AI risks have displaced malware as the primary threat for security leaders in the DACH region, while companies rely on governance and European controls.
76 percent of companies experienced disruptions caused by external partners with damages sometimes exceeding 10 million dollars, yet only 31 percent conduct joint tests with critical third-party providers.
API security incidents in Germany cost companies an average of €470,000 per incident, with authorization gaps and misconfigurations being the most common causes.
AI requires security boundaries through four-level governance—from training through access control to network monitoring—because AI agents act with user rights and create new attack surfaces.
Mid-market companies must clarify data location, access rights and jurisdiction as binding criteria when selecting security partners, rather than blindly relying on US or Israeli providers.
Anthropic calls for an aviation-like regulatory authority or commissioned private auditors to examine AI models for critical risks before their release.