Recent insights from PwC highlight a pressing concern among cybersecurity leaders regarding the growing threats targeting artificial intelligence (AI) systems. According to the consulting firm, this represents an area where stakeholders feel least prepared, with significant gaps in skills, accountability, and data protection contributing to the problem. The findings stem from PwC’s comprehensive survey involving 3,934 business and technology leaders across 71 countries, reported in their 2027 Global Digital Trust Insights document released on October 1.
A significant portion of the participants—52%—identified adversarial AI attacks as the most critical cyber preparedness gap. This perspective underscores the increasing challenges organizations face in defending against sophisticated cyber threats that specifically target AI frameworks. Compounding these difficulties are governance issues; PwC’s report reveals a lack of consensus concerning the ownership of AI risk management responsibilities. According to the survey, opinions were split on whether the Chief Information Officer (CIO), Chief Technology Officer (CTO), or technology functions should assume accountability (29%); whether a dedicated AI leader should take on this role (26%); or whether accountability belongs to the Chief Information Security Officer (CISO) or the cybersecurity function (17%). Notably, approximately a third (33%) of participating CEOs and security and risk leaders reported having already appointed a dedicated AI position, such as a chief AI officer, to navigate these challenges.
The report also shed light on the proliferating risk related to data—an issue that directly impacts AI risk management. Approximately half of the responding organizations acknowledged that they have yet to fully implement essential data classification (49%) and data loss prevention (48%) policies. This data inadequacy can exacerbate vulnerabilities within AI systems, making proactive measures critical.
Despite these challenges, optimism towards the future remains prevalent within the industry. An impressive 84% of security and finance leaders surveyed expect their budgets to increase, reflecting a rise of six percentage points compared to 2025. Over half (58%) indicated that AI has established itself as a top-five priority for cyber budgets, prioritizing responsible AI governance (42%), platform hardening (38%), and supply chain security (35%) as essential initiatives moving forward.
Moreover, organizations are exploring the implementation of AI in their cyber defenses. Key areas targeted for enhancement include threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%). As organizations increasingly recognize the potential of AI to bolster security measures, the role of technology is evolving, placing importance on the synergy between AI tools and human expertise.
Tonya Ugoretz, co-leader of PwC’s Cyber & Risk Innovation Institute, spoke to Infosecurity about the imperative for organizations to establish a strong foundational approach to address adversarial attacks. She emphasized, "Organizations should start with the fundamentals—understanding where sensitive data resides, controlling access, continuously testing and monitoring AI systems, and implementing clear processes for identifying and responding to incidents." Moreover, Ugoretz highlighted that technology alone cannot resolve these challenges. Clear accountability and oversight are also necessary, involving designated individuals who own decision-making processes, identify responsibilities when AI systems misbehave, and ensure adequate human intervention when necessary.
One of the most daunting challenges facing progress in AI security is the noticeable shortage of skilled professionals. More than two-fifths (44%) of Chief Information Security Officers (CISOs) pointed to workforce skills in AI oversight and governance as a top barrier to enhancing AI agent autonomy. This gap is significant; over half (55%) ranked the reliability of technology as a major obstacle to broader adoption of AI agents, according to PwC.
Interestingly, respondents view AI as part of the solution to this skills gap. More than half (53%) consider AI-enabled training vital to closing the skills shortage and retaining talent, alongside providing growth opportunities (59%) and fostering a robust cybersecurity culture (53%). In a related study by Swimlane, it was revealed that 62% of Security Operations Center (SOC) personnel believe AI has already contributed positively to their skill development.
As organizations navigate the complex terrain of AI security, the importance of addressing governance issues, filling skills gaps, and leveraging the potential of AI technologies becomes increasingly apparent. In facing the evolving challenges of cyber threats, businesses are urged not only to enhance their technology frameworks but also to cultivate a culture of accountability and continuous improvement within their cybersecurity practices.

