Bottom line: While the majority of enterprises rate AI risks and cloud security as critical, practitioners cannot track actual AI adoption, while management underestimates these control gaps.
A Bitdefender study with over 1,200 IT and cybersecurity experts from six countries shows that organisations recognise growing risks from AI, cloud, and attack surface, but increasingly cannot control them. Particularly critical: security practitioners report significantly poorer visibility into actual AI usage than management.
Lack of transparency in AI deployment: Just over half of respondents feel able to fully oversee approved and unapproved AI tools. Cybersecurity practitioners express significantly more concern than executives – a sign that management systematically underestimates risks from so-called shadow AI (unauthorised AI usage).
Most common attack scenarios: Greatest security concerns centre on internal AI systems, large language models, and cloud infrastructure. Unauthorised cloud access was the most common cause of security incidents according to the study, followed by Business Email Compromise (BEC) and ransomware. AI-driven social engineering attacks are also increasing and have become routine for many organisations.
Cultural challenges and corporate culture: More than half of surveyed experts from organisations affected by security incidents in the past year were asked not to disclose them publicly – despite believing disclosure was necessary. This points to ongoing pressure to handle cyber incidents confidentially rather than communicating transparently.
Implementation gaps in risk mitigation: While organisations recognise the need to reduce their attack surface, they often fail due to limited resources, complex security policies, and concerns about production downtime. Added to this are lack of visibility over which applications are actually needed, and the administrative burden of exceptions management, particularly for legacy IT systems.
Data sovereignty as a new driver: Over three-quarters of respondents would switch their security provider if concerns arose about data ownership or potential access by foreign authorities. Beyond traditional security questions, traceability of data processing is thus gaining relevance – reinforced by new regulatory requirements.
Source: www.it-daily.net · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.