Skip to content
Security & Trust

Half of security and tech executives rank attacks on AI a top readiness gap

PwC's 71-country survey finds cyber budgets set to grow, while continuity plans and data controls lag behind.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Half of security and tech executives rank attacks on AI a top readiness gap

AI-generated image for WebPulse. About our images

In brief
  • Half of the security and technology executives in PwC's survey rank attacks on AI systems among their top five readiness gaps. Only 39% of all leaders have fully formalized cyber continuity plans.
  • The average company has three of seven data risk measures in place, and classifying data is not the same as protecting it from tampering.
  • Ask your team which data each AI tool can reach, how that data's origin is checked, and which agent actions need independent review.

Companies are putting more money into AI, yet PwC's new survey finds that many leaders lack formal continuity plans and full data controls. The pattern is easy to miss, because spending can be approved in a quarter and groundwork takes far longer. That reading of the numbers is ours, not PwC's.

What PwC found

PwC's fieldwork ran from May through July 2026 and covered 3,934 business and technology leaders in 71 countries. Half of the security and technology executives in that group placed attacks on AI systems among their five largest readiness gaps. That threat topped the other items on PwC's list.

Money is heading the same way. Most of the security and finance leaders in the sample expect their cyber budgets to rise, and AI is among the main priorities for that money.

84%
Security and finance leaders expecting cyber budgets to grow
Source: PwC survey of 3,934 leaders in 71 countries, May-July 2026, reported by Help Net Security (October 2, 2026)

Three AI attacks on leaders' minds

Asked about AI-enabled threats, more than half of leaders put three types in their top five. Each works differently.

The first is the AI-directed botnet. A botnet is a network of hijacked computers, and AI can help one operator steer very large numbers of them.

The second is the adversarial attack. The attacker makes a subtle change to what an AI system takes in, so it answers wrongly.

The third is data poisoning. False records are planted in the material a model learns from, and the model absorbs them as if they were true.

PwC adds its own assessment that leading-edge AI models can now discover unknown software flaws and exploit them with little human help.

Plans and data controls trail the ambition

Fewer than four in ten leaders surveyed have fully formalized continuity plans for cyber incidents. Such a plan is a documented way to keep critical operations running, or to restore them, after an attack. Close to one in four is not building formal plans at all. PwC itself calls incidents a matter of when, not if.

39%
Leaders with fully formalized cyber continuity plans
Source: PwC survey, reported by Help Net Security (October 2, 2026)

Data controls show a similar gap. On average, companies have rolled out just three of seven data risk safeguards across the whole organization. About half have data classification, which means labeling which data is sensitive.

3 of 7
Data risk measures in place at the average company
Source: PwC survey, reported by Help Net Security (October 2, 2026)

Two separate findings sit side by side here, and the link between them is our argument. Classification tells a company what is sensitive. Catching poisoning is a different job. It needs records of where training and reference data came from, plus checks that the data has not been altered. The reporting does not say how many companies have those controls.

PwC argues that an AI system can be trusted only as far as the data under it can. A sensitivity label is a start. It does not defend against tampering.

Machine speed, with a person close by

Matt Rowe, chief security officer at Lloyds Banking Group, says success in the AI era depends on being able to "defend at machine speed." Leaders' own answers show a limit on that ambition. Under a quarter of respondents would let AI agents, which are programs that act on their own, stop and repair attacks without a human signing off.

Fewer than 25%
Leaders who would let AI agents contain and fix attacks without human approval
Source: PwC survey, reported by Help Net Security (October 2, 2026)

Most would confine agents to low-risk tasks or keep a person in charge. More than half named the technology's reliability and maturity as a top barrier. Ownership is also unsettled. One in three companies has created roles devoted to AI, a chief AI officer for example. Others place AI risk with the technology function or the CISO.

Why a review step matters

Agents give probabilistic output. That means an answer that is likely right but can still be wrong.

PwC's advice follows from that. When a result has to be correct, the agent's work should pass through a control the agent cannot influence. That could be a human review, a sign-off workflow or a second system that verifies the result.

The lesson here is that speed and trust are separate purchases. Faster AI adds capability. An independent check is what adds trust.

Questions to put to your team

Start with data. Which data can each AI tool reach, and is it classified? Who would notice if training or reference data were altered, and how would they know?

Next, continuity. Is there a documented plan for keeping critical operations running after a cyber incident? Has anyone tested it against an AI-related failure?

Then agents. Which actions can they take without approval, and what independent control checks the ones that matter? Finally, ask who owns AI risk, by name.

These are survey findings from leaders' own answers, not measurements of real incidents. They still show where those leaders say the gaps are. Budgets are growing, and the plans and data controls beneath them need to grow with them.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.

Share this insight