Skip to content

Executive Summary

Cybersecurity leaders report that threats targeting AI systems represent a current gap in addressing security concerns, alongside existing challenges in skills, accountability, and data protection. Adversarial AI attacks are cited as the largest cyber preparedness gap among business and tech leaders, with over half reporting this. Governance issues compound these risks, as no single ownership model has emerged for AI risk management, with opinions divided on where accountability should reside across different roles. Furthermore, data risk is increasing, impacting AI security; only about half of organizations have fully implemented necessary data classification and loss prevention policies. Despite these challenges, there is optimism regarding future investment, with a majority expecting budget increases and viewing AI integration in cyber defenses as a top priority. Areas of focus include responsible AI governance, platform hardening, supply chain security, and utilizing AI for specific defensive tasks like threat detection. Skills shortages persist, particularly regarding AI oversight, though there is a recognized appetite for AI-enabled training to address these gaps.

Facts Only

* Adversarial AI attacks represent the biggest cyber preparedness gap for over half of polled business and tech leaders.
* No single ownership model has emerged for AI risk management among respondents.
* Accountability for AI risk management is split across roles: CIO/CTO/technology function (29%), dedicated AI leader or function (26%), CISO/cyber function (17%).
* Thirty-three percent of CEOs and security/risk leaders have appointed a dedicated AI role, such as a Chief AI Officer.
* Only around half of responding organizations have fully implemented data classification and loss prevention policies.
* Eighty-four percent of security and finance bosses expect budgets to increase.
* Over half of respondents expect AI to be a top-five cyber budget priority.
* Responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) are top priorities for AI-related action.
* Organizations are interested in using AI for threat detection, fraud detection, and phishing detection/response.
* Over two-fifths of CISOs identified workforce skills in AI oversight and governance as a top barrier to increasing AI agent autonomy.
* Over half of respondents ranked the reliability of technology as preventing broader adoption of agents.
* Over half of respondents claimed AI-enabled training is a top priority for closing skills gaps and retaining employees.
* Sixty-two percent of SOC workers believe AI has already aided their SecOps skill development.

Full Take

The narrative highlights a significant divergence between stated aspirations regarding AI integration and the practical realities of establishing necessary control structures. The primary tension exists between the recognized potential of AI for cyber defense—evidenced by the strong interest in AI-enabled threat detection and fraud response—and the palpable gaps in governance, skills, and data hygiene required to manage these systems safely. The fragmentation in ownership models for AI risk management suggests a systemic difficulty in assigning clear accountability when autonomous systems are introduced, which risks creating diffusion of responsibility rather than centralized control. Furthermore, the focus on skills as a bottleneck underscores that technological adoption is fundamentally constrained by human capital limitations; relying on AI-enabled training as a solution acknowledges that the tools themselves cannot solve the inherent organizational and cognitive challenges. This creates an implicit tension: the drive for rapid AI deployment clashes with the slow, complex process of establishing robust, multi-layered governance and skilled oversight necessary for true digital trust. The pattern suggests that the focus remains heavily on tactical implementation (tools for defense) while underinvesting in the strategic, foundational elements of systemic risk management (accountability and skills). The implication is that without reconciling the functional roles of responsibility with the technological advancements, organizations will continue to face an unstable state where innovation proceeds faster than institutional maturity. Bridge questions include: If accountability models remain fragmented, what specific organizational or legal structures are most effective at allocating liability for AI-driven security failures? How can investment in AI training be decoupled from mere retention metrics to ensure genuine skill acquisition relevant to systemic governance? What long-term consequences arise if the perceived reliability of agents is prioritized over the deployment timeline?

From the original · InfoSecurity Magazine

Threats targeting AI systems is the area that cybersecurity leaders currently feel last able to address, with skills, accountability and data protection gaps also looming large, according to PwC. The consulting giant polled 3934 business and tech leaders across 71 countries for its 2027 Global Digital Trust Insights report, published on October 1.
Read the full story at infosecurity-magazine.com

Sentinel — Human

Confidence

The text appears to be a well-structured summary of survey results, exhibiting the dense citation style typical of industry reporting rather than purely generative writing.

Signals Detected
low severity: Moderate sentence length variance; uses direct data integration rather than purely expository flow.
low severity: Flow is logical, transitioning smoothly between identified gaps (threats, governance, data risk, skills) and potential solutions.
low severity: Directly quotes or cites PwC data points without apparent verbatim matching; structure follows a typical report summary pattern.
low severity: Claims are attributed to a specific, identifiable source (PwC) and structured around survey findings, suggesting factual grounding rather than pure generation.
Human Indicators
Use of precise, nested statistics and segmented thematic arguments suggests synthesis from raw data collection.
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds | Huntaegis