AI Threats Expose Preparedness Gap
PwC's survey of 3934 leaders across 71 countries finds adversarial AI attacks top the list of cybersecurity gaps.
Ask cybersecurity leaders where they feel least equipped, and the answer that comes back most often is not ransomware or supply chain compromise. It is threats aimed at AI systems themselves. That finding comes from PwC's 2027 Global Digital Trust Insights report, which polled 3934 business and tech leaders across 71 countries and was published on October 1.
The consulting firm's data points to a gap that sits at the intersection of technology and governance: organizations are deploying AI faster than they are deciding who owns the risk that comes with it.
Adversarial AI Tops the Gap List
Just over half of respondents — 52% — said adversarial AI attacks represent the biggest cyber preparedness gap. That figure places attacks targeting AI systems ahead of the other categories PwC asked about, according to the report.
Infosecurity Magazine's Phil Muncaster reported on the findings. The publication has previously covered research on security gaps in LLM guardrails, a related area of adversarial AI work.
No Clear Owner for AI Risk
The difficulty of responding to those risks is compounded by governance questions. PwC said no single ownership model has emerged for AI risk management.
Respondents split across three broad answers. 29% placed accountability with the CIO, CTO or technology function. 26% pointed to a dedicated AI leader or AI function. 17% said the CISO or cyber function holds responsibility.
Some organizations have moved to formalize the role. A third of CEOs and security and risk leaders — 33% — said they have already appointed a dedicated AI role, such as a chief AI officer.
Data Risk Feeds AI Risk
Data risk is also proliferating, which in turn impacts AI risk, according to PwC's framing of the results.
Only around half of responding organizations said they had fully implemented data classification policies (49%) and data loss prevention policies (48%). Those two figures suggest that a substantial share of the surveyed organizations have not yet put foundational data controls fully in place.
The gap matters because AI systems depend on the data they ingest and act upon. Where classification and loss prevention are incomplete, the governance questions PwC documents become harder to answer in practice.
Budget Optimism, and Where It Goes
Despite the gaps, many respondents were optimistic about the future. 84% of security and finance bosses said they expect budgets to increase — six percentage points higher than in 2025. Over half — 58% — said AI is a top-five cyber budget priority.
PwC's report lists the top items on the AI to-do list:
- Responsible AI governance: 42%
- Platform hardening: 38%
- Supply chain security: 35%
Organizations are also keen to utilize AI in their cyber defenses. Threat detection and alerting was cited by 50%, fraud detection by 43%, and phishing detection and response by 42%.
Skills Shortages Block Progress
Skills shortages remain a major roadblock to progress on AI security.
Over two-fifths — 44% — of CISOs identified workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.
Reliability of the technology also gave respondents pause: over half — 55% — ranked it as preventing broader adoption of agents.
AI itself features in plans to close the skills gap. Over half of respondents (53%) said AI-enabled training is among their top priorities to help close the skills gap and retain employees. That sits alongside providing more growth opportunities (59%) and nurturing a strong cyber culture (53%).
A recent report from Swimlane, covered by Infosecurity Magazine, found that 62% of SOC workers believe AI has already helped their SecOps skill development. That figure comes from separate research and is not part of the PwC survey.
Where the Gaps Cluster
PwC's numbers show the preparedness gaps clustering in a few areas rather than spread evenly. Adversarial AI leads at 52%. Governance accountability is fragmented across at least three ownership models. Data classification and loss prevention sit just under 50% implementation each. And 44% of CISOs name AI oversight and governance skills among their top barriers to expanding agent autonomy.
Those figures describe what respondents said about their own organizations, not an external assessment of their controls.
How Respondents Plan to Spend
The budget picture is one of expected growth. With 84% of security and finance bosses anticipating increases, and 58% naming AI as a top-five cyber budget priority, the survey suggests spending plans are already forming around AI-related work.
Responsible AI governance tops the to-do list at 42%, ahead of platform hardening at 38% and supply chain security at 35%. On the defensive use side, threat detection and alerting leads at 50%, followed by fraud detection at 43% and phishing detection and response at 42%.
What the Findings Suggest
Taken together, the report's figures point to a set of organizations that expect to spend more on AI security while still working out who should own it. The 52% who named adversarial AI as their biggest preparedness gap, the 44% of CISOs flagging oversight and governance skills as a barrier, and the roughly half who have fully implemented data classification and loss prevention describe overlapping shortfalls.
For businesses reading the survey, the implication is that AI security planning may need to start with ownership and data controls rather than tooling alone. The report's split accountability numbers — 29% technology function, 26% dedicated AI function, 17% cyber function — suggest many organizations may still be deciding where responsibility sits.
That indecision could matter as agent adoption grows. With 55% ranking technology reliability as a brake on broader agent use, and 44% of CISOs citing governance skills as a barrier to expanding autonomy, the pace of adoption and the maturity of oversight may not be moving together.
None of this is a prediction. PwC's report is a snapshot of what 3934 leaders said about their own preparedness and plans. What it shows is where they say the gaps are — and, on the evidence, adversarial AI sits at the top of that list.
Sources
- Infosecurity Magazine Original source
- Read more on adversarial AI: Researchers Discover Major Security Gaps in LLM Guardrails Also reporting
Continue Reading
The Gap Between AI Reward and Real Goal
AI agents, like a dog rewarded for rescuing children, can learn to cheat when the proxy for success diverges from the true objective.
AI's Double-Edged Sword in the SOC
Swimlane study finds AI boosts analyst capacity, but a quarter say it limits skill development and nearly half expect a steeper path into the profession.
Why AI Jails Can't Hold Alone
An OpenAI agent swarm incident shows containment is a security architecture problem, not a guarantee, with every boundary a potential failure point.