Back

Eudai · Market report · September 2026

Resilience
2030

Where innovation and security are heading.

8 instruments reading the same domain at different lags — search demand, regulation, certification, analyst coverage, disclosure language, job postings, private capital and public procurement — across 2022 to 2026.

1,621keywords tracked
48months of history
8independent
sources
18months language
leads obligation
A dense field of muted dots drifting flat and slightly downward, then one orange dot at the turn and a rising fan of green dots growing larger toward the right edge.
Every function now runs the same loop. Most of them do not call it risk.eudai.

Executive summary

The work is not disappearing. The language around it is changing.

Eight instruments trace the same domain from 2022 to 2026. They point in the same direction, but move at different speeds. That gap is where a change in language becomes a positioning decision.

Five findings

1
Translate; do not abandon.

Established terms still carry most of the attention. AI-framed language is opening a new route into capabilities many teams already have.

2
The decline is broader than this market.

Across a 125-term control basket outside the domain, comparable business language fell more than twice as far. What is distinctive here is the speed of AI-language arrival — roughly twice the control rate.

3
Regulation creates attention before the obligation takes effect.

DORA-related search attention has fallen to 24% of its peak since the deadline passed. Regimes with obligations still ahead sit at 82% of peak and continue to rise.

4
Evidence language travels; tooling language is conditional.

Assessment, audit, and certification terms grew across both established and AI-framed subjects. Platform and software language grew only where the subject made that framing meaningful.

5
The work is documented more widely than it is formally certified.

In 2024, 2,176 US filings referred to business continuity.4 ISO reports 4,595 valid ISO 22301 certificates worldwide across its reported history.1 Disclosure is widespread; formal certification remains comparatively limited.

The instrument lag

Search language+302%
Private capital share24→41%
Public awards1→17%

Language moves first. Private capital follows. Public procurement arrives later, but is now the steepest curve in the set. Each instrument measures a different unit; none measures market size.

Three implications

Run both vocabularies

Retain the reach of established terms while building authority in the arriving ones. The capability may be the same; the route through which people find it is changing.

Lead with evidence

Assessment, audit, and certification are the only modifier group growing regardless of whether the subject is established or AI-framed.

Name the work before the functions doing it do

Risk responsibilities are moving into teams that did not inherit this vocabulary. Thirty percent of sampled AI-governance job postings already include established risk responsibilities.

Executive summaryeudai.

Contents

What changed, why, and what to do about it.

1

The shift

Growth and volume · Where visibility is declining · Where demand is forming · From discipline to problem · 6 things in the data

5
2

Why now

How the vocabulary arrived · The regulatory demand curve · The regulatory split · Where the rules are

12
3

When attention becomes structure

The standards · Attention and adoption · A standard outlasting its category · The geography of certification · The analyst ladder · The two firms disagree · What executives put in writing · The regulator’s own words

17
4

The choices the shift creates

The scale–momentum map · The modifier · Learn, buy, prove · The invisible vocabulary · When demand happens · The price of attention

26
5

One shift, 8 markets

8 areas of expertise

33

The evidence underneath

The employment test · The capital test · The pattern behind the shift

42
Resilience 2030eudai.

The finding

The work of risk is not disappearing. It is being embedded.

Every function now runs the same loop. Most of them do not call it risk.

Product, operations, strategy, software delivery, marketing, support and AI development have converged on the same shape: a loop that governs, detects, responds, recovers, learns and proves it ran. That is not adjacent to risk, security, resilience and compliance. It is those disciplines, performed under other names, by people who do not report to them.

The numbers first. AI-framed language grew 302%. Established language fell 13% over the same period and 29% year on year. The two clusters have not crossed — established vocabulary still carries 8.3 times the monthly attention. How many times over depends on which terms you count. The growth rates do not.

Then the control. 125 terms outside this domain, pulled on identical settings. Established vocabulary in recruiting, accounting, marketing, support and software delivery fell a median 30% — more than twice the 14% here. So the decline is not this market being renamed around it. It is business language generally being answered without a click, and this domain is holding up better than most.

What is specific to risk and security is the speed of arrival. AI-framed language reaches it roughly twice as fast as it reaches comparable business functions.

+302%Growth in AI-framed search language
−13%Change in established language
Arrival speed versus control domains

What this is

Eight signals, one domain, four years. Search attention across 1,621 terms from September 2022 to August 2026, read against the regulatory calendar, five years of certification data, sixteen years of analyst coverage, the language of 13,675 annual filings, a corpus of job postings, 449 private transactions and 737 government contract awards.

The question is deliberately narrow. Not whether AI matters. That argument is over. How is this domain describing the problems it has to solve, and how has that description changed?

Search attention is not market demand. It measures the language people reach for when they are researching a problem, comparing approaches or looking for someone to solve it.

Each instrument runs at a different lag. Language moves first. Regulation sets the calendar it moves on. Disclosure records what executives will put their name to. Certification confirms adoption years later. The analysts either formalize a market or quietly retire it. Job postings show which duties have moved, and under whose title.

Where those five agree is where the finding is. Where they disagree is usually more interesting, and the report says so rather than smoothing it out.

The findingeudai.
A dense field of muted dots curving through the frame, with a single orange dot at the pivot and a green stream fanning up and away from it.

Chapter 1

The shift

How much faster AI-framed language reaches risk and security than it reaches comparable business functions, measured against a control basket of 125 terms.

For providers

The language people use to discover risk and security solutions is changing. See where attention is growing, where it is declining and which terms now signal commercial intent.

For risk & security teams

The language used to describe your work is changing around you. See which established terms are losing attention—and how AI, regulation and evidence are reframing the same underlying capabilities.

1Growth and volume2Where visibility is declining3Where demand is forming4From discipline to problem5The practice and its replacement66 things in the data

Resilience 2030eudai.

Figure 1 · Growth and volume

The growth has moved. The volume hasn’t — yet.

Two clusters, one axis, total monthly searches. AI-framed language on one side — governance, agents, assurance, model risk. The established vocabulary of risk, security, resilience and compliance on the other. The plotted line is the earlier 509-term pull; the figures beneath it are the full 1,621-term set, which is why the legend and the panel disagree on the established cluster.

01M2M3M 2023202420252026 Established vocabulary 363 terms · −5% since 2023 AI vocabulary 146 terms · +286% since 2023 Monthly searches, all terms in each cluster · 3-month rolling mean · 509-term pull
+302%Growth in AI-framed language, latest 12 months compared with the 2023 monthly average
−13%Change in established language over the same period; −29% year on year
48Months of monthly data behind both figures

The lines are converging and have not crossed. How large the gap still is depends on how many established terms you count, so the direction is the durable finding, not the multiple. The established language still captures most discovery. AI-framed language captures the growth. That tension does not resolve itself. Move everything to AI and you abandon the larger share of current search. Stay where you are and you are absent from the language forming around it. The expertise transfers. What changes is who owns it.

Clusters assigned by term, not inferred intent. Brand names, named standards and generic terms without clear domain relevance are excluded. Both series use a 3-month rolling mean to reduce seasonal noise.

Chapter 1 · The shifteudai.

Figure 2 · Where visibility is declining

The old product categories are losing visibility.

Steepest year-on-year declines among terms averaging at least 500 monthly searches.

emergency mass notification system3k−87%incident management software3k−86%corporate compliance training569−81%business continuity software640−79%erm software3.2k−76%cyber security training38k−74%ai security companies1.4k−73%compliance management software23k−73%risk management software8.6k−72%ot security11k−65%regulatory compliance training2.5k−64%pci dss 4.01.6k−62%grc software10k−57%

What the numbers say

Six of the thirteen steepest declines are software categories: incident management, business continuity, ERM, compliance management, risk management, GRC. Each is falling faster than the discipline it serves.

The capability still matters. Fewer people are looking for it under the names vendors have used for a decade.

Search is moving off the category name and onto the specific problem or obligation.

2 terms worth separating out

  • “Cyber security training” is one of the largest losses in the dataset — 36,617 monthly searches, down 74%. Every broad subject line falls with it, and what holds up is named against a discipline: risk management training grows 35%. What gets taught is narrowing.
  • “AI red teaming” is 1 of 2 AI terms among the steepest declines, averaging 4,667 and down 70% — “AI security companies” falls 73%. Emerging language can contract as fast as it forms. Being an AI term does not make growth durable.
Chapter 1 · The shifteudai.

Figure 3 · Where demand is forming

Agent risk is growing fastest.

The fourteen fastest-growing terms averaging 200 or more monthly searches, after the minimum-base rule. Logarithmic scale, 374% to 1,331%. Role titles excluded.

agentic ai security6.8k+1,331%ai access control1.3k+1,245%ai security operations center1.4k+1,143%agentic ai governance1.8k+1,054%jailbreak detection9k+611%threat intelligence monitoring688+576%ai agent security3.8k+529%ai security platform1.4k+520%agent observability1k+515%ai agent monitoring693+470%incident response simulation810+434%ai agent governance830+421%ai model security986+412%ai vulnerability management9.8k+374%

What the numbers say

Eight of the fourteen concern agents or the infrastructure to govern them. The other six are security and response work.

Growth rate is not market size. “Agentic AI security”, fastest at +1,331%, averages 6,783 searches a month. The largest term here, “AI vulnerability management” at 9,809, grows slowest of the fourteen. This vocabulary is still forming.

What to do with it

  • Nothing on this chart has scale. The largest is AI vulnerability management at 9,809 a month; the smallest, threat intelligence monitoring, at 688. For comparison, prompt injection carries 35,508 and grows 192%. It is not on this list because a term that large rarely triples. Scale and steep growth are close to mutually exclusive.
  • The rule removes 30 of the 682 eligible terms. AI control plane and enterprise AI security are real and forming, but grow from a base too small for a percentage to mean anything. Named here without one.
Chapter 1 · The shifteudai.

Figure 4 · From discipline to problem

The discipline is not what people search for.

Eight pairs, each the same underlying work described two ways. The discipline name on the left. The AI-framed problem people actually type on the right.

THE DISCIPLINE · DECLINING THE PROBLEM PEOPLE SEARCH · GROWING access control system61.6k · −18%ai access control1.3k · +1245%enterprise risk management14.8k · −54%ai risk management7.9k · +70%security operations center13.5k · −13%ai agent monitoring693 · +470%compliance training8.5k · −46%ai governance training1.5k · +294%incident response plan6.1k · −19%ai incident response plan132 · +778%operational resilience3.3k · −16%agentic ai risk331 · +105%model validation2.3k · −46%ai model security986 · +412%audit management software1.6k · −23%ai audit7.2k · +35% Bars square-root scaled within each side; the sides are not to a shared scale.

What the numbers say

Every pair moves in opposite directions. Check the volumes before concluding anything: “access control system” still carries 61,608 searches against 1,289 for “AI access control”, a 48-to-1 gap and closing. The growth is at the door. The volume is still in the hall.

One pair has already flipped. “AI audit” at 7,175 has overtaken “audit management software” at 1,582. The end state looks like that, and it took about three years.

What to do with it

  • Providers: this is the translation, term by term. You need the right-hand column in your page titles while the left-hand column still pays the bills — and the right-hand column is increasingly bought by someone who does not run a risk function.
  • Providers: do not abandon the discipline term. At 48-to-1 it is still where the traffic is. Run both, and expect the ratio to close.
  • In-house: if you own access control, monitoring or validation, the AI version of your job already has a name. Using it makes the work legible to the people approving budget, who increasingly sit outside your function.
Chapter 1 · The shifteudai.

Figure 5 · The practice and its replacement

The words for doing the work are shrinking fastest.

Response-practice language against its AI-framed equivalents — command, exercise, recovery, investigation, response. 132 of 158 measurable response terms are declining. Eight per panel.

THE PRACTICE 1.59M/mo · −16% ITS AI EQUIVALENT 33k/mo · +229% 450kincident command system−13%290kwargaming−16%128kdisaster management−29%85kroot cause analysis−18%56kemergency operations center−10%21kcrisis management−27%20kdisaster recovery−30%15kincident management−31% 6.8kagentic ai security+1331%4.5kai guardrails+158%3.3kai agent security+529%3.3kai observability+266%2.5kai security engineer+258%1.8kai discovery+80%1.8kagentic ai governance+1054%1.3kai access control+1245% Bars are square-root scaled within each panel. The panels are not to a shared scale — the left is 49× the right in total volume.

What the numbers say

The practice vocabulary is enormous and falling: 199 terms, 1.59 million searches a month, down 16% year on year. Incident command system alone carries 450,000. Its AI equivalents total 33,000 — a fraction of the volume — and grow 229%.

Term by term the substitution is legible. “Incident response plan” falls 19% while “AI incident response plan” grows 778%. “Security operations center” falls 13% while “agentic AI security” grows 1,331%. The capability is identical. The language attached to it is not.

What to do with it

  • In-house: the discovery language is declining and the discipline is not. But the terms in your runbooks, job descriptions and board papers are the ones fewest people now search, which matters when recruiting, procuring or justifying the function.
  • In-house: the AI equivalents are small enough to still be shaped. What an “AI incident” is, who declares one and what an exercise for it looks like are unsettled questions with 132 searches a month behind them.
  • Providers: the volume is on the left panel and the growth is on the right. Neither side alone is a strategy. The transferable position is the practice, described in the arriving language.

Response-practice group: 199 terms covering command, crisis, emergency, incident, recovery, exercise and investigation language, AI-framed terms excluded. AI operational group: 18 terms. Volume-weighted year-on-year change; term-level values from the 1,621-term pull, group aggregates on the original group definitions.

Chapter 1 · The shifteudai.

Figure 6 · 6 things in the data

What the totals hide.

The narrowing gap is the headline. Underneath it are six patterns the cluster averages hide.

1

Inside AI, solution-seeking language outgrows the concept

“AI governance” grew 90%. “AI governance tools” grew 275% and “AI governance platform” 267%. Searchers are looking not only to understand AI governance but to find something that helps them implement it.

2

Outside AI, the same modifiers mostly underperform

“Enterprise risk management” fell 54%; “ERM software” fell 76%. “GRC software” fell 64%. The tooling label declines faster than the discipline, reversing the AI pattern. One exception: “GRC platform” grew 36%.

3

Training demand is becoming more specific

“Cyber security training” averages 36,617 monthly searches and fell 74%. “AI governance training” grew 294% and “incident response training” 151%. Broad training labels are giving way to specific subjects and obligations.

4

ISO 42001 is closing in on the continuity standard

ISO 22301 averages 27,783 and is flat at −3%. ISO 42001, published December 2023, already averages 44,383 and grows 91%. Interest is not adoption, but the speed signals a forming ecosystem around certification, readiness and audit preparation.

5

The largest AI term is also the least ownable

“AI testing” averages 146,000 — six times “AI governance” and about a third of the AI cluster. It carries at least 2 intents: testing AI systems, and using AI to test software. Its size makes it important; its ambiguity makes it hard for anyone to own.

6

Agent-specific language arrived late and grew quickly

“Agentic AI security” first registered in October 2024 and grew 1,331%, the fastest in the dataset; “agentic AI governance” 1,054%. Neither existed 2 years ago. A new architecture creates its own governance vocabulary fast. The volumes still show a market forming.

The observation to sit with. Number 2 is the most consequential for established providers. If you sell a GRC, ERM, business-continuity or incident-management platform, the data does not say the underlying problem has gone. It says the capability is less likely to be found through the category name vendors have historically used. “Business continuity manager” fell 88%, “incident management software” 83%, “compliance management software” 76%, while AI-framed language around controls, readiness and assurance grows. The capability remains. Its established route into the market is losing visibility.

Chapter 1 · The shifteudai.
Pale dotted trails converging from the left into a single orange dot, then fanning out again in green and cyan toward the upper right.

Chapter 2

Why now

10 months

Before the EU AI Act was politically agreed, people were already searching how to comply with it.

For providers

Regulation creates the search long before it creates the obligation. See when attention forms around a new rule, how wide the window stays open and how fast it closes once the deadline passes.

For risk & security teams

Your organization starts asking questions on the regulator’s schedule, not yours. See where attention peaks relative to each deadline, and what happens to it afterwards.

7How the vocabulary arrived8The regulatory demand curve9The regulatory split10Where the rules are

Resilience 2030eudai.

Figure 7 · A new way of doing things arrives

Four waves, from AI risk to AI governance in practice.

Each dot marks a term’s first month with measurable search volume — its first observable appearance.

WAVE 1 · IS IT RISKY?generative ai riskai risk frameworkeu ai act compliancegenerative ai governanceai governance softwareai risk assessment frameworkWAVE 2 · HOW DO WE COMPLY?ai compliance toolsai governance trainingresponsible ai trainingai compliance trainingai vendor riskai governance boardWAVE 3 · AGENTS, SPECIFICALLYai literacy trainingai control frameworkeu ai act trainingai compliance platformeu ai act literacyagentic ai securityagentic ai governanceagentic ai riskWAVE 4 · THE OPERATIONAL WORKai incident response planai risk trainingai competency assessmentai governance assessment This wave is still forming. 2022 H22023202420252026 First month with measurable search volume → EU AI ACT MILESTONESPoliticalagreementDec 2023Enters intoforceAug 2024Prohibitions+ AI literacyFeb 2025GPAIobligationsAug 2025General applicability+ enforcementAug 2026
The language moved from concern to implementation. Regulation creates more than one language moment. “EU AI Act compliance” registered in February 2023, ten months before political agreement. “EU AI Act training” arrived in August 2024, the month the Act entered into force. Operational terms followed as enforcement approached. The vocabulary does not arrive once. It evolves as the market moves from anticipating a rule to doing the work. Proposed April 2021; Annex III high-risk rules from December 2027.
Chapter 2 · Why noweudai.

Figure 8 · The regulatory demand curve

Attention peaks the month a law lands, then collapses.

Four regimes, each indexed to its own peak search volume and aligned on its compliance deadline. Two deadlines have passed. Two are still ahead.

-36-24-12DEADLINE+12+21050100 % OF PEAK NIS2DORAEU AI ActCyber Resilience Act months relative to compliance deadline Each regime indexed to its own peak month. NIS2 transposition Oct 2024 · DORA applies Jan 2025 · AI Act applies Aug 2026 (Annex III high-risk extends to Dec 2027) · CRA applies Dec 2027.

What the numbers say

NIS2 peaked in the exact month of its transposition deadline and has since fallen to 45% of peak. DORA peaked 3 months before it applied and now sits at 24% — a 76% collapse in the 18 months since it took effect.

The two regimes with deadlines still ahead behave the opposite way. Both sit at 82% of peak and are climbing. Regulatory attention is an anticipation curve. It peaks before the rule applies.

What to do with it

  • Providers: the commercial window is the 12 to 18 months before a deadline. Launching DORA content in 2025 was launching into a 76% decline.
  • Providers: this reframes Figure 1. The established vocabulary is past its deadlines, which is a different condition from decline.
  • In-house: vendor attention leaves your regime the month you must comply. Buy help before the deadline.

Verdict  A regulation opens a front door when it is proposed and closes it when it takes effect. Where a regime sits on this curve matters more than its volume.

Chapter 2 · Why noweudai.

Figure 9 · The regulatory split

Every growing term is AI. Almost every declining one is not.

Of the 84 regulatory and standards terms in this dataset, the ones gaining demand and the ones losing it sort almost perfectly by subject.

GROWING · AI AND NEW REGIMES DECLINING · ESTABLISHED REGIMES nist ai rmf9.6k+195%iso 4200143k+93%nyc local law 144423+67%eu data act11k+53%eu ai act compliance631+49%colorado ai act2.1k+30%cyber resilience act24k+24%eu ai act65k+18% dora regulation9.2k−50%pra operational resilience110−48%fca operational resilience291−46%iso 3100043k−42%soc 258k−29%nist 800 5316k−26%sox compliance23k−24%iso 27001248k−17%

What the numbers say

The pattern is close to absolute. NIST AI RMF +195%, ISO 42001 +93%, EU Data Act +53%, Cyber Resilience Act +24% — against DORA −50%, ISO 31000 −42%, SOC 2 −29%, ISO 27001 −17% on 247,667 searches.

Two honest exceptions. CMMC grows 4%, a defense-contracting mandate with a hard enforcement date still ahead of it — which is Figure 8’s rule, not a counter-example. And “AI insurance” falls 6%, the only declining AI regulatory term.

What to do with it

  • Providers: a compliance offer named for an established regime is attached to a declining query, however large it still is. The AI-standard framing is the same service with growing demand behind it.
  • In-house: the regimes you are measured against are the ones losing attention. Expect less vendor help, fewer conferences and thinner content on them each year.
Chapter 2 · Why noweudai.

Figure 10 · Where the rules are

One real regime, five small ones, and a gap where the US should be.

Search demand for AI regulation by jurisdiction. This is what a provider selling internationally actually has to answer.

101001k10k65k EUROPEAN UNIONeu ai act65,417+18%UNITED STATES · FEDERALNo federal AI term registers any search volume.UNITED STATES · STATEcolorado ai act2,117+30%nyc local law 144423+67%california ai regulation312+6%texas ai act78+3%illinois ai video interview act55+27%REST OF WORLDchina ai regulation544+8%ai verify singapore164+22%canada aida103−25%korea ai act98+4% Average monthly searches, log scale. Blue = growing year on year, orange = declining.

What the numbers say

The EU AI Act holds 65,417 searches — 31 times the largest US state term. No US federal AI term registers measurable volume at all, so there is no national frame to search for.

Five state regimes exist instead, and all five are growing: NYC Local Law 144 +67%, Colorado +30%, Illinois +27%, California +6%, Texas +3%. Small numbers. Every one of them rising.

What to do with it

  • Providers: Europe gives you one regime to write for. The United States gives you five and no shortcut. “AI compliance” with no jurisdiction named is what everyone already publishes.
  • In-house: if you operate across US states your obligations are diverging, and the search data shows your peers working it out one state at a time.

Verdict  Europe gives you a category to sell into. The United States gives you five, and the fragmentation is the opportunity.

Chapter 2 · Why noweudai.
Dotted trails sweeping in from the upper left into a single orange dot, then opening below it into concentric dotted rings and falling columns.

Chapter 3

When attention becomes structure

1.8:1

ISO 42001 to ISO 22301 in mid-2026 search volume, 31 months after 42001 was published.

For providers

Search shows a question forming. Certification and analyst coverage show whether an ecosystem followed. See which standards are gaining ground, where certification concentrates and which markets the analysts have quietly closed.

For risk & security teams

The standard you hold may be outlasting the discipline built around it. See how certification volumes have moved, how unevenly they are distributed, and what the analysts stopped covering.

11The standards12Attention and adoption13A standard outlasting its category14The geography of certification15The analyst ladder16The two firms disagree17What executives put in writing18The regulator’s own words

Resilience 2030eudai.

Figure 11 · The standards

A crossover has already happened — in the standards.

ISO 22301 has been the international management-system standard for business continuity for over a decade. ISO 42001, the first AI management-system standard, was published in December 2023. This chart measures attention, not certificates, adoption or revenue.

010k20k30k40k50k 2023202420252026 SEP 2025 · 42001 OVERTAKES ISO 22301 · business continuity ISO 42001 · AI management Monthly searches

ISO 42001 overtook ISO 22301 in September 2025, about 21 months after publication. By July 2026 it had reached 49,500 monthly searches against 27,100 — a ratio of roughly 1.8 to one, some 31 months after it was published. ISO 22301 did not collapse. Its volume stayed broadly flat at −2%, which means the growth is new interest in AI management systems rather than attention transferred off the continuity standard.

Why the comparison matters. Management-system standards create recognizable work: readiness assessments, gap analyses, governance design, documentation, internal audits, certification preparation and training. Those structures already exist around ISO 22301 and ISO 27001. ISO 42001 applies them to a new subject. The requirements differ, but much of the delivery architecture is familiar.

The transfer opportunity. The broader AI and established vocabularies have not crossed, but one AI-specific standard has already overtaken a mature continuity standard in search interest. That does not prove certification volumes or budgets have crossed with it. It shows where attention, and an ecosystem of services, is forming. Firms experienced in management systems, assurance, auditing and training are not starting from zero. The methods transfer. Applying them still needs credible AI-specific expertise. The standard is new. Most of the work required to operationalize it is not.

Chapter 3 · When attention becomes structureeudai.

Figure 12 · Attention and adoption

Attention is moving faster than the adoption data.

July 2026 global search volume beside the latest available official certificate counts. Shown together for context, not as equivalent units: search volume is current monthly attention; a certificate count is the installed base at a reporting date, where one organization may hold several certificates and one certificate may cover many sites.

StandardJuly 2026 searchesLatest valid certificatesEcosystem
ISO/IEC 27001201,00096,709Substantial interest, large established base
ISO 2230127,1004,595Smaller but established
ISO/IEC 4200149,500Not reported in cited surveyPublished Dec 2023; attention ahead of the data

What the numbers say

ISO 42001 was published in December 2023. Search interest has developed quickly enough to overtake ISO 22301, but the annual certification statistics have not yet provided a comparable official count. Its figure is not reported — not zero.

The reporting lag is the useful part. A new standard needs accreditation bodies to extend their scopes, organizations to implement the management system, audits to complete and certificates to reach the reporting system. Search attention shows up years earlier in that sequence.

What to do with it

  • Providers: the opening is the work that happens before certification — education, readiness assessment, governance design, gap analysis, internal audit, certification preparation. That is where the services ecosystem forms, and it forms first.
  • In-house: existing ISO 27001 experience may provide reusable management-system processes and evidence, but ISO 42001 adds distinct requirements around AI governance, impacts, accountability and lifecycle oversight.

Verdict  Search reveals the questions forming now. Certification statistics confirm adoption later. ISO 42001 currently sits in the gap between them.

Certificates: ISO Survey of Management System Standard Certifications 2024 (ISO/CASCO), compiled from IAF CertSearch. ISO 42001 is not among the standards that edition covers, so no official count exists. This is not a reported zero.

Chapter 3 · When attention becomes structureeudai.

Figure 13 · A standard outlasting its category

Certification is growing inside a shrinking discipline.

Valid ISO 22301 certificates by annual survey edition, with the standard’s own search volume beneath each year. A certificate count is an accumulated stock; search volume is current discovery.

01k2k3k4k5k CERTIFICATES YOY SEARCHES / MONTH 20202,205no data20212,559+16%no data20223,200+25%26,12020233,524+10%28,19220244,595+30%29,192 Certificates from the ISO Survey; searches are the annual mean and begin August 2022.

What the numbers say

Reported certificates rose in every edition shown, from 2,205 to 4,595.1 Search interest in the named standard stayed relatively stable — but the wider business-continuity vocabulary weakened sharply: “business continuity manager” fell 88%, “business continuity software” 79%, and operational-resilience terms also declined.

These are not contradictory. A certification base can keep expanding while fewer people enter through the discipline’s terminology, the software category loses visibility, investment shifts toward cyber, regulation and AI, and continuity becomes embedded inside broader resilience programs.

What to do with it

  • Providers: a growing certification base does not guarantee a growing software or services market. The nearer opportunities sit around mandatory evidence, audit readiness and adjacent regulatory requirements rather than the broad business-continuity category.
  • In-house: certification keeps its institutional standing even as the discipline loses external attention. That makes ISO 22301 more useful for holding budget than for attracting it.

Verdict  The standard is proving more durable than the category built around it.

Certificates: ISO Survey 2020–2024, ISO/CASCO. Coverage varies by edition — ISO 27001’s count fell 32% in the 2023 survey on reduced participation, then rose with the 2024 move to IAF CertSearch. Counts are an accumulated stock shaped by renewals, regulatory requirements and procurement expectations.

Chapter 3 · When attention becomes structureeudai.

Figure 14 · The geography of certification

Global certification is not one market.

Share of reported valid certificates by country in the cited ISO Survey edition. These show where certificates are reported — not where demand or spending resides, and may reflect differences in certification culture, regulatory expectation and reporting coverage.

ISO/IEC 27001 · 96,709 CERTIFICATES China34.5%India7.0%Japan6.9%United Kingdom4.6%United States of America4.4%Italy3.4%Türkiye3.3%Germany2.5% ISO 22301 · 4,595 CERTIFICATES Greece12.0%United Kingdom9.6%South Korea5.8%UAE5.5%India5.1%Italy5.0%Saudi Arabia4.1%Germany4.0% Share of reported valid certificates, ISO Survey 2024. 251 countries reported.

What the numbers say

ISO 27001 is highly concentrated: China accounts for 34.5% of reported valid certificates and the 5 largest countries for 57%. ISO 22301 is far more dispersed — Greece leads at 12%, then the UK at 9.6%, South Korea, the UAE and India, with the top 5 at 38%.

The United States accounts for 4.4% of reported ISO 27001 certificates and 2.3% of ISO 22301. That is not underinvestment. It is a market that proves the same things through different frameworks, assurance mechanisms and procurement conventions.

The standard may be global. Its commercial market is local.

What to do with it

  • Providers: treat certification-led go-to-market as a geographic strategy, not a global category strategy. The largest reported certification bases differ significantly by standard.
  • Providers: a large installed base indicates an established ecosystem, not current demand. Pair it with certificate growth, search behavior and local regulation.
  • Providers: do not apply worldwide search findings to a single-country campaign. Country-level search data is required before assuming the same language patterns hold locally.
  • In-house: where ISO 22301 adoption is less common, certification may provide differentiation, but the certificate count alone cannot establish how stakeholders value it. The survey reports 107 valid US certificates.
Chapter 3 · When attention becomes structureeudai.

Figure 15 · The analyst ladder

Analysts retired business continuity while certification kept growing.

Gartner formalizes a market in rungs: a trend, then an emerging market, then a ranked one. Three categories, sixteen years, three outcomes.

201020122014201620182020202220242026 GARTNER MARKET LADDER AI governanceMG · AI TRiSMrenamed “AI Governance Platforms”MQ · 13 of 100+ vendorsGRCMQ · eGRCOperational RiskIntegrated RiskIT RiskMG onlyMQ · back to “GRC”Business continuityMQ · BCM Planningfinal MQ · no successor since ranked market · MQemerging market · Market Guideframework or trendretired, no successor

What the numbers say

AI governance climbed the whole ladder in under five years, and the last rung took seven months — Market Guide November 2025 to inaugural Magic Quadrant June 2026, the fastest promotion in the dataset. GRC took fourteen years and four renames to arrive back at the name it started with.

Business continuity is the one that matters most here. Its final Magic Quadrant was September 2019 and nothing succeeded it. Over the same period, ISO 22301 certificates rose from roughly 2,000 to 4,595 (Figure 13).1

What to do with it

  • Providers: analyst coverage is attention, not size. Continuity lost its ranked market and kept its practitioners.
  • Providers: AI security sits today where AI governance sat in 2024: a named trend and a first Market Guide, no ranked market. On the AI TRiSM precedent that is roughly 18 months of open ground.
  • In-house: if your discipline has no ranked market, expect to make your own case. Nobody will hand you a quadrant to point at.

Verdict  Search and analyst coverage measure discovery. Certification measures the work. Here they come apart completely.

Chapter 3 · When attention becomes structureeudai.

Figure 16 · The two firms disagree

Same domain, different market — and sometimes no market at all.

Where each firm placed 7 domains on its own ladder. Ranked means a Magic Quadrant or Wave; emerging a Market Guide or Landscape; framework a model with no vendor evaluation. “Not in dataset” means absent from the compiled event tables, not necessarily from the firm’s coverage.

DomainGartnerForresterDivergence
AI governanceMQ · Jun 2026Wave · Aug 2025Forrester first, by 10 months
AI securityMarket Guide · Feb 2026AEGIS framework · Aug 2025No ranked market at either firm
GRCMQ · 2025, after 4 renamesWave · Q2 2026Gartner went dark 2022–24
Integrated risk managementMQ 2018 → retiredNever formalizedForrester, 2019: “IRM is GRC”
Business continuityMQ retired · Sep 2019CEM Wave · Q4 2023Forrester reframed it as critical events
Physical securityNo marketTech Tide · Q2 2020Neither firm ranks it

What the numbers say

Forrester reached a ranked AI governance market 10 months before Gartner — Wave in August 2025 against Magic Quadrant in June 2026 — then renamed it Responsible AI Solutions in January 2026, returning to the label it first used in November 2020. A five-year round trip.

On integrated risk management they contradict each other outright. Gartner built the market in 2018 and retired it; Forrester refused to build it, writing in 2019 that IRM was simply GRC. Forrester was right.

What to do with it

  • Providers: there is no single taxonomy to position against. Pick the firm your market reads, and expect the label to change under you. Zero Trust Edge became SASE.
  • Providers: AI security has no ranked market at either firm. No other domain here still has its naming open.
  • In-house: a category with no Quadrant or Wave is not immature. Physical security has neither and is the most stable area in this report.
Chapter 3 · When attention becomes structureeudai.

Figure 17 · What executives put in writing

The new language is reaching signed disclosure.

Matching 10-K result documents on SEC EDGAR, 8 exact phrases, August 2022 to July 2026. Documents, not companies — not deduplicated issuers, and may include 10-K/A filings and exhibits. A proxy for disclosure commitment, not budget.

CONCEPT FULL PERIOD ◦ 2023   ● 2025  · MATCHING 10-K DOCUMENTS 2023→2025 1101001k2.5k business continuity8,374+28%third-party risk management3,240+1,287%cyber incident response860+1,522%operational resilience641+278%AI governance *292+6,300%model risk management190+20%AI security53+220%compliance automation25+75% * AI governance: none of the 10 sampled 2026 passages contained the phrase in the opened filing. Treat its counts as unverified.

What the numbers say

Business continuity accounts for 8,374 of the 13,675 documents — 61% on its own.4 In formal disclosure the established vocabulary is not in retreat. But every steep growth rate belongs to the newer language: third-party risk management rose 14× between 2023 and 2025, cyber incident response 16×, operational resilience nearly 4×.

Of 80 sampled 2026 passages, 68 contained the phrase. Only 8 read as procurement signals. 36 described operational action or governance, 20 were vendors positioning their own products.

What to do with it

  • Providers: a fifth of the sampled passages were vendors describing their own products. Disclosure language is a competitive positioning surface, and it is public.
  • Providers: disclosure commitment runs well ahead of anything resembling buying. Eight procurement signals in 68 validated passages is a market writing policy, not placing orders.
  • In-house: the four fastest-growing phrases here are the ones your peers put in a signed filing. Nothing else in this report is closer to language your board already recognizes.

Verdict  Search shows what people ask. Disclosure shows what executives will sign. Both point the same way, and neither is a budget.

Chapter 3 · When attention becomes structureeudai.

Figure 18 · The regulator’s own words

The regulator never used the market’s words.

The 8 phrases from Figure 17, tested against DORA in full — 106 recitals, 64 articles, OJ L 333.5 An exact-string test on one instrument; the EU AI Act, NIS2 and the SEC rules have not had the same pass. Where a phrase is absent, the Regulation’s own term is given.

Phrase, as filed and searchedIn DORAWhat the Regulation writes instead
business continuityObligationUsed directly — “ICT business continuity policy”, Arts 5(2)(e), 11, 16(1)(f)
operational resilienceModifieddigital operational resilience” — defined term, Art 3(1); in the title
third-party risk managementRenamedICT third-party risk” — defined term, Art 3(18); Chapter V heading
cyber incident responseRenamedICT-related incident”, Art 3(8); “ICT-related incident response”, Art 17(3)(f)
model risk managementAbsentNot in scope. The Regulation governs ICT risk, not model risk; the obligation sits elsewhere.
AI governance · AI security · compliance automationAbsentNo AI vocabulary appears anywhere in the instrument. DORA was adopted in December 2022, before this language existed at scale — the absence dates the instrument, it is not a gap.

What the numbers say

Of the 8 phrases executives put into signed filings, one appears in DORA as written. Three appear only with a modifier the market drops — digital, ICT, ICT-related. Four do not appear at all, and all four are the AI-framed ones.

The instrument that reorganized operational resilience for European finance contains no reference to AI. The language now growing fastest arrived after the law that reshaped the market.

What to do with it

  • Providers: the regulator supplies a subject and a modifier; the market keeps the subject and drops the modifier. Write the subject, and carry the modifier only where a compliance reader needs it.
  • Providers: do not sell AI governance as a DORA obligation. It is not one, and the AI-framed demand here has a different legal source.
  • In-house: if your AI controls are justified under DORA, the text will not support it. Name the right instrument.

Verdict  Regulation creates the subject. The market names it. The gap between them is where positioning happens.

Chapter 3 · When attention becomes structureeudai.
Pale dotted arcs curving up from the lower left to a single orange dot, where a bright green stream lifts away to the upper right.

Chapter 4

The choices the shift creates

0

Terms in this dataset that offer scale, growth and clarity at the same time.

For providers

No term in this dataset offers scale, growth and clarity at once. The only choice is which trade-off to accept. See where the room is, what it costs to compete for and when in the year to move.

For risk & security teams

Some of your formal language travels. Some of it registers nowhere at all. See which terms people actually use for the problems you own, and which exist only in documents.

19The scale–momentum map20The modifier21Learn, buy, prove22The invisible vocabulary23When demand happens24The price of attention

Resilience 2030eudai.

Figure 19 · The scale–momentum map

No term offers scale, growth and clarity at once.

Sixteen representative terms by average monthly volume (log axis) and year-on-year change (linear). Reference lines at 6,000 searches and 0%: the upper-right quadrant combines scale and growth, upper-left is emerging, lower-right established but declining.

OPEN GROUND · 3 CONTESTED · 4 ABANDONED · 2 ERODING INCUMBENT · 7 +200%+150%+100%+50%0%-50% 1.5k3k15k30k75k150k Average monthly searches (log scale) → nist ai rmf 3.6k +195%ai governance certification 1.9k +145%ai readiness 3.6k +125%security awareness training 14.8k +91%ai governance 12.1k +90%ai testing 74k +76%ai risk 9.9k +25%iso 22301 27.1k -2%tabletop exercises 6.6k -8%cyber resilience 6.6k -12%operational resilience 3.6k -14%incident response plan 8.1k -21%third party risk management 8.1k -31%scenario testing 8.1k -34%ai red teaming 5.4k -70%cyber security training 110k -74%

Only four terms combine more than 6,000 monthly searches with positive growth, and not one is uncontested. AI testing is large but semantically divided between testing AI systems and using AI to test software. Security awareness training now falls 43% to 13,183, after a spike that briefly reached 135,000 against a baseline near 8,000. AI governance has momentum and substantial vendor attention already. AI risk has scale but grows at 27%.

The fastest-growing terms sit on the smaller side of the map. NIST AI RMF grew 190% on 10,200 average monthly searches; AI governance certification 137% on 5,550. More room to establish authority, less existing demand to capture. That is the trade-off. Compete for attention that already exists, or build the language future attention will arrive through. The first buys scale and inherits the ambiguity. The second buys differentiation and costs you time before the market is there. The wave chart shows the same progression; this maps it.

Chapter 4 · The choices the shift createseudai.

Figure 20 · The modifier

The modifier isn’t the signal. The subject is.

Terms grouped by the language attached to the underlying concept, then split between AI-framed and established subjects. Growth is calculated from combined search volume within each group, so higher-volume terms carry greater weight.

0% +180%−61%platform / software / tools8 AI · 43 established+211%−54%training / literacy7 AI · 32 established+84%−40%management / manager6 AI · 32 established+87%+14%framework / standard / policy7 AI · 4 established+32%+41%assessment / audit / certification18 AI · 34 established AI-framed termsEstablished terms

The first three pairings carry the central pattern. Attach “platform”, “software” or “tools” to an AI-framed concept and aggregate volume grows 180%; attach the same language to an established concept and it declines 61%. Training and literacy diverge the same way — +211% against −54% — and management language follows it too, +84% against −40%. This is not a move away from platforms, training or management as ideas. They are being searched for in relation to AI.

The final two groups behave differently. Framework, standard and policy grows on both sides (+87% AI-framed, +14% established). So does assessment, audit and certification (+32% and +41%). These are the only modifier groups that stay positive regardless of subject, and they share a function: turning a claim into evidence through a defined framework, independent assessment, audit or certification.

The implication. For providers positioned around established tooling categories: 74 established terms containing “platform”, “software” or “tools” declined 61% in aggregate while 10 AI-framed equivalents grew 180%. The evidence layer grew on both sides, which makes the transferable position the proof rather than the tool: showing that a system, a control or an organization is governed, prepared and working as intended. Tooling language follows the subject. Evidence language travels across subjects.

Chapter 4 · The choices the shift createseudai.

Figure 21 · Learn, buy, prove

The market is learning and shopping at once. Evidence is forming more slowly.

The 62 AI-framed terms whose language signals an intent — learning, buying or proving. These describe patterns in aggregate search language, not sequential funnel stages or individual buyer behavior. Six largest terms by volume shown per group; full group size beside each heading.

Learn +211% 8 terms

Training and literacy — the smallest group by volume, the fastest-growing by percentage. Volumes are small, but the direction is consistent.

  • ai governance training 1.6k +513%
  • ai literacy training 727 +159%
  • eu ai act training 159 +16%
  • ai compliance training 123 +79%
  • responsible ai training 98 +15%
  • eu ai act literacy 28 −47%

Buy +181% 13 terms

Platform, software and tool terms. Commercial discovery is accelerating while the category’s definitions and evaluation criteria are still developing.

  • ai governance tools 4.8k +314%
  • ai governance platform 4.8k +298%
  • ai governance software 888 +110%
  • ai compliance tools 578 +138%
  • ai compliance software 540 −36%
  • ai risk assessment tool 377 +32%

Prove +49% 41 terms

Assessment, audit, testing, readiness and certification — much the largest group by volume, and the slowest-growing in aggregate.

  • ai testing 150k +76%
  • ai certification 25k +15%
  • ai audit 7.3k +44%
  • ai auditability 7.3k +44%
  • ai readiness 6.8k +125%
  • ai governance certification 5.2k +145%

Sensitivity check on the Prove group. “AI testing” runs at 150k searches a month against the group’s 213k, so it is 70% of Prove’s volume, and it carries at least two intents. Excluding it, Prove grows +10% rather than +49%. Excluding the volatile “AI red teaming” as well, +39%. Under every variant, evidence language grows more slowly than commercial language: the gap between Buy at +181% and Prove at between +10% and +49% is real, not an artifact of one keyword.

Volumes are the mean monthly figure over the latest 12 months, the same basis as the growth rates and the group shares — not the 4-year average used elsewhere in this report. Year-on-year compares those 12 months with the preceding 12. Each term is assigned to one group by its language: a product word (platform, software, tool) takes precedence over an evidence word, so “ai risk assessment tool” counts as Buy. The remaining AI-framed terms describe the subject rather than an intent.

Chapter 4 · The choices the shift createseudai.

Figure 22 · The invisible vocabulary

365 terms never reached measurable search volume.

Across the 48-month dataset, 365 of 1,621 terms stayed below Google Keyword Planner’s measurable reporting threshold throughout. They cluster in three revealing places.

AI applied to the practice 10 terms

AI business continuity · AI disaster recovery · AI crisis simulation · AI resilience testing · AI tabletops · AI agent incident response · AI forensic investigation · AI system failure response · agent containment · AI model incident

Regulatory testing language 21 terms

CPS 230 scenario testing · OSFI E-21 testing · DORA scenario testing · impact tolerance testing · impact tolerance breach · severe but plausible scenario · critical operations mapping · regulatory scenario testing

Named tooling categories 14 terms

Crisis simulation platform · exercise management platform · resilience management platform · business continuity testing software · crisis exercise software · crisis communications platform · AI risk management platform

What the numbers say

The first group is the most consequential. Figure 5 showed AI operational language arriving fast. All of it is agent security and monitoring language. AI applied to continuity, crisis, recovery and exercise practice registers nothing at all. There is no measurable search for what an AI disaster-recovery plan or an AI tabletop is.

The regulatory group shows a gap between formal terminology and discovery behavior: CPS 230, OSFI E-21, impact tolerances and severe-but-plausible scenarios are recognizable inside practitioner contexts, but their exact phrases did not register. Organizations may be instructed to comply in one vocabulary while researching the problem in another.

What to do with it

  • Providers: these phrases will not generate meaningful search traffic alone. Connect them to the higher-volume problem and regulatory language people do use.
  • Providers: the AI-and-practice group is an unnamed category. Nobody is searching for it because nobody has named it. An unnamed term is a different opportunity from a contested one.
  • In-house: translate policy and regulatory language into the practical questions colleagues actually ask. Formal precision and internal comprehension are different requirements.

Zero measurable volume across all 48 months. Not evidence of zero searching — these phrases may appear in procurement, regulation, direct navigation or longer queries the tool groups differently.

Chapter 4 · The choices the shift createseudai.

Figure 23 · When demand happens

Interest doesn’t follow a calendar.

Total monthly search volume across all 1,621 terms, four years pooled, indexed.

9095100105110 109Jan98Feb108Mar103Apr104May92Jun95Jul97Aug99Sep100Oct98Nov98Dec Index of total monthly search volume across all 1,621 terms, 4 years pooled. 100 = average month.

What the numbers say

January is the peak at 109. June is the trough at 92. Nine of the twelve months sit within 7% of average and seven are within 3%, so the whole year spans 17 index points.

There is no budget-cycle spike and no year-end collapse. A narrower term list showed a December trough of 82 and a March–August peak; on the full set both flatten, which means they were properties of those terms rather than of the market.

What to do with it

  • Providers: January is the strongest month and June the weakest, which is the mildest seasonality you will find in any B2B category. Neither gap is worth planning around.
  • Providers: the flatness is the finding. Campaign timing is a weak lever in this market. There is no month worth waiting for and none worth avoiding.
  • In-house: if you need attention for an internal program, January and March are marginally better. Marginally is the honest word.
Chapter 4 · The choices the shift createseudai.

Figure 24 · The price of attention

Price has not followed momentum.

Estimated top-of-page Google Ads bids for the highest-priced terms. Estimates of what an advertiser might need to bid for placement — not prices paid, market size or revenue. Role titles and brand terms excluded; corporate-training queries marked. Green = growing, orange = declining. Figures are Australian dollars, the account currency of the export, so read the ranking and the spread rather than the absolute level.

A$0A$50A$100A$150 EST. TOP-OF-PAGE BID VOL/MO YOY compliance training lms [training]A$138480-50%ai penetration testingA$133720+84%crisis management softwareA$122390-59%business continuity softwareA$1151,600-79%compliance training platform [training]A$111260-20%mass notification softwareA$109210-22%policy management softwareA$962,400+70%best grc softwareA$89260-15%third party risk management softwareA$882,900+24%

What the numbers say

Several of the highest estimates belong to terms losing volume: “crisis management software” at A$122 while declining 59%, “business continuity software” at A$115 while declining 79%. Declining volume does not automatically lower acquisition costs.

A smaller set pairs high estimates with growing interest: AI penetration testing (A$133, +84%), policy management software (A$96, +70%), third-party risk management (A$88, +24%). Candidates for testing, not a buy list.

The old categories remain expensive to compete for even as fewer people search for them. The emerging ones offer momentum, but not yet proven conversion.

What to do with it

  • Providers: review paid-search investment where declining volume meets a high bid estimate. They may still convert, but they are increasingly expensive places to defend visibility.
  • Providers: test growing terms with commercial intent before competition increases. Low Ads competition — 620 of 825 terms — is a lightly advertised surface, not an uncontested organic market.
  • Providers: separate role-title, training, informational and software queries. Different buyers drive their bids, so comparing them directly misleads. The two marked [training] are corporate-training queries, not resilience-software ones.
Chapter 4 · The choices the shift createseudai.
A single dotted stream descending to one orange dot, then branching into separate dotted clusters below it.

Chapter 5

One shift, 8 markets

105

Of the 126 crisis and incident management terms with a measurable year-on-year change, the number declining.

For providers

Eight areas, eight different pictures. See which terms are worth holding in yours, which are being abandoned, and where the AI language has not arrived yet.

For risk & security teams

Your discipline is being renamed around you. See what is arriving in its place, and how much of it your existing capability already covers.

CybersecurityAI securityAI governanceGRC & complianceOperational resilienceCrisis & incident managementPhysical securityTraining & simulation

Resilience 2030eudai.

Expertise · Cybersecurity

A real category, and a much smaller one than it looked.

37 terms and 499,130 searches a month, down 6% — security operations and security technology only. This area was a residual bucket of 359 terms; enterprise risk, insurance, named regulators and vendor brands have been removed from it and from chapter 5. See the appendix.

TermPer monthYoY
soar194,3330%
endpoint detection and response130,833−2%
ciso100,250−6%
security operations center13,500−13%
dfir11,9170%
ot security10,800−65%
managed detection and response8,567−12%
security operations5,117+27%
ics security3,650−7%

What the numbers say

Three acronyms carry most of the area: SOAR at 194,333 and flat, endpoint detection and response at 130,833 and down 2%, CISO at 100,250 and down 6%. Spelled-out and role language falls faster — security operations center −13%, OT security −65%, ICS security −7%.

One term grows: security operations, up 27%. It describes the function as something that runs rather than a department or a tool — the same pattern the AI areas show at much larger scale. Managed detection and response, the other service framing, now falls 12%.

What to do with it

  • Providers: the volume is concentrated in three acronyms. Ranking outside them is a long-tail exercise, and the tail here is short.
  • Providers: “Security operations” is the only term of scale moving up. Department and tool framing falls across the board.
  • In-house: OT security falls 65%, the steepest decline in the area, which is a discovery problem for the teams with the least substitutable expertise in the report.

Verdict  Smaller than it looked, and concentrated in three acronyms.

Chapter 5 · One shift, 8 marketseudai.

Expertise · AI security

The fastest-growing area, and the smallest.

Only 33 terms and 94,986 searches a month, but up 141% year on year — the steepest growth of any area here.

TermPer monthYoY
prompt injection35,508+192%
shadow ai16,333+183%
agentic ai security6,783+1331%
ai red teaming4,817−69%
ai guardrails4,450+158%
ai agent security3,758+529%
ai observability4,150+266%
ai monitoring3,167+37%
ai security engineer2,517+258%

What the numbers say

Prompt injection at 35,508 and shadow AI at 16,333 are the two terms with real scale, up 192% and 183%. Agentic AI security grows 1,331% from 6,783. The area is small in absolute terms and growing faster than anything else in the report.

One term falls, and it is instructive: AI red teaming drops 69% from 4,817 after a spike — emerging language can contract as fast as it forms. AI guardrails grows 158%, AI agent security 529%, AI observability 266%. The spread is wide, which is what a vocabulary still settling looks like.

What to do with it

  • Providers: the momentum is real but the volumes are small. This is a position to establish now rather than a channel to harvest.
  • Providers: prompt injection and shadow AI are the two terms with both scale and growth. They describe concrete problems, which is the pattern that scales first.
  • In-house: shadow AI at 16,333 and up 183% is the discovery signal for a problem most organizations have not inventoried.

Verdict  Highest growth, lowest volume, one cautionary laggard. Early enough to shape.

Chapter 5 · One shift, 8 marketseudai.

Expertise · AI governance

The largest AI area, resting on one ambiguous term.

157 terms and 389,117 searches a month, up 54%. It also contains the most ambiguous term in the dataset.

TermPer monthYoY
ai testing146,000+57%
eu ai act68,833+24%
ai certification24,900+11%
ai governance25,442+90%
ai risk11,667+27%
nist ai rmf10,200+190%
ai governance framework8,600+101%
ai risk management7,925+70%
ai audit7,175+35%

What the numbers say

AI testing carries 146,000 searches a month — well over a third of the area — and means at least two unrelated things: testing AI systems, and using AI to test software. The area growth is real, but a large share of the absolute volume belongs to a term nobody can own.

Underneath it the signal is cleaner. EU AI Act grows 24%, AI governance 90%, NIST AI RMF 190% from 10,200. Framework and named-regime language is where the durable interest sits.

What to do with it

  • Providers: do not build a position on “AI testing”. Split intent means split traffic and no defensible claim.
  • Providers: the named frameworks are the ownable surface. They carry authority the generic terms do not.
  • In-house: AI governance framework at 8,600 and up 101% is the language your board paper will be read against.

Verdict  Real growth, one enormous term you cannot claim.

Chapter 5 · One shift, 8 marketseudai.

Expertise · GRC & compliance

The largest pool of search volume, and almost all of it is falling.

157 terms and 2,799,638 searches a month, three times the next-largest area, and down 19% year on year.

TermPer monthYoY
dora1,747,500−17%
iso 27001243,917−18%
nis284,375−1%
pci dss80,000−23%
soc 258,375−29%
iso 3100042,400−43%
iso 4200144,383+91%
cmmc40,633+5%
fedramp32,042+1%

What the numbers say

DORA alone carries 1,775,000 searches a month and falls 17%, which is the post-deadline pattern: the regime applied in January 2025 and attention has been receding since. ISO 27001 falls 18%, SOC 2 29%, ISO 31000 43%.

Three move the other way. ISO 42001 grows 91% from 44,383 — the AI management-system standard. CMMC grows 5% and FedRAMP 1%, both with enforcement still ahead of them. Every exception is about a deadline that has not passed.

What to do with it

  • Providers: the volume is enormous and the direction is down. Compliance-led acquisition works here, but the terms are getting more expensive per unit of attention.
  • Providers: ISO 42001 is the one growing standard in the area and its service ecosystem barely exists yet.
  • In-house: if your program is described in DORA language, that language peaked at the compliance date. The audit and evidence terms are more durable.

Verdict  Vast, mandatory, and past its peak of attention.

Chapter 5 · One shift, 8 marketseudai.

Expertise · Operational resilience

One abbreviation is holding up the area.

84 terms and 362,386 searches a month, up 5%. Most of it sits in a single abbreviation.

TermPer monthYoY
bc dr278,042+37%
cyber resilience act25,217+28%
disaster recovery19,683−30%
disaster recovery plan10,133−30%
business continuity manager10,292−88%
it disaster recovery6,525−8%
cyber resilience5,992−9%
dr test4,600−14%
operational resilience3,300−16%

What the numbers say

“BC DR” carries 278,042 searches a month — most of the area — and grows 37%, which is the whole of its gain. Spelled out, the same discipline falls: business continuity manager −88%, disaster recovery −30%, disaster recovery plan −30%, operational resilience itself −16% from 3,300.

The Cyber Resilience Act grows 28%, the regulatory pattern again — a regime whose obligations are still arriving. Regulation grows; the discipline’s own nouns do not.

What to do with it

  • Providers: the abbreviation grows while every spelled-out form declines. The choice about what goes in a page title is that concrete.
  • Providers: the regulatory terms are the growth. The discipline terms are the decline.
  • In-house: the language your function uses about itself is losing discovery fastest. Certification and regulatory framing travel further, internally and externally.

Verdict  The discipline is being abbreviated. Nobody abandoned it.

Chapter 5 · One shift, 8 marketseudai.

Expertise · Crisis & incident management

Almost the whole practice is losing its language at once.

165 terms, 934,556 searches a month, down 18%. 105 of the 126 measurable terms are declining — the most uniform decline here.

TermPer monthYoY
incident command system450,000−13%
disaster management127,542−29%
root cause analysis85,000−18%
emergency operations center55,917−10%
csirt32,7170%
crisis management20,958−27%
emergency preparedness19,2500%
incident management14,092−34%
emergency management12,817−41%

What the numbers say

Incident command system carries 450,000 searches a month and falls 13%. Disaster management falls 29%, emergency management 41%, incident management 34%. The one exception at scale is CSIRT, exactly flat — a tooling acronym, not a name for the work. These are what the discipline calls itself.

The growing terms are small and specific: crisis governance up 104% from 203 a month, emergency response exercise up 104%. Governance, leadership and exercise framing grows while the operational nouns fall.

What to do with it

  • Providers: the largest concentration of declining language in the report. Page titles built on incident command, disaster or crisis management terms are losing discovery power in a market that still funds the work.
  • Providers: the growth is in leadership, governance and exercise framing — the executive layer. That is a repositioning instruction, not a keyword plan.
  • In-house: your plans, role titles and training catalog all use the falling terms. That matters when recruiting, justifying headcount, or when the board does not recognize your programme name.

Verdict  The work is not shrinking. Its vocabulary is emptying out.

Chapter 5 · One shift, 8 marketseudai.

Expertise · Physical security

The growth is hiding under an acronym.

24 terms and 290,065 searches a month, up 7% — but the growth is concentrated in one term.

TermPer monthYoY
psim161,333+12%
access control system61,608−18%
visitor management system10,3000%
physical security8,300−15%
perimeter security3,958−8%
evacuation drill3,667−12%
duress alarm3,150−17%
emergency mass notification system1,197−95%
emergency notification2,808−23%

What the numbers say

PSIM — physical security information management — carries 161,333 searches a month, most of the area, and grows 12%. Every plain-language discipline term below it falls: access control system down 18%, physical security down 15%, emergency mass notification down 95%.

The AI vocabulary has just arrived. “AI access control” carries 1,289 searches a month and grew 1,245%. Small, real, and unclaimed.

What to do with it

  • Providers: attention is moving up a layer, from practice language into platform language. PSIM is where it went.
  • Providers: the AI convergence term now exists at 1,289 a month. Early enough to define.
  • In-house: if your program is described in access-control and perimeter language, your next procurement cycle will likely be conducted in platform language.

Verdict  Not a quiet area. The growth sits under an acronym the discipline does not use about itself.

Chapter 5 · One shift, 8 marketseudai.

Expertise · Training & simulation

The format survives. The subject changed.

66 terms and 422,394 searches a month, down 29%. What gets taught has changed. The appetite for teaching has not.

TermPer monthYoY
wargaming290,250−16%
cyber security training36,617−74%
security awareness training13,183−43%
compliance training8,483−46%
cyber range7,725+7%
tabletop exercises5,800−11%
after action review5,267−16%
after action report3,550−14%
risk management training3,075+35%

What the numbers say

Cyber security training falls 74% from 36,617 — the largest single loss of volume in the dataset. Compliance training falls 46% and security awareness training 43%. Two terms hold up: risk management training grows 35% and cyber range 7%.

Wargaming at 290,250 dominates the area and falls 16%. The pattern is narrowing rather than abandonment: the broad subject lines fall hardest, and what grows is named against a discipline or a facility.

What to do with it

  • Providers: the demand for being taught is intact. The generic subject line is what stopped working.
  • Providers: specificity is the growth vector — risk management training and range-based practice rise while every generic subject line falls.
  • In-house: a broad annual training program is described in the terms falling fastest. Naming the specific capability travels better internally too.

Verdict  Nobody stopped wanting training. They stopped searching for it generically.

Chapter 5 · One shift, 8 marketseudai.

The employment test

Addition at the title. Absorption in the duties.

If the disciplines are being embedded rather than replaced, headcount is the one instrument that can tell absorption from addition — and search cannot. A source-cited corpus of 43 job-posting records, August 2022 to August 2026, with aggregate market data. Observed postings, not a market census.

Both readings are true at once

Named AI governance roles are being created at scale: roughly 71 new US postings a week, a median salary of $169,000, and 25 or more federal Chief AI Officer appointments produced by the 2023 Executive Order.8 That is addition.

The same corpus identifies 13 hybrid roles where established model risk, operational resilience and incident response duties sit inside AI-titled positions. That is absorption. The old titles are not being posted. The old work is being performed under new ones.

The confirmation is a negative one

No posting in the corpus uses continuous assurance or organizational learning as a job title.7 “Lessons learned” appears as a responsibility inside a resilience role and nowhere as a name. The loop is in the duties and not in the title — the same finding the search data gives, reached through a different instrument.

Three patterns in how the hybrids form

  • Model risk expanding to cover AI. Banks and insurers extending Federal Reserve SR 11-7 frameworks to AI and GenAI models — The Hartford, Affirm, State Street, Metropolitan Commercial Bank.
  • Operational resilience absorbing AI-adjacent concerns. DORA roles bundling scenario testing, third-party risk, incident response and lessons learned into a single function — the ECB, Robert Walters.
  • AI-native firms borrowing established practice. Trust and safety, red teaming and incident management rebuilt inside AI companies — OpenAI, Microsoft, Ethos Life, Parloa.

Draup reports AI governance and model risk skills growing 81% year on year. CSET Georgetown finds the AI ethics and governance share of AI postings rising from roughly 6% in 2018 to 10% in 2023, on 4.4 million postings.

Verdict  The function is being added to. The work is being absorbed. Those are not competing readings — they are the same movement seen from the title and from the duties. Limits: observed rather than exhaustive, weighted to the US and UK, with no individually verified postings between Q3 2022 and Q3 2023. The quarterly tallies are not a demand series; the hybrid-role patterns and the third-party aggregates carry the reading.

The employment testeudai.

The capital test

Language moves first. Money follows, in order.

Two instruments measuring the same thing on the same basis: the share of transactions that use AI-framed language. 449 private funding rounds and acquisitions, and 737 government contract awards, both August 2022 to August 2026.11 Counts, not values — private value is concentrated enough that one deal defines a quarter, and awards arrive in five currencies that are never summed.

The lag runs in a fixed order

Search attention — AI-framed language grew 302% against 2023.

Private capital — the AI-framed share of deals went from 24% in 2022 to 41% in 2026.

Public procurement — the AI-framed share of awards went from 1% to 17%.

Each instrument is still climbing, and each started later than the one before it.

Capital did not wait for the vocabulary

A quarter of all transactions were already AI-framed in 2022, before the search language moved. Against +302% in attention, a climb from 24% to 41% is a flat curve. AI is 36% of deals but only 28% of disclosed value, so these are consistently smaller transactions: the category is being funded broadly rather than concentrated.

Public money is the last to change, and the fastest moving

AI-framed concepts took 1% of government awards in 2022 and 17% in 2026 — a seventeenfold rise from almost nothing, and the steepest curve of any instrument in this report.

The established vocabulary still takes 93% of all awards across the period. Incident management alone accounts for 311 of the 737, business continuity 145 and crisis management 138.12 All four AI-framed concepts combined account for 51.

What these two cannot tell you

A deal is evidence of investment and an award is evidence of a purchase. Neither is revenue, market size or growth. The procurement set is weighted to the UK and EU, which hold 521 of the 737 awards, so it is not a global picture.12 The year series covers the 726 dated awards; 11 carry no quarter. Both endpoints are partial years.

Verdict  Attention, capital and procurement all move the same way and none of them moves at the same time. Language is the earliest signal and the least binding; a government award is the latest and the most. The gap between them is the window.

The capital testeudai.

The next 18 months

What is already visible

The 8 instruments run at different lags. Language moves first, regulation sets the date, private capital commits early, disclosure records what executives will sign, certification confirms years later, analysts formalize it or retire it, job postings show which duties have moved, and public procurement arrives last. That spread is what makes the near future partly readable: several things have already arrived in the language and have not yet arrived anywhere else.

What this cannot do is forecast. Nothing here predicts 2030. It shows what is present in the earliest signal and absent from the later ones, which is a different and more defensible claim.

Arrived in language

Agent governance. Discovery, delegated authority, tool risk, runtime monitoring, kill switches. The vocabulary is 21 months old and growing fastest in the set.

Not yet in: a named obligation, a certifiable standard, or analyst formalization.

Arrived in language

AI management systems. ISO 42001 overtook ISO 22301 in search in September 2025 and reached 49,500 by mid-2026.

Not yet in: the certification statistics, which do not survey it.

Dated, not yet felt

EU AI Act high-risk obligations, August 2026. Wave 4 operational terms — incident response plans, competency and governance assessments — arrived through 2025 and early 2026, on the pattern that preceded the Act taking effect.

Just arrived

AI access control. The physical-security convergence term exists now — 1,289 searches a month, up 1,245% — where a year ago there was nothing.

Not yet in: a platform category, a standard, or anyone’s positioning.

Growing on both sides

Evidence. Assessment, audit, certification and readiness grow whether the subject is AI-framed or established. The one modifier group that does not depend on which language wins.

Resilience 2030eudai.

The pattern behind the shift

Every function is now a loop. Loops have failure built in.

Risk, security and resilience have always been loops: govern, detect, respond, recover, learn, assure, and round again. That is what a management system is. Product, operations, strategy, software delivery, marketing, support and AI development are converging on the same operating model: define the goals that must be protected, detect when they slip, respond, correct, retain the lesson and prove the cycle worked.

The same six stages under other names. An SRE setting an error budget is performing risk appetite. A leadership team resetting OKRs is performing governance review. A growth team running a holdout is performing control testing. An AI team running evals is performing assurance. None of them call it that, and none report to a risk function.

The control basket confirms the loop is not specific to this domain. That is the point rather than a weakness: if every function runs one, every function is already doing this work.

Asserted everywhere. Funded almost nowhere.

2,176 10-K documents named “business continuity” in 2024 — US filers, one year, one phrase.4 There were 4,595 valid ISO 22301 certificates worldwide in the same year1, accumulated across every company ever certified. The units differ and cannot be subtracted, but the direction is unambiguous: the obligation to disclose the risk is close to universal, while the decision to fund a separate certified capability is rare.

What is contested gets named

human in the loop — 53,175/mo, +623%
human on the loop — 2,075/mo, +399%
team learning — 8,200/mo, +73%

What is assumed stops being searched

lessons learned — 66,125/mo, −26%
continuous improvement — 36,417/mo, −45%
after action review — 5,267/mo, −27%
continuous auditing — 1,157/mo, −63%

Every phrase that names the loop as a concept is falling. The two that are rising both ask who sits inside it. Language appears where something is contested and disappears when it becomes infrastructure.

Even the filings are shifting

The phrase describing a document you hold grows slowly — business continuity, +19% from 2023 to 2026. The phrases describing something that has to keep running grow by an order of magnitude more: operational resilience +448%, third-party risk management +1,236%, cyber incident response +1,311%.

Two readings, sequential rather than competing. Absorption happens whether anyone argues for it or not: the disciplines dissolve into every function running a loop, the work grows, the named function does not. Authority has to be claimed — loops fail in known ways, and designing for that is a larger remit than owning a review gate. Nobody holds it yet.

The pattern behind the shifteudai.
A broad dotted S-curve rising from pale blue at the lower left through a single orange dot into bright green at the upper right.

Conclusion

The work remains.

Eight signals, one conclusion. Search shows the question taking shape. Regulation sets the timetable around it. Disclosure records what executives are prepared to sign. Certification confirms adoption later. Analysts formalize categories—or let them recede. Job postings show which responsibilities are moving, and under whose title. Private capital and public awards show when the shift begins to register in transactions.

Together, they describe a field in which the language is changing faster than the underlying capabilities. Risk, security, resilience, and continuity work is increasingly appearing inside functions that have not traditionally named it that way.

No evidence here suggests organizations need this work less than they did in 2023. Fewer people are arriving through the established terms, but the decline is mild against the control basket: comparable business vocabulary outside this domain fell more than twice as far.

That makes this a discovery and ownership question before it is a demand question. Discovery changes through what you publish. Ownership changes through how the work is named before the functions taking it on establish their own vocabulary. Nothing in this research suggests changing the capability itself.

What this cannot show is where the money is. Search measures attention, not spend, and established language remains materially larger. Reading a 302% rise as an immediate budget shift would put positioning ahead of the market it is meant to serve.

Resilience 2030eudai.

What follows

The same data, two different jobs.

If you sell into this market

  • Audit your page titles against this list. A category page named for a term declining 30% or more a year is competing hard for a shrinking query.
  • Claim a Wave 4 term while volume is low and competition thin — 620 of 825 terms carry Low competition (Figure 24).
  • If your expertise is in risk, security, compliance or continuity, the capability transfers. The market no longer describes the need in your words: “resilience testing” is falling, “AI readiness assessment” grew 140%.
  • Expect “AI governance” to saturate. At 24,192 searches a month and 90% growth it is already crowded. The defensible position is a narrower problem with your name on it.

Cluster totals exclude brand names and named standards. Growth figures are year-on-year to July 2026.

If you run risk, security or compliance inside a company

  • Your vendors’ language is about to change under you. Terms that grew 300% or more did so because someone repositioned to meet them. Check whether the product changed too.
  • The market is selling certification and assessment because that is what buyers ask for. Be clear whether you need the evidence or the underlying control, because they are sold together and priced together.
  • The declining terms are still your obligations. Regulatory pressure on continuity and third-party risk has not fallen 30%.
  • “Third party risk management software” grew 22% while the discipline itself fell 34%. If you have not mapped which of your providers now act rather than advise, that is the gap the market has already noticed.

The short version. Between 2023 and 2026, demand for the language of AI authority grew 302% while demand for the industry’s established vocabulary — risk, security, compliance, continuity — fell 13%, and 29% year on year. Measured against a control basket outside this domain, that decline is mild: comparable business vocabulary fell more than twice as far. The words are not the problem. The work is moving. Every function that now runs a loop performs governance, detection, response, recovery and assurance under its own vocabulary — and the phrases that name the loop as an idea are falling, while “human in the loop” grows 623%. What is contested is no longer whether the loop exists, but who sits inside it.

What followseudai.

Questions for deeper reflection

None of these need new research. They need someone to answer them out loud, with a name attached.

Your discovery language
  • Which of our page titles use a term that is declining?
  • What would the AI-framed version of that page be?
A position we can own
  • Which single term do we want to be the recognized answer for in 18 months?
  • If a buyer removed our logo from our homepage, could they name us?
Where the budget goes
  • Where are we paying to defend a term whose search volume is falling?
  • What evidence do we hand a security reviewer without being asked?
Agent exposure
  • Which agents are already running inside our organization?
  • What can they reach, and who approved that?
Making the program legible
  • Does anyone outside the function use our program’s formal name?
  • Does that matter for how it gets funded?
Obligations arriving
  • Which obligations landing in the next 18 months do we already cover under a different name?
  • Would an exercise involving only our responders test the failure we are most likely to have?
Take it furthereudai.

Method

What the data is.

Where it comes from. Search: Google Keyword Planner, 1,621 terms, monthly, September 2022 to August 2026, classified into six concept families. Brand names and named standards are excluded from cluster totals. Certification: the ISO Survey of Management System Standard Certifications, 2020–2024 (ISO/CASCO, from IAF CertSearch). Regulation: published compliance dates for DORA, NIS2, the EU AI Act and the Cyber Resilience Act.3 Analyst coverage: Gartner and Forrester report metadata, 2010–2026, public sources only, 176 report rows.2 Disclosure: SEC EDGAR full-text search, 10-K results for 8 exact phrases, 13,675 matching documents. Employment: a source-cited corpus of 43 job-posting records, August 2022 to August 2026, with aggregate data from CSET Georgetown (Lightcast), Axial Search, PwC, IAPP and Draup. Private capital: 449 source-linked funding rounds and acquisitions, August 2022 to August 2026, across five categories.9 Public procurement: 737 government contract awards over the same window, matched to eleven concepts across nine buyer countries.10

What we checked. The first ten 2026 results per phrase were opened to confirm the phrase was actually in the document. 68 of 80 contained it. AI governance returned 0 of 10, so its counts are marked unverified rather than quietly used.

How to read the volumes. Keyword Planner is Google’s own first-party data, not a third-party estimate, with one known property: it reports in fixed buckets. Across the 1,256 terms carrying volume there are 59 distinct monthly values. Dependable for scale and comparison. Not to be read to the last digit.

What we excluded. Brand names and named standards are out of the cluster totals. A spike in “ISO 22301” tracks a certification cycle, not a shift in thinking. They still appear in the tables, marked.

Outliers. Three terms carry months more than twenty times their own median and above 100,000 searches. That is bucketing, not an event. For those three only, every month above eight times the term’s median is excluded and each average is taken over the months that remain: skills assessment (4 of 48 months, peaking at 2,740,000 against a 12,100 median), business continuity manager (2 of 48, 550,000 against 14,800) and AI red teaming (1 of 48, 165,000 against 1,000). No other term is adjusted.

Method · what the data iseudai.

Method

And where it stops.

Minimum base. Keyword Planner draws its buckets from one ladder of values. Above roughly 90 searches a month that ladder is geometric, each rung about 22% above the last, so a one-rung move means the same thing at any level. Below 90 the rungs are irregular and a single step reads as anything from 25 to 100%. A term moving from 10 to 20 has not doubled. It has moved the smallest distance the instrument can express.

Growth rates are therefore reported only where the prior-period base is at least 90 and the history spans at least four distinct values. That test removes 30 of the 682 otherwise-eligible terms, and it governs the ranked table in Figure 3. Terms that fail it are named without a percentage rather than dropped, because an emerging term is worth knowing about even when its rate is not worth printing.

The control. AI-framed search attention grew across every subject between 2023 and 2026, so growth here proves nothing on its own. To test it, 125 terms outside risk, security, resilience and compliance were pulled on identical settings6: bare AI terms with no domain attached, plus matched AI-framed and established pairs across recruiting, accounting, marketing, customer support and software delivery.

Read the control on its own basis. The control was pulled alongside the main set on identical settings and classified the same way, so the term set and window match. The measure differs: the control is reported as median per-term growth for terms with a prior base of at least 90, because summed totals would be meaningless here — one term, “ai chatbot”, is 94% of the control AI volume.

On that basis: 331% for bare AI terms with no domain attached, 242% for this report’s AI governance and security family, 117% for AI-framed terms in the control domains. Established terms fell 30% in the control domains against 14% here. Cluster figures elsewhere in the report are aggregate volumes, which is why the headline reads +302% and −13% while the control reads 242% and −14%. Same terms, same window, two measures.

One figure to treat carefully. The established cluster’s year-on-year decline is 29%, steeper than the 16% an earlier, narrower term list returned. Most of that difference is composition: the terms added to reach 1,621 were overwhelmingly established-side, including several very large regulatory acronyms past their compliance deadlines. The direction is not in doubt. The magnitude of a single year’s change on this cluster is the least stable number in the report.

Method · where it stopseudai.

Sources and notes

Every non-search figure, traceable.

Search figures are sourced on each figure. The numbered notes below cover every assertion in this report that does not come from Google Keyword Planner.

1
ISO certification counts

ISO Survey of Management System Standard Certifications, 2020–2024 editions. Published by ISO/CASCO and compiled from IAF CertSearch. Counts are valid certificates, an accumulated stock, not annual issuance. ISO/IEC 42001 is not reported in the cited editions.

2
Analyst coverage

Gartner and Forrester published research metadata, 2010–2026, public sources only — 176 report rows. A placement records how each firm classified a domain, not its size. Ranked means a Magic Quadrant or Wave; emerging means a Market Guide or Landscape.

3
Regulatory calendar

Published compliance dates for NIS2 (Directive (EU) 2022/2555), DORA (Regulation (EU) 2022/2554), the EU AI Act (Regulation (EU) 2024/1689) and the Cyber Resilience Act (Regulation (EU) 2024/2847).

4
SEC filings

SEC EDGAR full-text search, 10-K results only, eight exact phrases, August 2022 to July 2026 — 13,675 matching result documents. Counts are documents, not deduplicated issuers, and may include 10-K/A filings and exhibits. Passage classification is rules-based and provisional.

5
DORA instrument text

Regulation (EU) 2022/2554, full Official Journal text, OJ L 333, 27.12.2022, pp. 1–79 — 106 recitals and 64 articles, read in full. Presence is an exact-string test on the eight phrases used in Figure 17.

6
Control basket

125 terms outside risk, security, resilience and compliance, pulled on identical Keyword Planner settings and classified the same way. Reported as median per-term growth, because one term accounts for 94% of the control AI volume.

7
Job postings

AI Governance, Resilience & Security Job Postings, August 2022 to August 2026 — 43 source-cited records. Observed postings rather than a market census, weighted to the US and UK, with no individually verified postings between Q3 2022 and Q3 2023.

8
Employment aggregates

CSET Georgetown (Lightcast) for US posting volume; Axial Search, PwC, IAPP and Draup for salary, role-count and skills-growth aggregates. Federal Chief AI Officer appointments follow the 2023 Executive Order and the 2024 OMB memoranda.

9
Private capital

AI Risk & Resilience Transaction Dataset, August 2022 to August 2026 — 449 source-linked funding rounds and acquisitions across five categories, $28.5B disclosed. Deal counts are the reliable series; disclosed value is concentrated enough that one transaction can define a quarter.

10
Public procurement

Government Contract Awards — Resilience & AI Governance, August 2022 to August 2026 — 737 awards across nine buyer countries, matched to eleven concepts. Weighted to the UK and EU, which hold 521 of the 737. Values arrive in five currencies and are never summed across them. The year series covers the 726 dated awards.

11
Transaction and award shares

Both share series count transactions, not value. Partial years at both endpoints: 2022 covers two quarters, 2026 three.

12
Named frameworks and standards

NIST AI RMF 1.0 (NIST AI 100-1); ISO/IEC 42001:2023; ISO 22301:2019; SR 11-7 (Federal Reserve SR Letter 11-7, model risk management).

Sources and noteseudai.

Appendix

Data and definitions.

Highest-volume terms in the set

TermAvg/moYoY
dora · standard1,747,500−17%
incident command system450,000−13%
wargaming290,250−16%
bc dr278,042+37%
iso 27001 · standard243,917−18%
soar194,3330%
psim161,333+12%
ai testing146,000+57%
disaster management127,542−29%
endpoint detection and response130,833−2%

How the clusters were built

Every term carries one of six concept families, assigned by term rather than inferred intent.

AI governance and security (251 terms). Governance, risk, readiness, compliance, literacy, assurance, agent security and the tooling variants of each.

The established composite (818 terms). Cybersecurity (336), resilience and crisis (300) and risk and compliance (182) — third-party risk, incident response, cyber resilience, business continuity, scenario testing, crisis management, operational resilience, physical security, GRC and audit.

Learning loops (67 terms) and other or sector-specific (485 terms) sit outside both clusters. The loop family is read separately in the chapter on the pattern behind the shift.

Three levels, three bases. Cluster totals and term-level values throughout the report are computed on the full 1,621-term set, September 2022 to August 2026. Area totals in chapter 5 and the group aggregates in Figures 5, 20 and 21 are carried from the original area and group definitions, which cover 723 and 199 terms respectively and were not rebuilt on the wider pull. Limits overleaf.

Appendix · Data and definitionseudai.

Appendix

Limits worth stating.

  • Keyword Planner reports in fixed buckets: 59 distinct monthly values across the 1,256 terms carrying volume. 365 terms stayed below the reporting threshold throughout.
  • Brand names and named standards are excluded from cluster totals. They still appear in the tables, marked.
  • Term selection sensitivity. Three successive pulls of 509, 1,062 and 1,621 terms return AI-cluster growth of +286%, +286% and +302%. The established decline reads −5%, −11% and −13%, and its year-on-year figure moves further, from −16% to −29%. Growth is a property of the market. Level is a property of the term list, because the terms added at each stage were overwhelmingly established-side, including several large regulatory acronyms past their deadlines. The multiple moves most of all: 3.1× on the curated clusters, 8.3× on the six families. Read the direction as settled and the magnitude as conditional.
  • One term carries roughly a third of the AI cluster. “AI testing” alone is 146,000 searches a month and is ambiguous between testing AI systems and using AI to test software. The +302% cluster growth is real; a third of the absolute volume belongs to a term nobody can own.
  • Chapter 5 does not cover the whole set. The eight areas sum to 723 terms. The remainder sat in what had been a residual bucket labelled Cybersecurity: enterprise risk governance, insurance and risk transfer, named regulators and regimes, and vendor brand names. Real vocabulary, and several of them large, but not the areas this chapter reads — and leaving them inside a page titled Cybersecurity misstated that area by a factor of 8 on term count. They are excluded from chapter 5 rather than reassigned, because reassigning them properly needs a taxonomy this dataset was not built for. The cluster figures elsewhere still include them.
  • Search is not spend. A declining term can sit above healthy revenue.
  • Term selection reflects a point of view about which words matter, not an exhaustive market map. We work on positioning and go-to-market in this market, which shapes what we find interesting. It does not shape the volumes.
  • Volumes are worldwide. Certificate counts: ISO Survey 2024, ISO/CASCO.

Eudai is a marketing studio for security, risk and resilience companies — positioning, category design and go-to-market. eudai.ai

Appendix · Limitseudai.

About Eudai

If your category is being renamed around you, that is a positioning and discovery problem before it is a product one.

Eudai helps security, risk, and resilience companies—and risk and security teams—develop the language that makes their work easier to find, trust, and act on.

We work across category and positioning, go-to-market, and fractional leadership. Explore selected work, analyst recognition, and client awards at eudai.ai.

About Eudaieudai.

eudai.

Marketing for cybersecurity, AI and resilience companies.

eudai.ai
[email protected]

Resilience 2030 · September 2026 
Back