Skip to main content
Cybersecurity

Cybersecurity Leaders Struggle to Address AI Threats

Empty conference room with laptop and papers, overlooking cityscape.

Fifty-two percent of business and technology leaders told PwC that adversarial AI attacks are the single largest cyber-preparedness gap their organizations face — a striking majority in a survey of 3,934 leaders across 71 countries published in PwC’s 2027 Global Digital Trust Insights report on October 1.

Adversarial AI: the top preparedness gap

More than half of respondents (52%) ranked adversarial AI attacks ahead of other concerns, making threats to AI systems the area cybersecurity leaders feel least able to address. PwC’s global poll frames that finding against a broader set of preparedness shortfalls — skills, governance, and data protection all appear as simultaneous constraints that complicate defense against attacks targeting models, agents, and AI-driven processes.

Accountability: no single ownership model

PwC found no consensus on who should own AI risk. Respondents were split: 29% said the CIO, CTO or the technology function should hold accountability; 26% pointed to a dedicated AI leader or an AI function; and just 17% assigned primary responsibility to the CISO or cyber function. In parallel, a third (33%) of CEOs and security and risk leaders reported they have already appointed a dedicated AI role — for example, a chief AI officer — indicating organizations are experimenting with multiple governance structures as they scale AI.

Data controls lag where AI depends on them

The report ties AI risk back to a persistent data problem. Only about half of respondents said they have fully implemented basic protections: 49% reported full data classification and 48% reported full data loss prevention (DLP) policies in place. PwC frames those numbers as a material gap because weak data controls both enlarge the attack surface for adversarial manipulations and undercut trust in AI outputs derived from corporate datasets.

Skills shortages and the role of AI-enabled training

Workforce capability is another binding constraint. Over two-fifths of CISOs (44%) identified workforce skills in AI oversight and governance as a top barrier to increasing AI agent autonomy. More broadly, 55% of survey respondents said doubts about the technology’s reliability are preventing wider adoption of AI agents.

Still, respondents see AI itself as part of the remediation: 53% listed AI-enabled training among their top priorities to close the skills gap and retain employees. That sits alongside other workforce measures — 59% cited providing more growth opportunities and 53% highlighted nurturing a strong cyber culture. External corroboration comes from a recent Swimlane report cited by PwC: 62% of SOC workers said AI has already helped their SecOps skill development, suggesting practitioners are experiencing tangible training benefits even as leaders flag governance and oversight deficits.

Budgets, defensive AI use, and the to-do list

Despite the gaps, many security and finance leaders reported optimism about resourcing. Eighty-four percent expect cyber budgets to increase in the coming cycle — six percentage points higher than PwC recorded in 2025 — and 58% placed AI among their top-five cyber budget priorities. Where those funds will be directed is relatively specific: responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) topped the list of AI-related priorities.

  • Planned AI uses for defense include threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%).
  • These choices show organizations are balancing investments in governance and resilience with practical deployments that augment existing security operations.

How CISOs, CEOs, and SOC workers are responding

CISOs face a dual problem in PwC’s findings: they are both a proposed locus of accountability (17% said the CISO or cyber function should own AI risk) and a constituency reporting capability shortfalls (44% flagged skills in AI oversight and governance). CEOs and security and risk leaders are responding by creating dedicated AI roles — 33% have appointed such positions — suggesting organizational redesigns are underway. SOC workers appear to be gaining from AI’s operational side: 62% reported improved SecOps skills thanks to AI, aligning with leadership plans to deploy AI for detection, fraud control, and phishing response.

PwC’s numbers paint an organization-level balancing act: many firms expect budgets to rise and plan concrete uses for AI in cyber defense, yet a majority identify adversarial AI as their largest preparedness gap while basic data and governance controls remain incomplete.

Which governance model will coalesce as organizations move from pilots to production — and whether increased budgets will be directed sufficiently at the data, skills, and accountability gaps PwC identifies — are the concrete decisions the report leaves on the table for boardrooms and security teams alike.

https://www.infosecurity-magazine.com/news/mitigating-adversarial-ai-top/