Breaking
AI & MLDeveloping Story

AI Threats Expose Preparedness Gap

PwC's survey of 3934 leaders across 71 countries finds adversarial AI attacks top the list of cybersecurity gaps.

··2 hours ago·5 min read
robot and human hands reaching toward ai text
Photo by Igor Omilaev on Unsplash

Ask cybersecurity leaders where they feel least equipped, and the answer that comes back most often is not ransomware or supply chain compromise. It is threats aimed at AI systems themselves. That finding comes from PwC's 2027 Global Digital Trust Insights report, which polled 3934 business and tech leaders across 71 countries and was published on October 1.

The consulting firm's data points to a gap that sits at the intersection of technology and governance: organizations are deploying AI faster than they are deciding who owns the risk that comes with it.

Adversarial AI Tops the Gap List

Just over half of respondents — 52% — said adversarial AI attacks represent the biggest cyber preparedness gap. That figure places attacks targeting AI systems ahead of the other categories PwC asked about, according to the report.

Infosecurity Magazine's Phil Muncaster reported on the findings. The publication has previously covered research on security gaps in LLM guardrails, a related area of adversarial AI work.

No Clear Owner for AI Risk

The difficulty of responding to those risks is compounded by governance questions. PwC said no single ownership model has emerged for AI risk management.

Respondents split across three broad answers. 29% placed accountability with the CIO, CTO or technology function. 26% pointed to a dedicated AI leader or AI function. 17% said the CISO or cyber function holds responsibility.

Some organizations have moved to formalize the role. A third of CEOs and security and risk leaders — 33% — said they have already appointed a dedicated AI role, such as a chief AI officer.

Data Risk Feeds AI Risk

Data risk is also proliferating, which in turn impacts AI risk, according to PwC's framing of the results.

Only around half of responding organizations said they had fully implemented data classification policies (49%) and data loss prevention policies (48%). Those two figures suggest that a substantial share of the surveyed organizations have not yet put foundational data controls fully in place.

The gap matters because AI systems depend on the data they ingest and act upon. Where classification and loss prevention are incomplete, the governance questions PwC documents become harder to answer in practice.

Budget Optimism, and Where It Goes

Despite the gaps, many respondents were optimistic about the future. 84% of security and finance bosses said they expect budgets to increase — six percentage points higher than in 2025. Over half — 58% — said AI is a top-five cyber budget priority.

PwC's report lists the top items on the AI to-do list:

  • Responsible AI governance: 42%
  • Platform hardening: 38%
  • Supply chain security: 35%

Organizations are also keen to utilize AI in their cyber defenses. Threat detection and alerting was cited by 50%, fraud detection by 43%, and phishing detection and response by 42%.

Skills Shortages Block Progress

Skills shortages remain a major roadblock to progress on AI security.

Over two-fifths — 44% — of CISOs identified workforce skills in AI oversight and governance as one of their top barriers to increasing AI agent autonomy.

Reliability of the technology also gave respondents pause: over half — 55% — ranked it as preventing broader adoption of agents.

AI itself features in plans to close the skills gap. Over half of respondents (53%) said AI-enabled training is among their top priorities to help close the skills gap and retain employees. That sits alongside providing more growth opportunities (59%) and nurturing a strong cyber culture (53%).

A recent report from Swimlane, covered by Infosecurity Magazine, found that 62% of SOC workers believe AI has already helped their SecOps skill development. That figure comes from separate research and is not part of the PwC survey.

Where the Gaps Cluster

PwC's numbers show the preparedness gaps clustering in a few areas rather than spread evenly. Adversarial AI leads at 52%. Governance accountability is fragmented across at least three ownership models. Data classification and loss prevention sit just under 50% implementation each. And 44% of CISOs name AI oversight and governance skills among their top barriers to expanding agent autonomy.

Those figures describe what respondents said about their own organizations, not an external assessment of their controls.

How Respondents Plan to Spend

The budget picture is one of expected growth. With 84% of security and finance bosses anticipating increases, and 58% naming AI as a top-five cyber budget priority, the survey suggests spending plans are already forming around AI-related work.

Responsible AI governance tops the to-do list at 42%, ahead of platform hardening at 38% and supply chain security at 35%. On the defensive use side, threat detection and alerting leads at 50%, followed by fraud detection at 43% and phishing detection and response at 42%.

What the Findings Suggest

Taken together, the report's figures point to a set of organizations that expect to spend more on AI security while still working out who should own it. The 52% who named adversarial AI as their biggest preparedness gap, the 44% of CISOs flagging oversight and governance skills as a barrier, and the roughly half who have fully implemented data classification and loss prevention describe overlapping shortfalls.

For businesses reading the survey, the implication is that AI security planning may need to start with ownership and data controls rather than tooling alone. The report's split accountability numbers — 29% technology function, 26% dedicated AI function, 17% cyber function — suggest many organizations may still be deciding where responsibility sits.

That indecision could matter as agent adoption grows. With 55% ranking technology reliability as a brake on broader agent use, and 44% of CISOs citing governance skills as a barrier to expanding autonomy, the pace of adoption and the maturity of oversight may not be moving together.

None of this is a prediction. PwC's report is a snapshot of what 3934 leaders said about their own preparedness and plans. What it shows is where they say the gaps are — and, on the evidence, adversarial AI sits at the top of that list.

#ai security#pwc#cybersecurity preparedness#adversarial ai#ai governance#data risk

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories