PwC: Attacks on AI systems top firms' readiness gaps

PwC: Attacks on AI systems top firms' readiness gaps

Organizations are spending more on AI, yet attacks aimed at AI systems are the threat they feel least prepared for, according to new research from PwC.

The consultancy surveyed 3,934 business and technology leaders across 71 countries between May and July 2026. Among the security and technology executives in that group, half placed attacks on AI systems in their top five preparedness gaps. No other threat on the list ranked higher.

PwC's view is that frontier AI models can now discover previously unknown software flaws and exploit them with little human involvement. This report adds to earlier findings from the same survey on how ready companies are for emerging threats.

Three AI-enabled threats stand out

When leaders were asked about AI-enabled attacks, more than half put three specific threats in their top five.

The first is botnets steered by AI at scale. The second is adversarial attacks, where an attacker makes small changes to the input an AI system receives so that it produces a wrong answer. The third is data poisoning, where misleading records are slipped into the data a model learns from.

All three target the AI system itself rather than the traditional network around it. This makes them harder to spot with tools built for older types of intrusions.

More money, few backup plans

Spending is moving up. Of the security and finance leaders surveyed, 84 percent expect their cyber budgets to grow, and AI is one of the main areas where that money is expected to go.

Planning for when things go wrong has not kept up. Only 39 percent of leaders have fully formalized continuity plans for cyber incidents. These are documented procedures for keeping critical operations running during an attack, or for bringing them back afterwards. Nearly a quarter of respondents are not working on formal plans at all.

PwC itself describes cyber incidents as a question of when, not if.

Weak foundations under AI tools

The survey also looked at how companies protect the data their AI tools depend on. Out of seven data risk measures, the average organization has rolled out three across the whole business.

Only around half have implemented data classification, the basic step of identifying which data is sensitive. PwC argues that AI can only be as trustworthy as the data beneath it. Its advice to companies deploying AI tools this year is to check what data those tools can reach and how well that data is protected.

Humans stay in the loop

On defense, most leaders are not ready to hand control to AI. Fewer than a quarter would let AI agents, meaning software that takes actions on its own, contain and remediate attacks without a human signing off. Most would restrict agents to low-risk actions or keep a person in charge.

More than half named the reliability and maturity of the technology as a top barrier.

"To be successful in the era of AI, we need to be able to defend at machine speed," says Matt Rowe, chief security officer at Lloyds Banking Group.

There is also no agreement on who should own AI risk. A third of companies have created dedicated AI roles, such as a chief AI officer. Others give the responsibility to the technology function or to the CISO (chief information security officer).

PwC points out that agents produce probabilistic output, which is likely to be correct but not guaranteed. Where a result must be right every time, the consultancy recommends routing the agent's work through a control the agent cannot influence. Examples include a review, an approval workflow, or a check carried out by another system.

Our Take

The findings point to a gap between ambition and groundwork. Companies are buying AI, but many have not classified their data, written continuity plans, or decided who is accountable for AI risk. That combination suggests a growing attack surface sitting on foundations that have not been checked.

The concern about AI-driven exploitation also fits a wider pattern. Microsoft has recently argued that attackers currently lead defenders in the early AI race, and the caution about autonomous agents looks reasonable given reports that AI agents keep data access after their tasks end.

For readers, the practical lesson is that data inventory and access control come before any AI rollout. It is worth watching whether the reluctance to let agents act alone fades as the technology matures, and whether formal ownership of AI risk becomes standard practice.