Skip to main content
Emerging ThreatsMalware & Ransomware

Cybersecurity Leaders Warn of AI Trust Gap

Dimly lit industrial control room with unoccupied workstation and blurred laptop screen.

“22% of organizations experienced a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms.”

22% of organizations reported AI-enabled attacks in the past year

That figure, drawn from a report by Onapsis, is stark: more than one in five organizations said attackers used artificial intelligence as part of a successful security incident against critical business platforms within the previous twelve months. The statistic anchors the report’s broader finding that AI is no longer a hypothetical augment to cybercrime but a present-day tool adversaries have already exploited.

Rapid AI adoption in ERP despite widespread distrust

At the same time organizations report real-world AI-enabled compromises, adoption inside enterprise resource planning (ERP) systems is accelerating. Onapsis found 58% of respondents said their organizations began using AI-based applications or agents that touch the ERP in the last six months. Moreover, 86% said they have already integrated, or will shortly integrate, AI directly into their ERP code.

The juxtaposition is stark: a sizable share of firms are moving AI into the most sensitive transactional systems even as a majority of senior cybersecurity leaders express limited confidence in AI’s ability to secure business-critical data.

Security and IT lead resistance; compliance and confidence top concerns

Resistance inside organizations is tangible and specific. Nearly 57% of respondents reported that at least one business unit objected to implementing AI within the ERP environment. The security team was the most resistant group, cited by 41.4% of respondents, followed by IT—responsible for the ERP—at 20.7%.

When asked why business units pushed back, respondents named two dominant worries: lack of confidence in AI security (75%) and compliance risk (71.6%). Those answers place technical skepticism and regulatory exposure at the center of organizational debate over AI inside ERP systems.

Low confidence in detection and a short list of trust-builders

On detection capability, 68.6% of respondents said they were only “somewhat” or “not very” confident that their current defenses could detect an AI-based attack. Nearly the same share—70.6%—reported having only some, or no trust at all, in AI applications and agents to secure their organization’s most business-critical data.

When respondents were asked what would build trust over the next 12 months, the top three technical and governance measures were:

  • Robust access management controls — 61.8%
  • Strong personal data protections — 45.8%
  • Sandboxing or digital twin environments — 36.8%

Those preferences point to a demand for containment, accountability, and tighter control over what AI systems can access and do inside ERP environments.

What this means for security teams, procurement leaders, and adversaries

  • Security teams: The survey shows security personnel are the most likely internal holdouts on ERP AI—41.4% objected—reflecting their dual role as defenders and internal skeptics. They will likely press for the access controls, data protections, and sandboxing that respondents identified as trust prerequisites.
  • Procurement and IT leaders: IT teams, cited by 20.7% as objectors despite owning ERP operations, face a paradox: 86% of organizations plan to integrate AI into ERP code even while many in IT and security doubt AI’s reliability. Procurement decisions will therefore need to reconcile speed of deployment with the controls respondents say are required.
  • Adversaries and threat actors: The report’s 22% attack rate and the low confidence in detection (68.6%) suggest attackers already view AI as a force multiplier and that many organizations feel unprepared to spot AI-enabled intrusions.

Onapsis packages these findings alongside practical prompts—“ON DEMAND” briefings that argue for a decision layer to turn alerts into action and for governance, validation, and evidence-traceability controls where AI is used. Those recommendations mirror respondents’ explicit calls for concrete controls rather than blanket assurances.

Conclusion: The data create a clear, uneasy picture. Organizations are moving quickly to embed AI into transactional systems at scale, even as a majority of senior security leaders say they do not trust AI to protect their most critical data and many doubt their defenses could detect AI-enabled attacks. The immediate question — and the one the report’s respondents implicitly pose for leaders who will govern these deployments — is whether the technical and governance measures named as prerequisites will be implemented before AI is permitted to operate unchecked inside ERP code.

Original story