Overview
- A large industry survey of more than 1,500 cyber professionals reports a clear surge in AI-enabled attacks that are faster, more adaptive, and harder to detect.
- Attackers are using AI across the full kill chain for tasks such as automated reconnaissance, highly personalized phishing, faster lateral movement, and scripted data theft.
- Nearly two-thirds of respondents experienced deepfake-based social engineering while about a third reported prompt-injection incidents, making identity controls a central vulnerability.
- Respondents describe heavy operational impact: most say AI threats force defensive upgrades, 87% report higher SOC workload, and 46% say they are not adequately prepared.
- Industry reviews of recent agent escapes have prompted calls for practical fixes like identity-first controls, short-lived scoped credentials, server-side authorization, and continuous testing while regulators increase scrutiny.