. |
| AI governance · AI security · compliance automation | Absent | No AI vocabulary appears anywhere in the instrument. DORA was adopted in December 2022, before this language existed at scale — the absence dates the instrument, it is not a gap. |
Of the 8 phrases executives put into signed filings, one appears in DORA as written. Three appear only with a modifier the market drops — digital, ICT, ICT-related. Four do not appear at all, and all four are the AI-framed ones.
The instrument that reorganized operational resilience for European finance contains no reference to AI. The language now growing fastest arrived after the law that reshaped the market.
Verdict Regulation creates the subject. The market names it. The gap between them is where positioning happens.
Chapter 4
Terms in this dataset that offer scale, growth and clarity at the same time.
No term in this dataset offers scale, growth and clarity at once. The only choice is which trade-off to accept. See where the room is, what it costs to compete for and when in the year to move.
Some of your formal language travels. Some of it registers nowhere at all. See which terms people actually use for the problems you own, and which exist only in documents.
19The scale–momentum map20The modifier21Learn, buy, prove22The invisible vocabulary23When demand happens24The price of attention
Figure 19 · The scale–momentum map
Sixteen representative terms by average monthly volume (log axis) and year-on-year change (linear). Reference lines at 6,000 searches and 0%: the upper-right quadrant combines scale and growth, upper-left is emerging, lower-right established but declining.
Only four terms combine more than 6,000 monthly searches with positive growth, and not one is uncontested. AI testing is large but semantically divided between testing AI systems and using AI to test software. Security awareness training now falls 43% to 13,183, after a spike that briefly reached 135,000 against a baseline near 8,000. AI governance has momentum and substantial vendor attention already. AI risk has scale but grows at 27%.
The fastest-growing terms sit on the smaller side of the map. NIST AI RMF grew 190% on 10,200 average monthly searches; AI governance certification 137% on 5,550. More room to establish authority, less existing demand to capture. That is the trade-off. Compete for attention that already exists, or build the language future attention will arrive through. The first buys scale and inherits the ambiguity. The second buys differentiation and costs you time before the market is there. The wave chart shows the same progression; this maps it.
Figure 20 · The modifier
Terms grouped by the language attached to the underlying concept, then split between AI-framed and established subjects. Growth is calculated from combined search volume within each group, so higher-volume terms carry greater weight.
The first three pairings carry the central pattern. Attach “platform”, “software” or “tools” to an AI-framed concept and aggregate volume grows 180%; attach the same language to an established concept and it declines 61%. Training and literacy diverge the same way — +211% against −54% — and management language follows it too, +84% against −40%. This is not a move away from platforms, training or management as ideas. They are being searched for in relation to AI.
The final two groups behave differently. Framework, standard and policy grows on both sides (+87% AI-framed, +14% established). So does assessment, audit and certification (+32% and +41%). These are the only modifier groups that stay positive regardless of subject, and they share a function: turning a claim into evidence through a defined framework, independent assessment, audit or certification.
The implication. For providers positioned around established tooling categories: 74 established terms containing “platform”, “software” or “tools” declined 61% in aggregate while 10 AI-framed equivalents grew 180%. The evidence layer grew on both sides, which makes the transferable position the proof rather than the tool: showing that a system, a control or an organization is governed, prepared and working as intended. Tooling language follows the subject. Evidence language travels across subjects.
Figure 21 · Learn, buy, prove
The 62 AI-framed terms whose language signals an intent — learning, buying or proving. These describe patterns in aggregate search language, not sequential funnel stages or individual buyer behavior. Six largest terms by volume shown per group; full group size beside each heading.
Training and literacy — the smallest group by volume, the fastest-growing by percentage. Volumes are small, but the direction is consistent.
Platform, software and tool terms. Commercial discovery is accelerating while the category’s definitions and evaluation criteria are still developing.
Assessment, audit, testing, readiness and certification — much the largest group by volume, and the slowest-growing in aggregate.
Sensitivity check on the Prove group. “AI testing” runs at 150k searches a month against the group’s 213k, so it is 70% of Prove’s volume, and it carries at least two intents. Excluding it, Prove grows +10% rather than +49%. Excluding the volatile “AI red teaming” as well, +39%. Under every variant, evidence language grows more slowly than commercial language: the gap between Buy at +181% and Prove at between +10% and +49% is real, not an artifact of one keyword.
Volumes are the mean monthly figure over the latest 12 months, the same basis as the growth rates and the group shares — not the 4-year average used elsewhere in this report. Year-on-year compares those 12 months with the preceding 12. Each term is assigned to one group by its language: a product word (platform, software, tool) takes precedence over an evidence word, so “ai risk assessment tool” counts as Buy. The remaining AI-framed terms describe the subject rather than an intent.
Figure 22 · The invisible vocabulary
Across the 48-month dataset, 365 of 1,621 terms stayed below Google Keyword Planner’s measurable reporting threshold throughout. They cluster in three revealing places.
AI business continuity · AI disaster recovery · AI crisis simulation · AI resilience testing · AI tabletops · AI agent incident response · AI forensic investigation · AI system failure response · agent containment · AI model incident
CPS 230 scenario testing · OSFI E-21 testing · DORA scenario testing · impact tolerance testing · impact tolerance breach · severe but plausible scenario · critical operations mapping · regulatory scenario testing
Crisis simulation platform · exercise management platform · resilience management platform · business continuity testing software · crisis exercise software · crisis communications platform · AI risk management platform
The first group is the most consequential. Figure 5 showed AI operational language arriving fast. All of it is agent security and monitoring language. AI applied to continuity, crisis, recovery and exercise practice registers nothing at all. There is no measurable search for what an AI disaster-recovery plan or an AI tabletop is.
The regulatory group shows a gap between formal terminology and discovery behavior: CPS 230, OSFI E-21, impact tolerances and severe-but-plausible scenarios are recognizable inside practitioner contexts, but their exact phrases did not register. Organizations may be instructed to comply in one vocabulary while researching the problem in another.
Zero measurable volume across all 48 months. Not evidence of zero searching — these phrases may appear in procurement, regulation, direct navigation or longer queries the tool groups differently.
Figure 23 · When demand happens
Total monthly search volume across all 1,621 terms, four years pooled, indexed.
January is the peak at 109. June is the trough at 92. Nine of the twelve months sit within 7% of average and seven are within 3%, so the whole year spans 17 index points.
There is no budget-cycle spike and no year-end collapse. A narrower term list showed a December trough of 82 and a March–August peak; on the full set both flatten, which means they were properties of those terms rather than of the market.
Figure 24 · The price of attention
Estimated top-of-page Google Ads bids for the highest-priced terms. Estimates of what an advertiser might need to bid for placement — not prices paid, market size or revenue. Role titles and brand terms excluded; corporate-training queries marked. Green = growing, orange = declining. Figures are Australian dollars, the account currency of the export, so read the ranking and the spread rather than the absolute level.
Several of the highest estimates belong to terms losing volume: “crisis management software” at A$122 while declining 59%, “business continuity software” at A$115 while declining 79%. Declining volume does not automatically lower acquisition costs.
A smaller set pairs high estimates with growing interest: AI penetration testing (A$133, +84%), policy management software (A$96, +70%), third-party risk management (A$88, +24%). Candidates for testing, not a buy list.
The old categories remain expensive to compete for even as fewer people search for them. The emerging ones offer momentum, but not yet proven conversion.
Chapter 5
Of the 126 crisis and incident management terms with a measurable year-on-year change, the number declining.
Eight areas, eight different pictures. See which terms are worth holding in yours, which are being abandoned, and where the AI language has not arrived yet.
Your discipline is being renamed around you. See what is arriving in its place, and how much of it your existing capability already covers.
CybersecurityAI securityAI governanceGRC & complianceOperational resilienceCrisis & incident managementPhysical securityTraining & simulation
Expertise · Cybersecurity
37 terms and 499,130 searches a month, down 6% — security operations and security technology only. This area was a residual bucket of 359 terms; enterprise risk, insurance, named regulators and vendor brands have been removed from it and from chapter 5. See the appendix.
| Term | Per month | YoY |
|---|---|---|
| soar | 194,333 | 0% |
| endpoint detection and response | 130,833 | −2% |
| ciso | 100,250 | −6% |
| security operations center | 13,500 | −13% |
| dfir | 11,917 | 0% |
| ot security | 10,800 | −65% |
| managed detection and response | 8,567 | −12% |
| security operations | 5,117 | +27% |
| ics security | 3,650 | −7% |
Three acronyms carry most of the area: SOAR at 194,333 and flat, endpoint detection and response at 130,833 and down 2%, CISO at 100,250 and down 6%. Spelled-out and role language falls faster — security operations center −13%, OT security −65%, ICS security −7%.
One term grows: security operations, up 27%. It describes the function as something that runs rather than a department or a tool — the same pattern the AI areas show at much larger scale. Managed detection and response, the other service framing, now falls 12%.
Verdict Smaller than it looked, and concentrated in three acronyms.
Expertise · AI security
Only 33 terms and 94,986 searches a month, but up 141% year on year — the steepest growth of any area here.
| Term | Per month | YoY |
|---|---|---|
| prompt injection | 35,508 | +192% |
| shadow ai | 16,333 | +183% |
| agentic ai security | 6,783 | +1331% |
| ai red teaming | 4,817 | −69% |
| ai guardrails | 4,450 | +158% |
| ai agent security | 3,758 | +529% |
| ai observability | 4,150 | +266% |
| ai monitoring | 3,167 | +37% |
| ai security engineer | 2,517 | +258% |
Prompt injection at 35,508 and shadow AI at 16,333 are the two terms with real scale, up 192% and 183%. Agentic AI security grows 1,331% from 6,783. The area is small in absolute terms and growing faster than anything else in the report.
One term falls, and it is instructive: AI red teaming drops 69% from 4,817 after a spike — emerging language can contract as fast as it forms. AI guardrails grows 158%, AI agent security 529%, AI observability 266%. The spread is wide, which is what a vocabulary still settling looks like.
Verdict Highest growth, lowest volume, one cautionary laggard. Early enough to shape.
Expertise · AI governance
157 terms and 389,117 searches a month, up 54%. It also contains the most ambiguous term in the dataset.
| Term | Per month | YoY |
|---|---|---|
| ai testing | 146,000 | +57% |
| eu ai act | 68,833 | +24% |
| ai certification | 24,900 | +11% |
| ai governance | 25,442 | +90% |
| ai risk | 11,667 | +27% |
| nist ai rmf | 10,200 | +190% |
| ai governance framework | 8,600 | +101% |
| ai risk management | 7,925 | +70% |
| ai audit | 7,175 | +35% |
AI testing carries 146,000 searches a month — well over a third of the area — and means at least two unrelated things: testing AI systems, and using AI to test software. The area growth is real, but a large share of the absolute volume belongs to a term nobody can own.
Underneath it the signal is cleaner. EU AI Act grows 24%, AI governance 90%, NIST AI RMF 190% from 10,200. Framework and named-regime language is where the durable interest sits.
Verdict Real growth, one enormous term you cannot claim.
Expertise · GRC & compliance
157 terms and 2,799,638 searches a month, three times the next-largest area, and down 19% year on year.
| Term | Per month | YoY |
|---|---|---|
| dora | 1,747,500 | −17% |
| iso 27001 | 243,917 | −18% |
| nis2 | 84,375 | −1% |
| pci dss | 80,000 | −23% |
| soc 2 | 58,375 | −29% |
| iso 31000 | 42,400 | −43% |
| iso 42001 | 44,383 | +91% |
| cmmc | 40,633 | +5% |
| fedramp | 32,042 | +1% |
DORA alone carries 1,775,000 searches a month and falls 17%, which is the post-deadline pattern: the regime applied in January 2025 and attention has been receding since. ISO 27001 falls 18%, SOC 2 29%, ISO 31000 43%.
Three move the other way. ISO 42001 grows 91% from 44,383 — the AI management-system standard. CMMC grows 5% and FedRAMP 1%, both with enforcement still ahead of them. Every exception is about a deadline that has not passed.
Verdict Vast, mandatory, and past its peak of attention.
Expertise · Operational resilience
84 terms and 362,386 searches a month, up 5%. Most of it sits in a single abbreviation.
| Term | Per month | YoY |
|---|---|---|
| bc dr | 278,042 | +37% |
| cyber resilience act | 25,217 | +28% |
| disaster recovery | 19,683 | −30% |
| disaster recovery plan | 10,133 | −30% |
| business continuity manager | 10,292 | −88% |
| it disaster recovery | 6,525 | −8% |
| cyber resilience | 5,992 | −9% |
| dr test | 4,600 | −14% |
| operational resilience | 3,300 | −16% |
“BC DR” carries 278,042 searches a month — most of the area — and grows 37%, which is the whole of its gain. Spelled out, the same discipline falls: business continuity manager −88%, disaster recovery −30%, disaster recovery plan −30%, operational resilience itself −16% from 3,300.
The Cyber Resilience Act grows 28%, the regulatory pattern again — a regime whose obligations are still arriving. Regulation grows; the discipline’s own nouns do not.
Verdict The discipline is being abbreviated. Nobody abandoned it.
Expertise · Crisis & incident management
165 terms, 934,556 searches a month, down 18%. 105 of the 126 measurable terms are declining — the most uniform decline here.
| Term | Per month | YoY |
|---|---|---|
| incident command system | 450,000 | −13% |
| disaster management | 127,542 | −29% |
| root cause analysis | 85,000 | −18% |
| emergency operations center | 55,917 | −10% |
| csirt | 32,717 | 0% |
| crisis management | 20,958 | −27% |
| emergency preparedness | 19,250 | 0% |
| incident management | 14,092 | −34% |
| emergency management | 12,817 | −41% |
Incident command system carries 450,000 searches a month and falls 13%. Disaster management falls 29%, emergency management 41%, incident management 34%. The one exception at scale is CSIRT, exactly flat — a tooling acronym, not a name for the work. These are what the discipline calls itself.
The growing terms are small and specific: crisis governance up 104% from 203 a month, emergency response exercise up 104%. Governance, leadership and exercise framing grows while the operational nouns fall.
Verdict The work is not shrinking. Its vocabulary is emptying out.
Expertise · Physical security
24 terms and 290,065 searches a month, up 7% — but the growth is concentrated in one term.
| Term | Per month | YoY |
|---|---|---|
| psim | 161,333 | +12% |
| access control system | 61,608 | −18% |
| visitor management system | 10,300 | 0% |
| physical security | 8,300 | −15% |
| perimeter security | 3,958 | −8% |
| evacuation drill | 3,667 | −12% |
| duress alarm | 3,150 | −17% |
| emergency mass notification system | 1,197 | −95% |
| emergency notification | 2,808 | −23% |
PSIM — physical security information management — carries 161,333 searches a month, most of the area, and grows 12%. Every plain-language discipline term below it falls: access control system down 18%, physical security down 15%, emergency mass notification down 95%.
The AI vocabulary has just arrived. “AI access control” carries 1,289 searches a month and grew 1,245%. Small, real, and unclaimed.
Verdict Not a quiet area. The growth sits under an acronym the discipline does not use about itself.
Expertise · Training & simulation
66 terms and 422,394 searches a month, down 29%. What gets taught has changed. The appetite for teaching has not.
| Term | Per month | YoY |
|---|---|---|
| wargaming | 290,250 | −16% |
| cyber security training | 36,617 | −74% |
| security awareness training | 13,183 | −43% |
| compliance training | 8,483 | −46% |
| cyber range | 7,725 | +7% |
| tabletop exercises | 5,800 | −11% |
| after action review | 5,267 | −16% |
| after action report | 3,550 | −14% |
| risk management training | 3,075 | +35% |
Cyber security training falls 74% from 36,617 — the largest single loss of volume in the dataset. Compliance training falls 46% and security awareness training 43%. Two terms hold up: risk management training grows 35% and cyber range 7%.
Wargaming at 290,250 dominates the area and falls 16%. The pattern is narrowing rather than abandonment: the broad subject lines fall hardest, and what grows is named against a discipline or a facility.
Verdict Nobody stopped wanting training. They stopped searching for it generically.
The employment test
If the disciplines are being embedded rather than replaced, headcount is the one instrument that can tell absorption from addition — and search cannot. A source-cited corpus of 43 job-posting records, August 2022 to August 2026, with aggregate market data. Observed postings, not a market census.
Named AI governance roles are being created at scale: roughly 71 new US postings a week, a median salary of $169,000, and 25 or more federal Chief AI Officer appointments produced by the 2023 Executive Order.8 That is addition.
The same corpus identifies 13 hybrid roles where established model risk, operational resilience and incident response duties sit inside AI-titled positions. That is absorption. The old titles are not being posted. The old work is being performed under new ones.
No posting in the corpus uses continuous assurance or organizational learning as a job title.7 “Lessons learned” appears as a responsibility inside a resilience role and nowhere as a name. The loop is in the duties and not in the title — the same finding the search data gives, reached through a different instrument.
Draup reports AI governance and model risk skills growing 81% year on year. CSET Georgetown finds the AI ethics and governance share of AI postings rising from roughly 6% in 2018 to 10% in 2023, on 4.4 million postings.
Verdict The function is being added to. The work is being absorbed. Those are not competing readings — they are the same movement seen from the title and from the duties. Limits: observed rather than exhaustive, weighted to the US and UK, with no individually verified postings between Q3 2022 and Q3 2023. The quarterly tallies are not a demand series; the hybrid-role patterns and the third-party aggregates carry the reading.
The capital test
Two instruments measuring the same thing on the same basis: the share of transactions that use AI-framed language. 449 private funding rounds and acquisitions, and 737 government contract awards, both August 2022 to August 2026.11 Counts, not values — private value is concentrated enough that one deal defines a quarter, and awards arrive in five currencies that are never summed.
Search attention — AI-framed language grew 302% against 2023.
Private capital — the AI-framed share of deals went from 24% in 2022 to 41% in 2026.
Public procurement — the AI-framed share of awards went from 1% to 17%.
Each instrument is still climbing, and each started later than the one before it.
A quarter of all transactions were already AI-framed in 2022, before the search language moved. Against +302% in attention, a climb from 24% to 41% is a flat curve. AI is 36% of deals but only 28% of disclosed value, so these are consistently smaller transactions: the category is being funded broadly rather than concentrated.
AI-framed concepts took 1% of government awards in 2022 and 17% in 2026 — a seventeenfold rise from almost nothing, and the steepest curve of any instrument in this report.
The established vocabulary still takes 93% of all awards across the period. Incident management alone accounts for 311 of the 737, business continuity 145 and crisis management 138.12 All four AI-framed concepts combined account for 51.
A deal is evidence of investment and an award is evidence of a purchase. Neither is revenue, market size or growth. The procurement set is weighted to the UK and EU, which hold 521 of the 737 awards, so it is not a global picture.12 The year series covers the 726 dated awards; 11 carry no quarter. Both endpoints are partial years.
Verdict Attention, capital and procurement all move the same way and none of them moves at the same time. Language is the earliest signal and the least binding; a government award is the latest and the most. The gap between them is the window.
The next 18 months
The 8 instruments run at different lags. Language moves first, regulation sets the date, private capital commits early, disclosure records what executives will sign, certification confirms years later, analysts formalize it or retire it, job postings show which duties have moved, and public procurement arrives last. That spread is what makes the near future partly readable: several things have already arrived in the language and have not yet arrived anywhere else.
What this cannot do is forecast. Nothing here predicts 2030. It shows what is present in the earliest signal and absent from the later ones, which is a different and more defensible claim.
Agent governance. Discovery, delegated authority, tool risk, runtime monitoring, kill switches. The vocabulary is 21 months old and growing fastest in the set.
Not yet in: a named obligation, a certifiable standard, or analyst formalization.
AI management systems. ISO 42001 overtook ISO 22301 in search in September 2025 and reached 49,500 by mid-2026.
Not yet in: the certification statistics, which do not survey it.
EU AI Act high-risk obligations, August 2026. Wave 4 operational terms — incident response plans, competency and governance assessments — arrived through 2025 and early 2026, on the pattern that preceded the Act taking effect.
AI access control. The physical-security convergence term exists now — 1,289 searches a month, up 1,245% — where a year ago there was nothing.
Not yet in: a platform category, a standard, or anyone’s positioning.
Evidence. Assessment, audit, certification and readiness grow whether the subject is AI-framed or established. The one modifier group that does not depend on which language wins.
The pattern behind the shift
Risk, security and resilience have always been loops: govern, detect, respond, recover, learn, assure, and round again. That is what a management system is. Product, operations, strategy, software delivery, marketing, support and AI development are converging on the same operating model: define the goals that must be protected, detect when they slip, respond, correct, retain the lesson and prove the cycle worked.
The same six stages under other names. An SRE setting an error budget is performing risk appetite. A leadership team resetting OKRs is performing governance review. A growth team running a holdout is performing control testing. An AI team running evals is performing assurance. None of them call it that, and none report to a risk function.
The control basket confirms the loop is not specific to this domain. That is the point rather than a weakness: if every function runs one, every function is already doing this work.
2,176 10-K documents named “business continuity” in 2024 — US filers, one year, one phrase.4 There were 4,595 valid ISO 22301 certificates worldwide in the same year1, accumulated across every company ever certified. The units differ and cannot be subtracted, but the direction is unambiguous: the obligation to disclose the risk is close to universal, while the decision to fund a separate certified capability is rare.
human in the loop — 53,175/mo, +623%
human on the loop — 2,075/mo, +399%
team learning — 8,200/mo, +73%
lessons learned — 66,125/mo, −26%
continuous improvement — 36,417/mo, −45%
after action review — 5,267/mo, −27%
continuous auditing — 1,157/mo, −63%
Every phrase that names the loop as a concept is falling. The two that are rising both ask who sits inside it. Language appears where something is contested and disappears when it becomes infrastructure.
The phrase describing a document you hold grows slowly — business continuity, +19% from 2023 to 2026. The phrases describing something that has to keep running grow by an order of magnitude more: operational resilience +448%, third-party risk management +1,236%, cyber incident response +1,311%.
Two readings, sequential rather than competing. Absorption happens whether anyone argues for it or not: the disciplines dissolve into every function running a loop, the work grows, the named function does not. Authority has to be claimed — loops fail in known ways, and designing for that is a larger remit than owning a review gate. Nobody holds it yet.
Conclusion
Eight signals, one conclusion. Search shows the question taking shape. Regulation sets the timetable around it. Disclosure records what executives are prepared to sign. Certification confirms adoption later. Analysts formalize categories—or let them recede. Job postings show which responsibilities are moving, and under whose title. Private capital and public awards show when the shift begins to register in transactions.
Together, they describe a field in which the language is changing faster than the underlying capabilities. Risk, security, resilience, and continuity work is increasingly appearing inside functions that have not traditionally named it that way.
No evidence here suggests organizations need this work less than they did in 2023. Fewer people are arriving through the established terms, but the decline is mild against the control basket: comparable business vocabulary outside this domain fell more than twice as far.
That makes this a discovery and ownership question before it is a demand question. Discovery changes through what you publish. Ownership changes through how the work is named before the functions taking it on establish their own vocabulary. Nothing in this research suggests changing the capability itself.
What this cannot show is where the money is. Search measures attention, not spend, and established language remains materially larger. Reading a 302% rise as an immediate budget shift would put positioning ahead of the market it is meant to serve.
What follows
Cluster totals exclude brand names and named standards. Growth figures are year-on-year to July 2026.
The short version. Between 2023 and 2026, demand for the language of AI authority grew 302% while demand for the industry’s established vocabulary — risk, security, compliance, continuity — fell 13%, and 29% year on year. Measured against a control basket outside this domain, that decline is mild: comparable business vocabulary fell more than twice as far. The words are not the problem. The work is moving. Every function that now runs a loop performs governance, detection, response, recovery and assurance under its own vocabulary — and the phrases that name the loop as an idea are falling, while “human in the loop” grows 623%. What is contested is no longer whether the loop exists, but who sits inside it.
None of these need new research. They need someone to answer them out loud, with a name attached.
Method
Where it comes from. Search: Google Keyword Planner, 1,621 terms, monthly, September 2022 to August 2026, classified into six concept families. Brand names and named standards are excluded from cluster totals. Certification: the ISO Survey of Management System Standard Certifications, 2020–2024 (ISO/CASCO, from IAF CertSearch). Regulation: published compliance dates for DORA, NIS2, the EU AI Act and the Cyber Resilience Act.3 Analyst coverage: Gartner and Forrester report metadata, 2010–2026, public sources only, 176 report rows.2 Disclosure: SEC EDGAR full-text search, 10-K results for 8 exact phrases, 13,675 matching documents. Employment: a source-cited corpus of 43 job-posting records, August 2022 to August 2026, with aggregate data from CSET Georgetown (Lightcast), Axial Search, PwC, IAPP and Draup. Private capital: 449 source-linked funding rounds and acquisitions, August 2022 to August 2026, across five categories.9 Public procurement: 737 government contract awards over the same window, matched to eleven concepts across nine buyer countries.10
What we checked. The first ten 2026 results per phrase were opened to confirm the phrase was actually in the document. 68 of 80 contained it. AI governance returned 0 of 10, so its counts are marked unverified rather than quietly used.
How to read the volumes. Keyword Planner is Google’s own first-party data, not a third-party estimate, with one known property: it reports in fixed buckets. Across the 1,256 terms carrying volume there are 59 distinct monthly values. Dependable for scale and comparison. Not to be read to the last digit.
What we excluded. Brand names and named standards are out of the cluster totals. A spike in “ISO 22301” tracks a certification cycle, not a shift in thinking. They still appear in the tables, marked.
Outliers. Three terms carry months more than twenty times their own median and above 100,000 searches. That is bucketing, not an event. For those three only, every month above eight times the term’s median is excluded and each average is taken over the months that remain: skills assessment (4 of 48 months, peaking at 2,740,000 against a 12,100 median), business continuity manager (2 of 48, 550,000 against 14,800) and AI red teaming (1 of 48, 165,000 against 1,000). No other term is adjusted.
Method
Minimum base. Keyword Planner draws its buckets from one ladder of values. Above roughly 90 searches a month that ladder is geometric, each rung about 22% above the last, so a one-rung move means the same thing at any level. Below 90 the rungs are irregular and a single step reads as anything from 25 to 100%. A term moving from 10 to 20 has not doubled. It has moved the smallest distance the instrument can express.
Growth rates are therefore reported only where the prior-period base is at least 90 and the history spans at least four distinct values. That test removes 30 of the 682 otherwise-eligible terms, and it governs the ranked table in Figure 3. Terms that fail it are named without a percentage rather than dropped, because an emerging term is worth knowing about even when its rate is not worth printing.
The control. AI-framed search attention grew across every subject between 2023 and 2026, so growth here proves nothing on its own. To test it, 125 terms outside risk, security, resilience and compliance were pulled on identical settings6: bare AI terms with no domain attached, plus matched AI-framed and established pairs across recruiting, accounting, marketing, customer support and software delivery.
Read the control on its own basis. The control was pulled alongside the main set on identical settings and classified the same way, so the term set and window match. The measure differs: the control is reported as median per-term growth for terms with a prior base of at least 90, because summed totals would be meaningless here — one term, “ai chatbot”, is 94% of the control AI volume.
On that basis: 331% for bare AI terms with no domain attached, 242% for this report’s AI governance and security family, 117% for AI-framed terms in the control domains. Established terms fell 30% in the control domains against 14% here. Cluster figures elsewhere in the report are aggregate volumes, which is why the headline reads +302% and −13% while the control reads 242% and −14%. Same terms, same window, two measures.
One figure to treat carefully. The established cluster’s year-on-year decline is 29%, steeper than the 16% an earlier, narrower term list returned. Most of that difference is composition: the terms added to reach 1,621 were overwhelmingly established-side, including several very large regulatory acronyms past their compliance deadlines. The direction is not in doubt. The magnitude of a single year’s change on this cluster is the least stable number in the report.
Sources and notes
Search figures are sourced on each figure. The numbered notes below cover every assertion in this report that does not come from Google Keyword Planner.
ISO Survey of Management System Standard Certifications, 2020–2024 editions. Published by ISO/CASCO and compiled from IAF CertSearch. Counts are valid certificates, an accumulated stock, not annual issuance. ISO/IEC 42001 is not reported in the cited editions.
Gartner and Forrester published research metadata, 2010–2026, public sources only — 176 report rows. A placement records how each firm classified a domain, not its size. Ranked means a Magic Quadrant or Wave; emerging means a Market Guide or Landscape.
Published compliance dates for NIS2 (Directive (EU) 2022/2555), DORA (Regulation (EU) 2022/2554), the EU AI Act (Regulation (EU) 2024/1689) and the Cyber Resilience Act (Regulation (EU) 2024/2847).
SEC EDGAR full-text search, 10-K results only, eight exact phrases, August 2022 to July 2026 — 13,675 matching result documents. Counts are documents, not deduplicated issuers, and may include 10-K/A filings and exhibits. Passage classification is rules-based and provisional.
Regulation (EU) 2022/2554, full Official Journal text, OJ L 333, 27.12.2022, pp. 1–79 — 106 recitals and 64 articles, read in full. Presence is an exact-string test on the eight phrases used in Figure 17.
125 terms outside risk, security, resilience and compliance, pulled on identical Keyword Planner settings and classified the same way. Reported as median per-term growth, because one term accounts for 94% of the control AI volume.
AI Governance, Resilience & Security Job Postings, August 2022 to August 2026 — 43 source-cited records. Observed postings rather than a market census, weighted to the US and UK, with no individually verified postings between Q3 2022 and Q3 2023.
CSET Georgetown (Lightcast) for US posting volume; Axial Search, PwC, IAPP and Draup for salary, role-count and skills-growth aggregates. Federal Chief AI Officer appointments follow the 2023 Executive Order and the 2024 OMB memoranda.
AI Risk & Resilience Transaction Dataset, August 2022 to August 2026 — 449 source-linked funding rounds and acquisitions across five categories, $28.5B disclosed. Deal counts are the reliable series; disclosed value is concentrated enough that one transaction can define a quarter.
Government Contract Awards — Resilience & AI Governance, August 2022 to August 2026 — 737 awards across nine buyer countries, matched to eleven concepts. Weighted to the UK and EU, which hold 521 of the 737. Values arrive in five currencies and are never summed across them. The year series covers the 726 dated awards.
Both share series count transactions, not value. Partial years at both endpoints: 2022 covers two quarters, 2026 three.
NIST AI RMF 1.0 (NIST AI 100-1); ISO/IEC 42001:2023; ISO 22301:2019; SR 11-7 (Federal Reserve SR Letter 11-7, model risk management).
Appendix
| Term | Avg/mo | YoY |
|---|---|---|
| dora · standard | 1,747,500 | −17% |
| incident command system | 450,000 | −13% |
| wargaming | 290,250 | −16% |
| bc dr | 278,042 | +37% |
| iso 27001 · standard | 243,917 | −18% |
| soar | 194,333 | 0% |
| psim | 161,333 | +12% |
| ai testing | 146,000 | +57% |
| disaster management | 127,542 | −29% |
| endpoint detection and response | 130,833 | −2% |
Every term carries one of six concept families, assigned by term rather than inferred intent.
AI governance and security (251 terms). Governance, risk, readiness, compliance, literacy, assurance, agent security and the tooling variants of each.
The established composite (818 terms). Cybersecurity (336), resilience and crisis (300) and risk and compliance (182) — third-party risk, incident response, cyber resilience, business continuity, scenario testing, crisis management, operational resilience, physical security, GRC and audit.
Learning loops (67 terms) and other or sector-specific (485 terms) sit outside both clusters. The loop family is read separately in the chapter on the pattern behind the shift.
Three levels, three bases. Cluster totals and term-level values throughout the report are computed on the full 1,621-term set, September 2022 to August 2026. Area totals in chapter 5 and the group aggregates in Figures 5, 20 and 21 are carried from the original area and group definitions, which cover 723 and 199 terms respectively and were not rebuilt on the wider pull. Limits overleaf.
Appendix
Eudai is a marketing studio for security, risk and resilience companies — positioning, category design and go-to-market. eudai.ai
About Eudai
Eudai helps security, risk, and resilience companies—and risk and security teams—develop the language that makes their work easier to find, trust, and act on.
We work across category and positioning, go-to-market, and fractional leadership. Explore selected work, analyst recognition, and client awards at eudai.ai.
eudai.
Marketing for cybersecurity, AI and resilience companies.
eudai.ai
[email protected]