More Detail
CISOs must increase their focus on evolving AI-related threats. Over 60% of organizations report evidence or suspicion of unsanctioned use of GenAI tools.1 And 79% of CISOs report a noticeable increase in both the volume and sophistication of phishing and business email compromise (BEC) attacks attributed to AI-enhanced techniques, and one-third of organizations have already experienced deepfake incidents, with some reporting major incidents involving voice and video impersonation.1 These findings show that both internal and external AI-related threats are real today.
Top Internal AI-Related Cyberthreats
Limited AI Literacy and Guiding Policy
A major CISO challenge is limited AI literacy across organizations, which hampers effective policy and risk management. The shortage of AI expertise leaves organizations less prepared to monitor and mitigate risks. Notably, 60% of CISOs know which AI types are in use, compared to only 18% of other cybersecurity professionals, creating blind spots that make it difficult to deploy or understand AI-driven countermeasures.1
How to address: Implement targeted AI training and establish clear AI security policies. Training must cover understanding model behavior, recognizing attack vectors, interpreting AI decisions, managing AI alerts, and staying current on relevant regulations. For more insight, see A CISO’s Guide to AI Cyber Stewardship.
Shadow AI From Employees
The unsanctioned use of AI tools and applications by employees poses a growing risk. With the widespread availability of commercial AI services, organizations are losing oversight over how sensitive data is processed and shared, increasing the risk of data leaks, regulatory violations, and compromised business decisions. Nearly half of organizations suspect or have evidence of employees using embedded or custom-built GenAI tools without proper risk management, and many are also concerned about the use of unauthorized public AI services.
How to address: Conduct regular audits to detect unauthorized AI use and enforce approval processes. Embed cybersecurity into broader AI governance efforts, and embrace agile risk management processes, such as DevSecOps, rather than relying on traditional, waterfall risk assessments — which can’t scale at the speed of AI experimentation. For more insight, see CISOs Must Bring Shadow AI Into the Light. Data Leakage and Grounding via AI Prompts
CISOs face significant risks of data leakage through AI prompts, as employees inadvertently share sensitive or proprietary information when interacting with generative AI tools. This risk is heightened by features like chat histories, file uploads, and provider logging, which can expose confidential data to unauthorized parties or external vendors. Incidents such as the Samsung source code leak underscore how easily data loss can occur via AI interactions.1
How to address: Deploy prompt monitoring tools, enforce restrictions on sensitive data input into AI systems, and implement data security posture management (DSPM) or TRiSM tools to discover, classify, and protect sensitive information across AI workflows. For more insight, see Generative AI Adoption: Top Security Threats, Risks and Mitigations. Limited Visibility of Embedded AI Features
CISOs must navigate the limited visibility of embedded AI features, especially those integrated by third-party vendors. As organizations rapidly adopt solutions with built-in AI, many of these features are enabled and used without proper oversight or security assessment. This lack of transparency means cybersecurity teams may not know what data is being processed, how models are being trained, or if sensitive information is being exposed.
Uncontrolled Experimentation With Custom-Built AI Applications, Including Agents
Uncontrolled experimentation with custom-built AI applications and agents creates serious risks for the organization. This can lead to new attack surfaces, like model context protocol (MCP) server vulnerabilities, where attackers manipulate or disrupt AI models. AI agents may also act unpredictably, increasing the risk of data exposure or system compromise in ways that are hard to detect or control.
Top External AI Cyberthreats
AI-Enhanced Phishing, Deepfakes, and Social Engineering
AI-enhanced phishing and BEC attacks are a growing threat, with 37% of CISOs reporting deepfake incidents during video calls and 43% during audio calls.2 Attackers now use AI to automate, personalize, and scale their campaigns, making phishing emails and social engineering attempts more convincing and harder to detect. An estimated 12% of emails, including phishing, show signs of being written by large language models.3
These advances enable attackers to target high-value individuals, impersonate executives with deepfakes, and bypass traditional defenses, significantly increasing the risk of data breaches and financial loss for organizations.
Regulatory and Compliance Impacts
CISOs are increasingly threatened by the growing complexity and stringency of AI-related regulations, such as the EU AI Act and various U.S. state and local laws. These regulations introduce significant compliance burdens, including the need for rigorous risk assessments, detailed documentation, and continuous oversight of AI systems. Noncompliance can result in severe financial penalties and reputational damage. The fragmented nature of regulations across jurisdictions further complicates compliance efforts, increasing operational complexity and costs.
Attacks on AI Infrastructure and Prompts
As AI systems become ubiquitous in business operations, adversaries are targeting underlying infrastructure, models, and supply chains. Twenty-nine percent of organizations report experiencing an attack on their enterprise GenAI application infrastructure in the last 12 months.1 These attacks can include data poisoning, which can corrupt training datasets and bias models, model theft and inversion to extract sensitive information, model evasion to bypass detection, and backdoor or Trojan attacks that embed hidden vulnerabilities.
Third-Party AI Risks
Third-party AI-specific risks arise from the reliance on vendor-supplied models and cloud-based AI services, which may contain hidden vulnerabilities or be updated without notice. The complexity of multicloud and SaaS environments makes it even harder to track where and how AI models operate, and whether third-party providers are following best practices for data privacy and security.
Unpatched or unsecured vendor models and services can create exploitable weaknesses, while insufficient contractual controls may limit an organization’s ability to enforce security requirements or receive timely incident notifications. Additionally, limited visibility into vendor operations can make it difficult to detect unauthorized data access or data leakage.
Supply Chain Vulnerabilities
Beyond direct third-party relationships, AI systems are also exposed to a broader range of supply chain vulnerabilities. These arise from dependencies on open-source AI libraries, embedded components, and upstream service providers that vendors themselves may utilize. Such components may contain hidden vulnerabilities or be updated without notice.
The complexity of multicloud and SaaS environments further complicates the task of mapping and monitoring all embedded AI elements, making it harder for security leaders to assess and manage risks across an increasingly interconnected AI ecosystem.