AI adoption now prompts 41% of enterprises to increase their investments in information security. Other key drivers cited include the rising costs associated with IT security breaches, migration to cloud infrastructure, and recently experienced security incidents. These insights stem from the recent global study conducted by the Kaspersky’s Internal Research Center.
The growing threat of AI vulnerabilities
The survey conducted by Kaspersky's internal research center[1] revealed that 19% of enterprises consider AI vulnerabilities among the most dangerous threats facing their organizations today, ranking behind only risks such phishing (22%) and mass malware attacks (20%). This highlights the growing recognition of AI-related threats and, among other factors, explains the increase in cybersecurity expenditures. This heightened awareness is especially pronounced within the Financial, IT, and Government sectors, which are increasingly targeted due to the critical nature of their digital assets.
Employee-driven risky behaviors
External threats are not the only reasons why companies perceive AI as a serious risk. An equally significant danger comes from employees who, often in a mass and uncontrolled manner, use third-party AI tools such as ChatGPT and DeepSeek for work tasks, a phenomenon known as “Shadow AI”. Indeed, 31% of respondents identified this behavior as a common risk factor, emphasizing the urgent need for careful management and regulation of external AI solutions to mitigate potential data leaks and security breaches.
Moreover, it appears that many companies do not fully monitor or control how their staff use such tools. According to the survey, 59% of organizations permit the use of third-party AI tools under certain restrictions such as prohibiting the uploading of company names or internal documents, while 23% allow unrestricted access but provide guidance and training to promote secure practices.
Strategic AI development plans
The pace of AI integration across organizations remains rapid, despite associated risks. An impressive 81% of companies are actively exploring or deploying internal AI tools powered by Large Language Models, while 18% have already integrated these technologies into their workflows.
For organizations that have adopted their own internal AI solutions, the primary drivers are improved process efficiency (59%), a reduction in human error (59%), and enhanced quality of client deliverables (59%). These motivations underscore a strong organizational commitment to leveraging AI as a means to gain a competitive edge and achieve operational excellence.
"As organizations actively adopt AI to accelerate business processes and reduce routine workloads, security risks such as AI vulnerabilities and Shadow AI also rise. The most effective protection strategy is to leverage comprehensive cybersecurity solutions like Kaspersky Next, which already incorporate advanced AI capabilities. This approach can significantly reduce costs by preventing breaches and streamlining security management, enhancing operational resilience through faster containment and impact reduction. It also improves efficiency without increasing headcount and optimizes security investment by consolidating tools," comments Vladislav Tushkanov, Group Manager at Kaspersky AI Technology Research Center.
To protect companies against emerging AI-related threats, Kaspersky recommends:
- Applying all-encompassing solutions from the Kaspersky Next product line to provide real-time protection, threat visibility, investigation and response capabilities of EDR and XDR. Its AI-driven capabilities are used to automate and optimize security processes, helping teams operate more efficiently and reduce manual workload and skill gaps. Generative AI models within the platform enable rapidly convert collected data into structured, actionable information for security teams and decision-makers.
- Equiping your cybersecurity team with in-depth visibility into cyber threats targeting your organization. The latest Kaspersky Threat Intelligence delivers rich, contextual insights throughout the entire incident management cycle, enabling timely identification of cyber risks. Machine learning and generative AI support malware classification, analysis of large-scale threat data, and AI-generated summaries of indicators of compromise, enabling security teams to make faster and more informed decisions.
Enterprises can also explore how advanced AI features can strengthen their cybersecurity through Kaspersky expert guidance that is tailored to their specific environment.
[1] The research surveyed 1,800 IT and cybersecurity decision-makers and specialists, representing organizations across 18 countries and multiple industries, including IT, manufacturing, finance, retail and wholesale etc.