Skip to content

Security1 publisher2 min readPublished

Just over half of PwC's 3,934 respondents call attacks on AI their biggest cyber gap

PwC surveyed 3,934 leaders and found 52% rank attacks on AI systems as their biggest cyber preparedness gap. Only 17% place AI risk with the CISO, so in most of the sample the security function does not own the threat it feels least ready for.

The Watch · Security desk

Illustration accompanying Just over half of PwC's 3,934 respondents call attacks on AI their biggest cyber gap

What happened

  • The largest share of respondents, 29%, put AI risk with the CIO, CTO or technology function, and PwC says no single ownership model has emerged.
  • Budgets are expected to grow, with 84% of security and finance bosses forecasting an increase, six percentage points above the 2025 figure.
  • Among CISOs, 44% named AI oversight and governance skills as a top barrier to giving AI agents more autonomy.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure In the 83% of responses that did not name the CISO, an attack on an AI system puts the security team in charge of containing an asset another executive is accountable for.
  • constraint Where data is not fully classified, security teams have no labels to enforce when limiting what an AI tool may read or send out.
  • decision With AI a top-five cyber budget priority for 58%, organisations have to decide which executive controls that spending while formal ownership of AI risk is still split.

PwC, a consulting firm, collected the responses in 71 countries and published the report on October 1 [1]. The survey measures how ready respondents feel [2]. The published summary does not include incident counts or a definition of an adversarial AI attack. Its specific figures are about who owns AI risk and where the money is going [3][10].

The three ownership models PwC reported add up to 72% of responses [1]. Take out the CISO share and 83% of respondents gave an answer other than the CISO or the cyber function when asked who is accountable for AI risk [2].

Hiring an AI executive has not settled who owns the risk [3]. A third of CEOs and security and risk leaders said they have appointed a dedicated AI role such as a chief AI officer [6]. A smaller 26% of respondents put AI risk with a dedicated AI leader or function [4]. PwC reports those figures for different respondent groups, so one cannot be subtracted from the other [4][6].

In my view, data classification and data loss prevention are the two controls most security teams already run for deciding what an AI tool may read and what it may send out. PwC links rising data risk to AI risk [8]. By its figures, 51% of organisations have not fully implemented classification and 52% have not fully implemented DLP [3].

Fewer respondents are working on hardening than are worried about attack [2][11]. Platform hardening is a top AI priority for 38% [11], 14 points below the share that called attacks on AI their biggest gap [4]. Responsible AI governance leads that list at 42%, with supply chain security third at 35% [11]. Interest in AI as a defensive tool runs higher: 50% want it for threat detection and alerting, 43% for fraud detection and 42% for phishing detection and response [12].

Agents face a second limit beyond skills [13]. Some 55% of respondents said the reliability of the technology is preventing broader adoption of agents [14].

What to watch

  • Whether PwC's full report breaks out the 28% of ownership answers that fall outside the three models Infosecurity reported.
  • Whether the 17% CISO share of AI risk ownership moves in PwC's next Digital Trust Insights edition.
  • Disclosed incidents involving attacks on production AI systems, to set against the self-reported preparedness gap.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories