Strategy & CIO

84% Expect Bigger Cyber Budgets, Yet Half Say Attacks on AI Systems Are the Threat They Are Least Ready For

PwC's survey of nearly 4,000 executives shows money flowing towards AI security faster than the controls, skills and continuity plans needed to spend it well. Deepfake and vulnerability data published the same week shows where the gap is already costing.

October 8, 2026 · Strategy & CIO
An empty meeting room with white leather chairs around a wooden table, a laptop, tablet and coffee cups, and a wall screen showing a company data presentation

Key Takeaways

  • PwC surveyed 3,934 executives in 71 countries and territories: 84% of security and finance leaders expect cyber budgets to rise, up from 78% a year earlier.
  • 58% of security leaders rank AI among their top cyber budget priorities, yet 50% say attacks on AI systems are the threat they are least prepared to address.
  • Only 5% of organisations have fully implemented all seven data-risk measures PwC examined, down from 7%, and just 39% have a fully formalised continuity plan covering cyber risk.
  • Pindrop found roughly three in four security leaders encountered or suspected a deepfake attack in the past year, while about 10% have purpose-built defences.

Security budgets are going up again, and AI is the reason most often given. The harder question is what the money is buying. PwC's latest global survey, released on October 1, finds leaders putting AI at the top of next year's spending list while naming attacks on AI systems as the threat they are least able to handle, and the basic data controls those systems depend on are, if anything, slipping backwards.

More Money, Less Readiness

The 2027 Global Digital Trust Insights Survey polled almost 4,000 business and technology executives across 71 countries and territories. Eighty-four percent of security and finance leaders expect cyber spending to rise over the next 12 months, up from 78% a year earlier, and 58% of security leaders rank AI among their top cyber budget priorities. Fieldwork ran from May to mid-July, according to Bloomberg Law, so the results predate the latest wave of frontier model releases.

Readiness tells a different story. Half of security leaders say attacks on AI systems are among the threats their organisations are least prepared for, ahead of cloud threats at 40%, third-party breaches at 34% and ransomware at 33%. Asked about specific AI attack types, leaders reported the weakest preparedness for autonomous botnet compromises (53%), adversarial attacks (52%) and data poisoning (52%), according to WealthBriefing's summary of the report.

"AI is changing both sides of the cyber equation. It is creating new risks and expanding the attack surface," said Avinash Rajeev, global cyber, data and tech risk leader at PwC US, adding that it can also transform how organisations defend themselves. Leaders are not yet ready to hand it the controls: only 22% would authorise AI agents to carry out cyber defence actions fully autonomously, with 55% citing reliability and technology maturity as the main barrier and 46% citing accountability and explainability.

The Foundations Are Slipping

The most uncomfortable number in the survey is about data, not AI. PwC examined seven data-risk measures; organisations have implemented an average of three, and only 5% have fully implemented all seven, down from 7% last year. Forty-nine percent have fully implemented data classification policies and 48% have fully deployed data-loss prevention across key exit channels. Those are the controls that decide what an AI system can read and what it can leak, which makes them the first line of defence against the data poisoning and model manipulation leaders say they fear most.

Resilience planning shows the same pattern. Only 39% of security, risk and operations leaders have a fully formalised and integrated operational continuity plan that addresses cyber risk. Forty-seven percent strongly agree that cyber risk is a standing board agenda item, and about a third of organisations have created dedicated AI roles. Ownership is fragmented: AI accountability sits with the CIO, CTO or a similar role in 29% of organisations, with a dedicated AI leader in 26% and with the CISO or cyber function in 17%. Meanwhile, 44% of CISOs name workforce skills in AI oversight and governance as a major obstacle.

Older debts have not gone away either. Detectify's analysis of 1,293 customers, published September 30, found 86% of open critical and high-severity findings in the US had been exposed for more than 90 days, rising to 92% in the UK and 97% in the Nordics. Organisations with publicly exposed AI tooling resolved critical and high flaws at less than half the rate of the wider customer base. "The danger is not experimentation itself; it is experimentation becoming invisible infrastructure," said Detectify CEO Carlsson.

Where the Gap Is Already Costing

AI is also arriving through the front door as an attack tool. Pindrop's 2026 Deepfake Readiness Index found roughly three in four security leaders encountered or suspected a deepfake attack in the past year, while about 10% say their organisations have purpose-built deepfake defences. Of organisations that experienced or suspected an attack, nearly half put total costs at $500,000 or more, about a quarter at $1 million or more, and 49% reported follow-on cyberattacks, including ransomware. Thirty-seven percent said a single deepfake attack could put a company like theirs out of business.

Pindrop also found that three quarters of respondents expect deepfakes to become a boardroom priority only after a leader is personally fooled or impersonated. That is the same dynamic PwC describes: concern and spending rising together, while the controls that would turn spending into protection lag behind. Morgan Adamski, US leader of PwC's cyber, data and technology risk business, framed the broader shift as leaders recognising "that cyber has no geographical boundary," with 54% adopting multi-cloud or hybrid strategies and half changing how they manage vendor and supply chain risk in response to geopolitics.

For IT leaders setting 2027 budgets now, the data suggests a simple test for any AI security line item: does it close one of the gaps leaders already admit to, or does it add a new tool on top of foundations that are not yet in place?

Rising budgets are a vote of confidence that security matters. PwC's numbers suggest the next year will be judged less on how much organisations spend on AI security than on whether they finally finish the data and resilience work that AI systems quietly depend on.

Share

More in Strategy & CIO

All Resources →