As artificial intelligence continues to integrate into the backbone of modern enterprise, a troubling paradox has emerged: while organizations are racing to deploy AI-driven solutions, cybersecurity leaders feel increasingly ill-equipped to defend these systems against sophisticated threats. According to the 2027 Global Digital Trust Insights report published by PwC on October 1, adversarial AI attacks represent the single greatest preparedness gap facing businesses today.
The report, which draws on a comprehensive survey of 3,934 business and technology leaders across 71 countries, highlights that over half (52%) of respondents consider adversarial AI—attacks specifically designed to manipulate, deceive, or compromise AI models—as their most significant cybersecurity challenge. This vulnerability is not merely a technical oversight; it is a systemic issue rooted in a lack of governance, fragmented ownership, and persistent gaps in data protection and workforce expertise.
The Governance Conundrum: Who Owns AI Risk?
The challenge of securing AI environments is being compounded by a lack of clarity regarding internal accountability. As organizations scramble to establish guardrails, they are finding that traditional corporate structures are often ill-suited for the rapid, cross-functional nature of AI risk management. PwC’s findings reveal that no singular ownership model has emerged as the industry standard.
The survey indicates that responsibility is currently fractured across the C-suite. Approximately 29% of respondents believe accountability should rest with the CIO, CTO, or the broader technology function. Meanwhile, 26% favor a dedicated AI leader or a specialized AI function, and 17% believe the CISO or the cybersecurity department is the most appropriate home for AI risk oversight.
Despite this lack of consensus, there is a clear trend toward professionalizing AI governance. A third (33%) of CEOs and security risk leaders have already moved to appoint dedicated AI roles, such as a Chief AI Officer, to bridge the gap between technical innovation and risk mitigation. This shift signals an industry-wide recognition that AI is no longer a peripheral IT project but a core business component that requires dedicated, specialized leadership.
The Foundation of Risk: Data Governance Shortfalls
The report further emphasizes that AI risk cannot be isolated from broader data security concerns. The integrity of any AI system is inextricably linked to the quality and security of the data it consumes. However, many organizations continue to struggle with the foundational elements of data hygiene.
PwC’s research shows that only about half of the responding organizations have fully implemented essential data classification (49%) and data loss prevention (48%) policies. This data fragmentation creates a precarious environment where sensitive information is exposed, making it easier for malicious actors to conduct adversarial attacks, such as data poisoning or model inversion, which rely on access to training data or system inputs. Without robust data classification, organizations cannot effectively enforce the "guardrails" necessary to prevent LLMs (Large Language Models) from leaking sensitive information or being manipulated by adversarial prompts.
Budgetary Shifts and Defensive Strategies
Despite the daunting nature of these challenges, there is a distinct sense of optimism and strategic resolve among organizational leaders. Financial commitments to cybersecurity are rising, with 84% of security and finance executives expecting their budgets to increase—a six-percentage-point rise compared to 2025 projections.

AI has become a cornerstone of these defensive strategies. More than half (58%) of respondents identified AI as a top-five priority for their cybersecurity budgets. When it comes to deploying AI, the focus is bifurcated between securing the technology itself and using it as a defensive tool. On the "to-do" list for AI security, organizations are prioritizing responsible AI governance (42%), platform hardening (38%), and supply chain security (35%).
Simultaneously, businesses are aggressively pursuing AI to bolster their internal security operations. By automating threat detection and alerting (50%), fraud detection (43%), and phishing detection and response (42%), organizations hope to leverage the speed and scale of AI to offset the capabilities of attackers who are using the same tools to launch more sophisticated, automated campaigns.
Addressing the Human Element: Bridging the Skills Gap
Perhaps the most significant roadblock to progress is the persistent shortage of skilled personnel. Technology and sophisticated automated controls are only as effective as the human teams managing them. Tonya Ugoretz, co-leader of the Cyber & Risk Innovation Institute at PwC US, emphasized that organizations must return to the fundamentals to address the threat of adversarial attacks.
"That means understanding where sensitive data sits, controlling access, continuously testing and monitoring AI systems, and having clear processes to identify and respond when something goes wrong," Ugoretz stated. She further stressed that technology alone is insufficient, noting that organizations require "clear accountability for AI risk—who owns the decisions, who is responsible when an AI system behaves unexpectedly and where human oversight is required—alongside people with the skills to exercise that oversight effectively."
The data supports this call for human capital investment. More than two-fifths (44%) of CISOs identified the lack of workforce skills in AI oversight and governance as a primary barrier to increasing the autonomy of AI agents. This skills gap has tangible consequences for the adoption of new technologies; over half (55%) of respondents cited the reliability of the technology—and the associated difficulty in managing it—as a significant hurdle to broader adoption of AI agents.
However, the industry is not standing still in the face of this talent crisis. Organizations are increasingly looking toward AI-enabled training as a solution. Over half (53%) of those surveyed prioritize AI-driven training programs to help bridge the skills gap and retain existing employees. This strategy is complemented by efforts to provide better career growth opportunities (59%) and a stronger emphasis on nurturing a resilient cyber culture (53%).
The sentiment is echoed by broader industry trends. Recent data from the security firm Swimlane suggests that the integration of AI is already providing dividends in workforce development, with 62% of Security Operations Center (SOC) workers reporting that AI has helped them improve their own skill sets. By automating repetitive tasks, analysts are finding more time to focus on complex, high-level threat hunting and governance, effectively creating a feedback loop where AI helps upskill the very humans needed to secure it.
As organizations navigate the next phase of the digital transformation, the consensus is clear: the threat landscape is evolving, and adversarial AI is the new frontier. Success will not be found in simple software patches or static policies, but in a holistic approach that combines rigorous data hygiene, clear organizational accountability, and a committed investment in the human expertise required to govern the systems of the future. The increase in budgetary allocation reflects a growing recognition that in the age of AI, security is not just a defensive measure, but a prerequisite for sustained innovation and business growth.
