The current image has no alternative text. The file name is: technology.jpg

As artificial intelligence becomes more integrated into the daily operations of companies, a new form of cybersecurity risk is emerging. Companies are giving AI systems too much access to their internal systems without understanding where their sensitive data is located.

According to the Thales 2026 Data Threat Report, only 34 percent of companies have full visibility of their data. This is a huge problem as companies are giving AI systems more autonomy within their internal systems. Executives from companies in the automotive, energy, finance, and retail sectors cited the speed of AI adoption as the biggest security issue. As companies are integrating AI into their software development, analytics, and customer service, they are giving the AI systems too much access to their data. In some cases, the access restrictions for the AI systems are less strict than those for human employees. This has led 61 percent of companies to cite AI as their biggest concern for data security.

This report comes at a time when there is a lot of public discussion about the impact of AI on the economy and society. Market volatility has been caused by comments from analysts and company executives about how advanced AI could affect the economy and the value of companies. While some economists have said that the worst predictions about AI are overstated, market volatility has continued, especially in the technology industry.

The research from Thales indicates that the more pressing problem may not come from malicious superintelligence, but from the increasing normalization of AI as a trusted insider. As these systems mature from external productivity agents to deeply integrated digital assistants, they retain broad credentials throughout cloud infrastructure, databases, and software applications.

Sébastien Cano, senior vice president of cybersecurity products at Thales, highlighted that insider threats have expanded to include automated systems. He explained that these systems can amplify weak governance structures at speeds that no human could ever hope to keep up with. When identity management, access controls, or encryption policies are weak, AI systems can inadvertently accelerate vulnerabilities throughout an entire enterprise.

The survey, which collected data from over 3,000 IT and cybersecurity professionals at companies with annual revenues above $100 million, found other vulnerabilities as well. Only 39 percent of companies reported being able to fully classify their data, and nearly half of sensitive cloud data remains unencrypted. Because AI applications are constantly ingesting and processing data throughout cloud and SaaS infrastructure, implementing least privilege access has become increasingly difficult. If machine credentials are compromised, the extent of possible damage could be significant.

Cybercriminals are already taking advantage of these vulnerabilities. Credential phishing has become the most prevalent method in cloud breaches, with 67 percent of affected companies pointing to credential phishing as a contributing factor. At the same time, half of the surveyed companies pointed to secrets management, including API key and machine identity management, as a top application security concern.

Threats from outside are also undergoing changes. Almost 60 percent of the respondents have witnessed cases of deepfakes created by AI, and almost half of them have been victims of reputational damage due to misinformation or impersonation attacks. Human mistakes are still a contributing factor in 28 percent of the breaches, and automation can even multiply the effects of small errors.

However, with the growing threats, there is still a lack of investment in specific security for AI. Only 30 percent of the companies surveyed have budgets for AI security. More than half of the companies are still using traditional security models that were specifically designed to handle human users and perimeter security.

According to Eric Hanselman, the chief analyst of S&P Global 451 Research, companies need to reassess basic security models. As AI becomes a part of the core business, basic data visibility, encryption, and identity governance will no longer be an optional feature. Companies that want to leverage the power of AI without risking catastrophic breaches need to keep up with the pace of the technology.

0
0
Your Cart
Empty CartYour cart is empty
Secure Checkout
Fast Shipping
Easy Returns

Register Your brand with The Diamond Magazine!

Get your business, you brand in front of The Diamond Magazine’s global audience.

Register today,  promote your business, your, and reach more potential clients.

Register Your brand with The Diamond Magazine!

Get your business, you brand in front of The Diamond Magazine’s global audience.

Register today,  promote your business, your, and reach more potential clients.

THE DIAMOND MAGAZINE NEWS

Our fineststories and strategic insights shaping business, leadership, and global influence.

By signing up, you agree to receive The Diamond Magazine newsletter and other updates about The Diamond and its affiliated offerings. You also agree to our [Terms of Service] and acknowledge our [Privacy Policy].