AI · 8 October 2026
AI Security: PwC Report Flags Biggest Cyber Readiness Gap
PwC finds business leaders feel least prepared for attacks targeting AI systems, more than for traditional cybersecurity threats, as AI adoption outpaces investment in securing models and data.
What happened
A new report from PwC finds that, of all the cybersecurity threats facing organisations today, attacks targeting artificial intelligence systems are the ones business leaders feel least prepared to handle. The finding places AI-specific risk ahead of more familiar threat categories in terms of perceived readiness gaps, according to Finextra's coverage of the report.
PwC's analysis suggests that as organisations rush to deploy AI across operations, customer service and decision-making, many have not matched that pace with equivalent investment in securing the models, data pipelines and infrastructure underpinning these systems. The result is a widening gap between AI adoption and AI assurance.
Why it matters
This is fundamentally a digital transformation story: organisations are embedding AI into core processes — from fraud detection to customer interactions — faster than they are building the governance, monitoring and incident-response capabilities needed to protect those systems. An AI model that is compromised, manipulated or fed poisoned data doesn't just fail quietly; it can actively produce flawed outputs, biased decisions or leaked information at scale, often without obvious warning signs.
For leaders overseeing AI rollouts, the report is a signal to treat AI security as a first-class risk category rather than an extension of conventional IT security. That means specific attention to model integrity, data provenance and adversarial testing, not just the perimeter defences organisations have historically relied on.
The Renascence take
Most organisations still think about AI risk in terms of output quality — hallucinations, bias, accuracy — while treating security as someone else's problem. PwC's finding suggests the opposite blind spot may be more dangerous: leaders know AI is exposed, but haven't built the muscle to defend it.
The uncomfortable truth is that AI systems are being trusted with customer-facing decisions before they're trusted enough to be properly secured. A compromised AI isn't just a technical failure — it's a service failure, a trust failure, and potentially a regulatory one, all at once. Operators building AI into their service stack should insist on the same rigour they'd apply to a core banking system: red-teaming, monitoring and clear ownership of what happens when the model itself is the attack surface. Confidence in AI's capabilities means nothing if confidence in its integrity hasn't been earned first.
Sources
This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
FAQ
Questions we get on this topic
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.
