PwC: AI Attacks Top Threat List, But Only 22% Back Autonomous Cyber Defense
What happened
PwC's 2027 Global Digital Trust Insights report surveyed nearly 4,000 business and technology leaders across more than 70 countries. It found that attacks targeting AI systems rank as the top cyber threat that enterprises feel least ready to address. Only 22% of respondents would allow AI agents to defend their networks without human approval of each action. Additionally, 55% cited reliability concerns and 44% pointed to insufficient AI governance skills inside their organizations. A separate finding shows that just 21% of respondents are implementing measures to resist future quantum computing attacks. This is despite active campaigns in which adversaries collect encrypted data today to decrypt it once more powerful computers become available.
Why it matters
- ·The 44% governance skills gap is an internal readiness failure, not just a technology problem. Boards and compliance teams that have not yet built AI governance competency are the same ones unable to evaluate whether autonomous cyber defense tools are safe to deploy.
- ·Only 22% readiness for autonomous AI agents maps directly to obligations under the EU AI Act (Regulation (EU) 2024/1689). That regulation requires meaningful human oversight for high-risk AI decisions. Enterprises lacking skills to operate AI defensively may also be failing oversight obligations on the operational side.
- ·The 21% quantum-security adoption rate is a latent data protection risk with a compliance dimension. Organizations holding long-lived sensitive data under laws such as the General Data Protection Regulation (GDPR) may face future breach liability. This risk applies to those that have not begun migrating to quantum-resistant protections before decryption becomes feasible.
Governance controls affected
What to do now
- ☐Survey your security and AI teams to determine whether your organization has documented criteria for when a human must approve an AI-driven security action before it takes effect, and close that gap if those criteria do not exist.
- ☐Ask your chief information security officer or equivalent whether your encryption strategy includes a plan to replace algorithms that future quantum computers could break, and request a timeline for beginning that transition.
- ☐Assess whether your AI governance team has the skills to evaluate autonomous AI tools, including an ability to review vendor safety claims without relying solely on the vendor's own documentation.
- ☐Review contracts with AI security vendors to confirm they include disclosure requirements if the vendor changes the level of autonomy in their product, so your human-oversight threshold is not quietly bypassed by a product update.
- ☐Include AI governance skills as an explicit criterion in your next senior hire or training program review, and report current skill coverage to your board or audit committee alongside the PwC benchmark.
What to watch next
Compliance teams should monitor whether regulators cite the PwC readiness gaps as evidence that voluntary AI governance measures are insufficient. This is particularly relevant as the EU AI Act (Regulation (EU) 2024/1689) enforcement machinery accelerates through 2026 and 2027. National standards bodies in several jurisdictions are also expected to issue guidance on quantum-resistant security timelines for regulated industries; early movers will have more flexibility in sequencing the work. The CISO AI Confidence Tracks Governance Readiness, Not Control Effectiveness story noted earlier this year that self-assessed readiness and actual control maturity often diverge. Organizations should therefore test their oversight processes against realistic scenarios rather than survey responses.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
