{"id":305753,"date":"2025-07-31T05:00:13","date_gmt":"2025-07-31T05:00:13","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/305753\/"},"modified":"2025-07-31T05:00:13","modified_gmt":"2025-07-31T05:00:13","slug":"enterprises-neglect-ai-security-and-attackers-have-noticed-the-register","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/305753\/","title":{"rendered":"Enterprises neglect AI security \u2013 and attackers have noticed \u2022 The Register"},"content":{"rendered":"<p>Organizations rushing to implement AI are neglecting security and governance, IBM claims, with attackers already taking advantage of lax protocols to target models and applications.<\/p>\n<p>The findings come from Big Blue&#8217;s <a href=\"https:\/\/www.ibm.com\/reports\/data-breach\" rel=\"nofollow noopener\" target=\"_blank\">Cost of a Data Breach Report 2025<\/a> report, which shows that AI-related exposures currently make up only a small proportion of the total, but these are anticipated to grow in line with greater adoption of AI in enterprise systems.<\/p>\n<p>Based on data reported by 600 organizations globally between March 2024 and February 2025, IBM says 13 percent of them flagged a security incident involving an AI model or AI application that resulted in an infraction.<\/p>\n<p>Almost every one of those breached organizations (97 percent) indicated it did not have proper AI access controls in place.<\/p>\n<p>About a third of those that experienced a security incident involving their AI suffered operational disruption and saw criminals gain unauthorized access to sensitive data, while 23 percent said they incurred financial loss as a result of the attack, with 17 percent suffering reputational damage.<\/p>\n<p>Supply chain compromise was the most common cause of those breaches, a category that includes compromised apps, application programming interfaces (APIs), and plug-ins. The majority of organizations that reported an intrusion involving AI said the source was a third-party vendor providing software as a service (SaaS).<\/p>\n<p>IBM&#8217;s report draws particular attention to the danger of unsanctioned or so-called shadow AI, which refers to the unofficial use of these tools within an organization, without the knowledge or approval of the IT or data governance teams.<\/p>\n<p>Because shadow AI may go undetected by the organization, there is an increased risk that attackers will exploit its vulnerabilities.<\/p>\n<p>The survey for the report found that most organizations (87 percent) have no governance in place to mitigate AI risk. Two-thirds of those that were breached didn&#8217;t perform regular audits to evaluate risk and more than three-quarters reported not performing adversarial testing on their AI models.<\/p>\n<p>This isn&#8217;t the first time that security and governance have been raised as issues when it comes to corporate AI rollouts. Last year, The Register reported that many large enterprises had <a href=\"https:\/\/www.theregister.com\/2024\/08\/21\/microsoft_ai_copilots\/\" target=\"_blank\" rel=\"noopener\">hit pause<\/a> on integrating AI assistants and virtual agents created with Microsoft Copilot because these were pulling in information that employees shouldn&#8217;t have access to.<\/p>\n<p>Also last year, analyst Gartner estimated that at least <a href=\"https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2024-07-29-gartner-predicts-30-percent-of-generative-ai-projects-will-be-abandoned-after-proof-of-concept-by-end-of-2025\" rel=\"nofollow noopener\" target=\"_blank\">30 percent of enterprise projects involving generative AI (GenAI)<\/a> would be abandoned after the proof-of-concept stage by the end of 2025, due to poor data quality, inadequate risk controls, escalating costs, or unclear business value.<\/p>\n<p>IBM&#8217;s report appears to show that many organizations are simply bypassing security and governance in favor of getting AI adoption in place, perhaps because of a fear of being left behind with all the hype surrounding the technology.<\/p>\n<p>&#8220;The report reveals a lack of basic access controls for AI systems, leaving highly sensitive data exposed and models vulnerable to manipulation,&#8221; said IBM&#8217;s VP of Security and Runtime Products, Suja Viswesan.<\/p>\n<p>&#8220;As AI becomes more deeply embedded across business operations, AI security must be treated as foundational. The cost of inaction isn&#8217;t just financial, it&#8217;s the loss of trust, transparency and control,&#8221; she said, adding that &#8220;the data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it.&#8221; \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Organizations rushing to implement AI are neglecting security and governance, IBM claims, with attackers already taking advantage of&hellip;\n","protected":false},"author":2,"featured_media":305754,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3163],"tags":[323,1942,53,16,15],"class_list":{"0":"post-305753","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-artificial-intelligence","10":"tag-technology","11":"tag-uk","12":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114946088844679981","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/305753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=305753"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/305753\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/305754"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=305753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=305753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=305753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}