Organisations underprepared for cyber-threats from AI adoption
As artificial intelligence radically reshapes business, around 90% of organisations do not believe they are adequately prepared to secure their organisations against AI-centred cyber-attacks. Despite the rapid adoption of AI at many organisations, just one-fifth have even implemented policies and training for its use – leaving them highly exposed to hostile actors.
As the adoption of AI across the global economy reportedly accelerates, Accenture has surveyed 2,286 executives to examine their preparedness. Comprising of 80% chief information security officers and 20% chief information officers from $1 billion organisations in 24 industries across 17 countries in North and South America, Europe, Asia-Pacific, the Middle East and Africa, the results show that while most talk a good game, they are often neglecting key details of their transformations.
In particular, Accenture found that many businesses were overlooking cyber-security issues relating to AI adoption. Despite the rapid growth of AI enterprise adoption, only 22% of organisations were found to have implemented clear policies and training for the use of generative AI. Furthermore, very few maintain a comprehensive inventory of AI systems, which is crucial for managing supply chain risks. Meanwhile, only 25% of organisations had fully leveraged encryption methods and access controls to protect sensitive information.

"The rapid advancement of gen AI represents a profound paradigm shift in cybersecurity, bringing unique challenges and opportunities. By designing AI systems with security at their core and continuously monitoring and updating them, organizations can stay ahead of the most critical threats,” said Daniel Kendzior, global Data and AI Security Lead at Accenture. “Business resilience requires readiness to quickly response to disruptive forces and confidence in your organization’s ability to act effectively.”
Further highlighting a critical gap between ambition and readiness, the research reveals widespread cybersecurity immaturity across regions. Only 14% of North American and 11% of European organisations have mature postures. In Latin America, 77% lack basic strategies and capabilities, while 71% of Asia-Pacific organisations remain in the “Exposed Zone,” facing serious operational and financial risk. And while the situation improved from that marginally in Europe, 60% of organisations being “Exposed” to AI-related cyber-risks is hardly a glowing commendation.
Key concerns
When asked to cite their biggest areas of concern looking ahead, European organisations were particularly worried about the training data being used for generative AI systems. A 76% portion said they were concerned that “threat actors” might “poison” the data – something echoed by the researchers amid growing threats of international hostilities.
"Rising geopolitical tensions, economic volatility and increasingly complex operational environments, coupled with AI-augmented attacks, are leaving organizations more vulnerable to cyber risks. This report serves as a wake-up call that cybersecurity can no longer be an afterthought. It must be embedded by design into every AI-driven initiative,” said Paolo Dal Cin, global lead, Accenture Security. “Taking this proactive approach will help ensure a competitive edge, strengthen customer loyalty and turn cybersecurity into a business enabler.”
Not all of the threats were quite so melodramatic, though. While hostile actors could conceivably insert fake information into a generative AI’s training data, the technology has already proven quite capable of ‘hallucinating’ on its own terms – having often been fed information indiscriminately, or sans context. But it also presents plenty of other risks, which are much more run-of-the-mill.
Previous research by scientists from the University of North Carolina, Chapel Hill, has explored how difficult it is to remove sensitive data from large language models (LLMs) such as OpenAI’s ChatGPT and Google’s Bard. According to the researchers’ paper, the task of “deleting” information from LLMs is possible, but it is equally as difficult to verify the information has been removed as it is to actually remove it. This poses a huge risk to firms built around sensitive data, which plumb AI into their organisations – yet only 17% of respondents in Accenture’s poll had considered this.
