Executives Identify AI System Attacks as Their Biggest Security Blind Spot

A PwC survey of nearly 4,000 business leaders across 71 countries found that attacks on AI systems rank among the top preparedness gaps, with half of security executives naming them as a critical vulnerability despite increased AI investment. The most pressing threats include AI-directed botnets, adversarial attacks that manipulate AI perception, and data poisoning that corrupts training data, particularly as frontier AI models gain capabilities to discover and exploit unknown software flaws. Organizations are increasing cybersecurity budgets but only 39 percent have fully formalized continuity plans for cyber incidents.
The survey reveals a critical gap between investment and readiness in enterprise security. While companies are channeling significant resources into artificial intelligence tools, most have not established the foundational protections necessary to defend these systems. The three dominant threat categories—automated botnet deployment, perception manipulation through subtle data alterations, and corrupted training datasets—represent attack vectors that exploit the complexity and autonomy of modern AI systems.
The disconnect extends to incident response capacity. The majority of surveyed organizations lack documented procedures to maintain operations during or after cyberattacks, despite acknowledging that such incidents are inevitable rather than unlikely. This preparedness deficit becomes more acute as companies deploy autonomous software agents, which most leaders remain hesitant to authorize without human intervention due to concerns about reliability.
Organizations' vulnerability to AI-specific attacks could affect operational continuity across financial services, infrastructure, and healthcare sectors. The gap between AI deployment and security readiness may create financial and reputational risks for businesses, potentially impacting customer trust and regulatory compliance. Society could face cascading consequences if critical systems experience disruption from attacks on their AI components, suggesting the need for standardized security frameworks and maturity standards before further AI proliferation in essential services.