A recent survey of nearly 4,000 business and technology leaders across 71 countries indicates that while companies are increasing their investment in artificial intelligence, they feel least prepared to defend against AI-specific threats. Among security and technology executives, half identified attacks targeting AI systems as a top-five gap in their preparedness, surpassing other threats.
The survey, conducted by PwC between May and July 2026, found that over half of the leaders concerned about AI-enabled attacks ranked three specific threats in their top five. These include large-scale botnets directed by AI, adversarial attacks that subtly manipulate AI system inputs to induce incorrect responses, and data poisoning, where misleading information is introduced into a model's training data. PwC's analysis suggests that advanced AI models are now capable of discovering and exploiting previously unknown software vulnerabilities with minimal human intervention.
Despite a projected increase in cybersecurity budgets, with 84 percent of security and finance leaders expecting growth and AI being a primary focus for these funds, preparedness for cyber incidents remains low. Only 39 percent of leaders have fully formalized continuity plans, which are documented procedures for maintaining or restoring critical operations after an attack. Nearly a quarter of organizations are not developing formal plans at all, even as cyber incidents are increasingly viewed as inevitable.
A significant concern highlighted by the survey is the quality and protection of data underpinning AI systems. The average company has implemented only three out of seven recommended data risk measures across their organization. Crucially, only about half have implemented data classification, a fundamental step for identifying sensitive data. The trustworthiness of AI is directly linked to the data it uses, prompting advice for organizations rolling out AI tools to assess the accessibility and protection of the data those tools can reach.
Regarding defensive applications of AI, fewer than a quarter of leaders expressed willingness to allow AI agents—autonomous software that takes actions—to contain and fix attacks without human oversight. Most prefer to restrict AI agents to low-risk actions or maintain human supervision. Over half of the respondents cited the reliability and maturity of AI technology as a primary barrier to its broader adoption in security operations. The need for machine-speed defense in the AI era was emphasized by one chief security officer.
The responsibility for AI-related risks within organizations is also fragmented. While a third of companies have established dedicated AI roles, such as a chief AI officer, others assign this responsibility to their technology function or the Chief Information Security Officer (CISO).
The probabilistic nature of AI agent outputs, meaning they are likely but not guaranteed to be correct, raises further concerns. PwC recommends that for outcomes requiring absolute accuracy, an AI agent's work should be subjected to an independent control mechanism, such as a human review, an approval workflow, or verification by another system, to ensure reliability.






