What Are the Top AI-Related Cybersecurity Threats to Organizations?

10 September 2025 - ID G00839104 - 8 min read
By Craig Porter
AI-related cyberthreats are a top concern for CISOs. These insights provide an overview of the top threats, their impact on the broader threat landscape, external drivers for cyber risk, and the critical challenges and solutions to mitigate these threats.

Quick Answer

What are the top AI-related cyberthreats faced by cybersecurity leaders?

CISOs must navigate both the controlled and uncontrolled proliferation of AI within organizations, as well as AI-enhanced cyberattacks that exploit expanded attack surfaces and outpace traditional defenses. Top threats include:
  • Limited AI literacy and guiding policy — A lack of AI expertise and clear policies leaves organizations unprepared to identify, monitor, or mitigate AI-driven risks, creating blind spots that attackers can exploit.
  • Shadow AI Employees using unsanctioned AI tools without oversight leads to potential data leaks, regulatory violations, and loss of control over sensitive information.
  • Data leakage via AI prompts Sensitive or proprietary data may be inadvertently shared with AI systems, especially through chat histories and file uploads, increasing the risk of data exposure to unauthorized parties or vendors.
  • Limited visibility of embedded AI features Organizations do not know what AI capabilities are active within third-party solutions, making it difficult to assess security risks or prevent unauthorized data processing.
  • Uncontrolled experimentation with custom-built applications, including agents Developing and deploying custom AI applications without proper security guardrails introduces new vulnerabilities and unpredictable behaviors, potentially leading to system compromise or data loss.
Externally, risks are driven by:
  • AI-enhanced phishing, deepfakes, and social engineering Attackers use AI to create convincing phishing emails, audio, or video deepfakes, increasing the likelihood of successful impersonation, fraud, or data breaches.
  • Fragmented regulations and compliance Varying and evolving AI regulations across regions complicate compliance, increasing the risk of legal penalties, operational disruptions, and reputational harm.
  • Attacks on AI infrastructure and prompts Adversaries target AI models and infrastructure with techniques like data poisoning, model theft, and prompt injection, which corrupt outputs, expose sensitive information, or introduce backdoors.
  • Third-party and supply chain vulnerabilities Reliance on external vendors and open-source AI components introduces risks from hidden vulnerabilities, lack of transparency, and insufficient contractual controls, potentially leading to unauthorized access or data leakage.

More Detail


CISOs must increase their focus on evolving AI-related threats. Over 60% of organizations report evidence or suspicion of unsanctioned use of GenAI tools.1 And 79% of CISOs report a noticeable increase in both the volume and sophistication of phishing and business email compromise (BEC) attacks attributed to AI-enhanced techniques, and one-third of organizations have already experienced deepfake incidents, with some reporting major incidents involving voice and video impersonation.1 These findings show that both internal and external AI-related threats are real today.

Top Internal AI-Related Cyberthreats

Limited AI Literacy and Guiding Policy

A major CISO challenge is limited AI literacy across organizations, which hampers effective policy and risk management. The shortage of AI expertise leaves organizations less prepared to monitor and mitigate risks. Notably, 60% of CISOs know which AI types are in use, compared to only 18% of other cybersecurity professionals, creating blind spots that make it difficult to deploy or understand AI-driven countermeasures.1
How to address: Implement targeted AI training and establish clear AI security policies. Training must cover understanding model behavior, recognizing attack vectors, interpreting AI decisions, managing AI alerts, and staying current on relevant regulations. For more insight, see A CISO’s Guide to AI Cyber Stewardship.

Shadow AI From Employees

The unsanctioned use of AI tools and applications by employees poses a growing risk. With the widespread availability of commercial AI services, organizations are losing oversight over how sensitive data is processed and shared, increasing the risk of data leaks, regulatory violations, and compromised business decisions. Nearly half of organizations suspect or have evidence of employees using embedded or custom-built GenAI tools without proper risk management, and many are also concerned about the use of unauthorized public AI services.
How to address: Conduct regular audits to detect unauthorized AI use and enforce approval processes. Embed cybersecurity into broader AI governance efforts, and embrace agile risk management processes, such as DevSecOps, rather than relying on traditional, waterfall risk assessments — which can’t scale at the speed of AI experimentation. For more insight, see CISOs Must Bring Shadow AI Into the Light.

Data Leakage and Grounding via AI Prompts

CISOs face significant risks of data leakage through AI prompts, as employees inadvertently share sensitive or proprietary information when interacting with generative AI tools. This risk is heightened by features like chat histories, file uploads, and provider logging, which can expose confidential data to unauthorized parties or external vendors. Incidents such as the Samsung source code leak underscore how easily data loss can occur via AI interactions.1
How to address: Deploy prompt monitoring tools, enforce restrictions on sensitive data input into AI systems, and implement data security posture management (DSPM) or TRiSM tools to discover, classify, and protect sensitive information across AI workflows. For more insight, see Generative AI Adoption: Top Security Threats, Risks and Mitigations.

Limited Visibility of Embedded AI Features

CISOs must navigate the limited visibility of embedded AI features, especially those integrated by third-party vendors. As organizations rapidly adopt solutions with built-in AI, many of these features are enabled and used without proper oversight or security assessment. This lack of transparency means cybersecurity teams may not know what data is being processed, how models are being trained, or if sensitive information is being exposed.
How to address: Maintain an AI feature inventory and require transparency from vendors. For more insight, see Use TRiSM to Manage AI Governance, Trust, Risk and Security.

Uncontrolled Experimentation With Custom-Built AI Applications, Including Agents

Uncontrolled experimentation with custom-built AI applications and agents creates serious risks for the organization. This can lead to new attack surfaces, like model context protocol (MCP) server vulnerabilities, where attackers manipulate or disrupt AI models. AI agents may also act unpredictably, increasing the risk of data exposure or system compromise in ways that are hard to detect or control.
How to address: Establish sandboxed environments and approval workflows for custom AI development. For more insight, see How to Secure Custom-Built AI Agents.

Top External AI Cyberthreats

AI-Enhanced Phishing, Deepfakes, and Social Engineering

AI-enhanced phishing and BEC attacks are a growing threat, with 37% of CISOs reporting deepfake incidents during video calls and 43% during audio calls.2 Attackers now use AI to automate, personalize, and scale their campaigns, making phishing emails and social engineering attempts more convincing and harder to detect. An estimated 12% of emails, including phishing, show signs of being written by large language models.3
These advances enable attackers to target high-value individuals, impersonate executives with deepfakes, and bypass traditional defenses, significantly increasing the risk of data breaches and financial loss for organizations.
How to address: Adopt modern email security platforms with AI/ML detection and augment awareness training to include emerging AI-driven threats. For more insight, see Overcome AI-Powered Attacks by Leveling Up Your Email Security Platform and How to Mitigate Deepfake Identity Impersonation Attacks.

Regulatory and Compliance Impacts

CISOs are increasingly threatened by the growing complexity and stringency of AI-related regulations, such as the EU AI Act and various U.S. state and local laws. These regulations introduce significant compliance burdens, including the need for rigorous risk assessments, detailed documentation, and continuous oversight of AI systems. Noncompliance can result in severe financial penalties and reputational damage. The fragmented nature of regulations across jurisdictions further complicates compliance efforts, increasing operational complexity and costs.
How to address: Collaborate with legal and compliance teams as part of an AI governance team to understand how to comply with current requirements and prepare for upcoming regulations. For more insight, see How Global AI Policy and Regulations Will Impact Your Enterprise and Simplifying AI Regulatory Compliance — A Unified Approach for a Fragmented Landscape.

Attacks on AI Infrastructure and Prompts

As AI systems become ubiquitous in business operations, adversaries are targeting underlying infrastructure, models, and supply chains. Twenty-nine percent of organizations report experiencing an attack on their enterprise GenAI application infrastructure in the last 12 months.1 These attacks can include data poisoning, which can corrupt training datasets and bias models, model theft and inversion to extract sensitive information, model evasion to bypass detection, and backdoor or Trojan attacks that embed hidden vulnerabilities.
How to address: Implement layered visibility and real-time monitoring across AI systems. These include AI governance tools for oversight, runtime inspection for anomaly detection, advanced observability dashboards, and shadow AI monitoring to catch unauthorized use. For more insight, see Hype Cycle for AI and Cybersecurity, 2025 and Use TRiSM to Manage AI Governance, Trust, Risk and Security.

Third-Party AI Risks

Third-party AI-specific risks arise from the reliance on vendor-supplied models and cloud-based AI services, which may contain hidden vulnerabilities or be updated without notice. The complexity of multicloud and SaaS environments makes it even harder to track where and how AI models operate, and whether third-party providers are following best practices for data privacy and security.
Unpatched or unsecured vendor models and services can create exploitable weaknesses, while insufficient contractual controls may limit an organization’s ability to enforce security requirements or receive timely incident notifications. Additionally, limited visibility into vendor operations can make it difficult to detect unauthorized data access or data leakage.
How to address: Implement AI-specific vendor risk assessments, establish AI-related contractual obligations, and continuously monitor the security posture and compliance of all third-party AI services integrated into operations. For more insight, see Getting Ready for the EU AI Act, Phase 3: Manage Third-Party Risks.

Supply Chain Vulnerabilities

Beyond direct third-party relationships, AI systems are also exposed to a broader range of supply chain vulnerabilities. These arise from dependencies on open-source AI libraries, embedded components, and upstream service providers that vendors themselves may utilize. Such components may contain hidden vulnerabilities or be updated without notice.
The complexity of multicloud and SaaS environments further complicates the task of mapping and monitoring all embedded AI elements, making it harder for security leaders to assess and manage risks across an increasingly interconnected AI ecosystem.
How to address: Require vendors to provide an AI software bill of materials (SBOM), use automated tools to scan dependencies, and maintain visibility into upstream components and updates. For more insight, see Use TRiSM to Manage AI Governance, Trust, Risk and Security.

Evidence


2 2025 Gartner Cybersecurity Innovations in AI Risk Management and Use Survey.